Business Email Compromise (BEC) is one of the most prevalent and costly cyber threats facing organizations today. These sophisticated email scams target businesses of all sizes by impersonating trusted individuals or organizations to deceive employees into transferring funds or disclosing sensitive information.
BEC attacks typically involve fraudulent or spoofed emails that appear to originate from a legitimate source, such as a company executive, customer, vendor, or business partner. These deceptive communications are carefully crafted to appear authentic and may prompt recipients to initiate wire transfers, authorize ACH payments, or share confidential business information. As a result, organizations may unknowingly send funds or sensitive data directly to cybercriminals.
Maintaining a strong culture of awareness and vigilance is essential to safeguarding your business against these increasingly sophisticated schemes.
At Amerant Bank, we are committed to helping protect your business. The following best practices can help you identify, prevent and respond to Business Email Compromise attempts.
Here are nine ways to protect yourself and your business:
- Do not rely solely on payment instructions received via email or text messages. Always verify payment requests by phone using known and trusted phone numbers.
- Validate changes to payment instructions directly with the intended recipient, paying special attention to requests involving changes to account numbers or banking details.
- Carefully review email communications and text messages for suspicious or unusual details, such as unfamiliar sender addresses, unexpected instructions, spelling or grammatical errors, or changes in established communication patterns.
- Understand your customers’ and vendors’ normal business practices, including their typical payment methods, payment schedules, and communication preferences.
- Perform appropriate due diligence when onboarding new vendors and customers.
- Be cautious of requests that convey a sense of urgency or secrecy. Fraudsters often use pressure tactics to prompt immediate action without allowing sufficient time for proper verification.
- Think before you click. Avoid clicking on links, attachments, or communications from unknown, unexpected, or unsolicited sources.
- Implement strong security controls, such as multi-factor authentication and dual approval processes for wire transfers and other high-risk transactions.
- Establish system controls and email security rules, including:
o Flagging emails that closely resemble, but do not exactly match, your company’s email domain.
o Flagging emails where the “Reply-To” address differs from the sender’s displayed email address.
o Clearly distinguishing between internal and external email communications.
By incorporating these controls into your daily business processes, your organization can significantly reduce the risk of becoming a victim of Business Email Compromise fraud.
If You Suspect BEC Fraud
If you believe you may have been a victim of fraud, contact us immediately at 1(855)263-7268.
For more information about protecting your accounts, visit the Amerant Security Center.



