ScamsImpersonationProtecting your small business from scams: an owner's playbook
High

Protecting your small business from scams: an owner's playbook

Business email compromise alone drained close to $2.8 billion in 2024, and small firms get hit hardest because one rushed employee can move the money. Here is how an owner builds the controls — approval rules, out-of-band verification, MFA, and staff training — so no single email can drain the account.

Sources checked:FBI IC3CISAFTC

If you run a small business, the scam most likely to cost you real money won’t look like a scam at all. It’ll look like an ordinary email about an invoice or a bank detail — from a vendor you know, a client you trust, or your own “CEO” — and it’ll catch the person whose job is to pay things quickly. That’s the whole design, and it works.

The numbers are sobering. The FBI’s Internet Crime Complaint Center recorded 21,442 business email compromise (BEC) complaints in 2024, with close to $2.8 billion in reported losses — second only to investment fraud by total dollars. BEC hits firms of every size, but small businesses get hurt worst, because the controls that would catch a faked request at a big company often don’t exist yet at a small one. The good news: the defenses are cheap, mostly one-time setups, and don’t depend on anyone being clever in the moment.

The scams that target businesses (they’re variations of one move)

Strip away the cover stories and nearly every business scam is the same act: get someone to send money or change where money goes, based on an email alone. The common forms:

  • Vendor bank-change / fake invoice. A supplier you really use “updates” their banking details, or an invoice arrives for goods you may have ordered. You pay — straight to the scammer. See the line-by-line of a BEC invoice email for how convincing it gets.
  • CEO / executive wire request. A message from the “owner” or “CFO” — often “I’m in a meeting, can’t talk” — asks for an urgent wire or a batch of gift cards, quietly.
  • Payroll diversion. HR or payroll gets a request to reroute an employee’s direct deposit to a new account.
  • Phishing for the keys. A fake login page harvests an employee’s email password, and the attacker then sends the fraudulent requests from a real internal account.
  • Money-mule recruitment. Staff or “contractors” are tricked into forwarding goods or moving money that turns out to be stolen.

Different masks, one machine: a trusted-looking sender, an urgent reason, a push to act on the message in front of you without checking elsewhere.

Why small businesses get hit hardest

At a five- or ten-person company, the same person often receives the invoice, approves it, and pays it. There’s no second set of eyes by default, no formal procedure for “a vendor changed their bank details” — just a busy person trying to clear the inbox. Generative AI has made it worse: the fraudulent emails are now fluent, error-free, and closely mimic real correspondence, so the old tell of clumsy wording is gone.

The lesson isn’t “hire a security team”. It’s that the protection has to live in your process, not in any individual’s alertness — because the scam is specifically engineered to fool an alert, competent person doing their normal job.

The controls to set up now

These are one-time setups that quietly defend you every day afterward (full checklist in the box):

  • A money-movement rule. Write it down: any request to send funds or change banking/payroll details must be verified on a second, known channel before it happens. As the FTC puts it, “pick up the phone and call that vendor, colleague, or client” — on a number you already have, never one from the email. This is the Two-Channel Verification move, made into company policy.
  • Two approvers over a threshold. Require a second person to sign off on payments and account changes above a set amount, so no single employee can be talked into moving money alone.
  • MFA everywhere. Turn on multi-factor authentication across email, file storage, and remote access — CISA advises starting with admin accounts and anyone handling sensitive data. Not all MFA is equal: phishing-resistant MFA, like a security key, gives the strongest protection.
  • Lock your domain. Set up email authentication (SPF, DKIM, DMARC) so scammers can’t spoof your company’s address. The FTC notes this lets receiving servers confirm a message is really from you and block imposters.
  • Train and refresh. Teach staff to recognize and report suspicious emails, and keep it current with short refreshers — CISA’s point is that your security is only as strong as your least-trained employee. Make reporting easy and blame-free.

Two of these overlap with personal defenses worth knowing: Lock the Front Door (MFA and password hygiene) and The Pause on Money for any unexpected payment.

