Business email compromise (BEC) uses believable messages to trick employees into sending money, sharing sensitive information, or changing payment details. The sender may appear to be a company leader, supplier, or colleague, and the request may arrive during a busy workday. Staff can reduce the risk by noticing unusual details, verifying requests outside the email thread, and reporting concerns promptly. A careful pause is often safer than acting on an urgent message.
Watch for unusual requests
Treat unexpected requests for wire transfers, gift cards, payroll changes, or confidential files with caution, especially when the message insists on secrecy or immediate action. Scammers often use urgency to discourage normal checks. A familiar name or logo does not prove a message is genuine, and a request that fits someone’s role can still be fraudulent.
Check the sender’s full email address, not only the display name. Look for misspellings, extra characters, or a domain that differs slightly from the organization’s real domain. Also review the reply-to address and be cautious if a message suddenly changes tone, asks you to bypass an established process, or starts an unexpected conversation about a transaction.
Verify through a trusted channel
Before paying an invoice or changing account details, confirm the request using a contact method already on file. Call a known phone number or use a trusted internal directory; do not use the number, link, or contact details supplied in the questionable message. For payment changes, follow your organization’s approval process and require a second authorized person to review the change.
For a message that appears to come from a manager or coworker, contact them through a separate channel, such as a known work number or established messaging app. Ask what they requested without forwarding sensitive information. If you cannot confirm the request, do not reply with credentials, open unexpected attachments, click links, or proceed with the transaction.
Report without spreading risk
Use your organization’s approved reporting button or send the message to its designated security contact. Follow internal instructions for preserving the original email, including its attachments and sender details. Avoid forwarding it to coworkers as a warning unless your security team asks you to; forwarding can expose others to links or files and may remove useful message information.
If you clicked a link, entered a password, opened an attachment, or sent money, report it immediately. Tell your IT or security team what happened and when, and provide the message if you can do so safely. If credentials may be exposed, use a trusted device to change them and follow the organization’s instructions. Do not delete evidence unless the response team directs you to.
Make verification routine
Set clear rules for approving payments, updating supplier details, and sharing sensitive records. Keep verified supplier contact information in an approved system, and make sure staff know where to report suspicious messages. Managers should reinforce that employees can pause a request for verification, even when it appears to come from a senior leader.
Practice with realistic examples during team training, including messages that use familiar names or create time pressure. Review reporting instructions when roles or systems change. Consistent procedures make it easier for staff to recognize a request that falls outside normal practice and act before money or information leaves the organization.
A suspicious email deserves a pause, not an impulsive reply. Check the sender and request, verify through a separate trusted channel, and report concerns using your organization’s approved process. Make these steps part of everyday work, and contact Queenstown Email Security if your business needs help reviewing its email safeguards.