If you’ve already paid

Move fast; the first hours matter most. Contact your bank immediately and ask them to recall or freeze the wire or transfer — quick action gives the best chance of recovery. Then report it to the FBI’s IC3 at ic3.gov, which is the channel specifically set up to act on BEC and can sometimes help claw back funds, and notify local law enforcement and the FTC at ftc.gov. If an employee’s email was compromised, reset that password, force MFA, and check for mail-forwarding rules the attacker may have added to keep watching your messages.

Most importantly, don’t treat it as one person’s mistake. The fix is the same either way: turn the gap that let it through into a written rule, so the next request that looks exactly right still has to clear a second channel and a second person. For the wider toolkit, see our defense moves and try the 60-second quiz with your team — it’s a low-friction way to make this part of how the business runs.

Warning signs
  • An email asks to change where money goes — a vendor's "new bank details", an employee's payroll account, or a wire for an urgent deal — and pushes for speed and discretion.
  • The sender looks right (a boss, a known vendor, a regular client) but the request breaks the normal routine, and "confirm by replying here" keeps you on the same channel.
  • An invoice arrives for something you're not sure you ordered, or a "CEO" emails from outside a meeting asking you to buy gift cards or move funds quietly.
Defense move — Two-Channel Verification
  • Make it a rule: any request to send money or change banking/payroll details is verified on a second, known channel — call the vendor or colleague on a number you already have, never the one in the email.
  • Require two people to approve any payment or account change above a set threshold — so no single employee can be socially-engineered into moving funds alone.
  • Turn on MFA everywhere, starting with email and admin accounts; phishing-resistant MFA (a security key) is the strongest.
  • Set up email authentication (SPF, DKIM, DMARC) so imposters can't spoof your domain, and train staff to spot and report suspicious messages.
Editor's note

Every business-scam story I’ve read has the same shape: it wasn’t a dumb employee, it was a normal employee doing their job fast. Someone in accounts payable got an email that looked exactly like a vendor they pay every month, with new bank details and a polite nudge, and they paid it — because paying invoices is literally their job. You can’t train your way out of that with willpower; the request is designed to look routine. What actually works is taking the decision off the individual: a rule that any banking change gets a call-back and a second pair of eyes, no exceptions. Boring procedures beat sharp instincts here, because the scam is built to fool the instinct.

Frequently asked

We're a small shop — aren't these scams really a big-company problem?

It's the opposite. The FBI's IC3 logged 21,442 business email compromise complaints in 2024 with close to $2.8 billion in reported losses — second only to investment fraud by dollar amount — and smaller firms tend to take the worst hits because they have fewer controls and fewer people to catch a fake request. A scam that a large company's finance team would flag in seconds can clear instantly at a five-person business where one person both receives the invoice and pays it. The fix isn't a bigger budget; it's a couple of simple rules, set up once.

What's the single most important control if I only do one thing?

Verify every money-movement request on a second channel. Almost every business scam — fake vendor bank-change, CEO wire request, payroll diversion, fake invoice — relies on you acting on the email alone. The FTC's advice is blunt: when a message asks you to send money or change payment details, "pick up the phone and call that vendor, colleague, or client" on a number you already have, not one from the email. Build that into a written rule so it's the default, not a judgment call someone makes under pressure.

How do I get my staff to actually follow this without slowing everything down?

Make the rule about the request type, not about suspicion, so no one has to decide whether an email "looks fishy". Any banking change or payment over a threshold simply requires a call-back and a second approver — every time, even when it seems obviously fine. CISA's guidance is that a company's security is only as strong as its least-trained employee, so reinforce it with short, periodic refreshers and make reporting a suspicious email easy and blame-free. People follow a clear procedure far more reliably than a vague warning to "be careful".

RY
Ryon — Founder & Editor
Consumer-safety advocate · Scamblare

Scamblare researches scams every day so you don't have to. Every article is checked, claim by claim, against primary sources like the FTC and FBI IC3 under our published editorial standard. How we fact-check ›