On this page
It starts with a single email. Someone on your team clicks a link, enters their password on a page that looks exactly like the Microsoft 365 login screen, and goes on with their day. They have no idea that their inbox now belongs to an attacker.
What happens next can cost your business six figures. And it happens to businesses in Northern Ontario more than you might think.
Business Email Compromise (BEC) is one of the most financially damaging categories of cybercrime. According to the FBI Internet Crime Complaint Center (IC3) 2024 Internet Crime Report, BEC attacks accounted for $2.77 billion USD in reported losses, second only to investment fraud and more than any other type of internet crime. That figure only reflects cases that were reported. The actual number is almost certainly higher.
Here is exactly how the attack works, step by step.
The Anatomy of a BEC Wire Fraud
Step 1: The Inbox Is Compromised
It usually starts with a phishing email. The message looks like a routine notification — a shared document, a voicemail transcription, a password expiry warning. The link leads to a convincing login page. Your employee enters their credentials, and the attacker now has access.
In more sophisticated attacks, the phishing page also captures the multi-factor authentication (MFA) token in real time using adversary-in-the-middle toolkits like EvilGinx. This means even MFA does not always stop the initial compromise if you are using basic SMS or app-based approval methods.
Step 2: The Attacker Sits and Watches
This is the part most people do not expect. The attacker does not immediately send spam or do anything obvious. Instead, they sit quietly in the compromised inbox for days or even weeks, reading every email.
They learn who your clients are, who your vendors are, who handles payments, and what invoices are coming due. They study the tone and style of emails. They note who signs off with “Thanks” versus “Best regards.” They are building a profile.
Step 3: A Payment Opportunity Is Identified
The attacker identifies a real transaction in progress. Maybe you are about to pay a contractor, close on a property, or settle an invoice with a long-standing supplier. The attacker now knows the amount, the timing, and the people involved.
Step 4: Interception Is Set Up
The attacker creates an email rule in the compromised inbox that automatically moves certain messages to a hidden folder and marks them as read. This means the legitimate account owner stops seeing emails from the targeted contact.
In some cases, the attacker registers a lookalike domain. If your vendor’s domain is “smithconstruction.ca,” the attacker might register “smlthconstruction.ca” (with a lowercase L replacing the I) or “smith-construction.ca.” The difference is nearly invisible in a busy inbox.
Step 5: Fraudulent Payment Instructions Are Sent
The attacker sends an email, either from the compromised inbox directly or from the lookalike domain, with modified payment instructions. The message looks perfectly normal. It references the correct invoice number, the correct amount, and uses language consistent with previous correspondence.
The only change is the bank account number.
Step 6: The Money Is Wired
Your accounts payable team processes the payment. The wire goes to the attacker’s account, which is typically a mule account that gets drained immediately and forwarded through multiple hops, often ending up overseas within hours.
Step 7: Discovery Comes Too Late
Days or weeks later, the real vendor follows up about their unpaid invoice. Confusion leads to investigation. Investigation leads to the sickening realization that the money is gone.
Why the Money Almost Never Comes Back
Once a wire transfer clears and the funds are moved, recovery is extremely difficult. Banks are not obligated to reverse wire transfers the way they might reverse a credit card charge. Wire fraud recovery rates are notoriously low — industry estimates put successful recovery at under 30% — and the window to act closes rapidly, often within 24 to 48 hours.
If the funds move internationally, recovery becomes nearly impossible. The money is gone.
Your Obligations Under PIPEDA
If a BEC attack compromises personal information in the inbox (and it almost always does — think client emails, employee data, financial records), you have obligations under PIPEDA (Personal Information Protection and Electronic Documents Act).
Since November 2018, Canadian businesses must report breaches involving personal information to the Office of the Privacy Commissioner, notify affected individuals, and maintain records of all breaches. Failing to report can result in fines up to $100,000 CAD per violation under the PIPEDA Breach of Security Safeguards Regulations (2018).
What Actually Stops BEC Wire Fraud
There is no single control that prevents BEC. It requires layers. Here is what works.
Email Authentication: SPF, DKIM, and DMARC
DMARC (Domain-based Message Authentication, Reporting, and Conformance) prevents attackers from sending email that appears to come from your domain. When properly configured with a p=reject policy, receiving mail servers that honour the policy block spoofed messages outright.
If you have not set up DMARC yet, start with our guide on SPF, DKIM, and DMARC configuration. It is one of the highest-impact security improvements you can make.
Phishing-Resistant MFA
Standard MFA (SMS codes, push notifications) can be bypassed by adversary-in-the-middle attacks. Phishing-resistant MFA methods like FIDO2 security keys or Microsoft Entra ID certificate-based authentication are significantly harder to compromise. The CISA Phishing Guidance Report (2023) recommends phishing-resistant MFA as the single most effective control against credential theft.
Payment Verification Procedures
Technology alone is not enough. Your team needs a clear, enforced policy:
- Never change payment details based on email alone. Any request to change banking information must be verified by phone using a known, previously established phone number, not a number provided in the email.
- Require dual authorization for wire transfers above a set threshold.
- Flag new payees for additional scrutiny.
- Implement a waiting period of 24 to 48 hours for first-time wire transfers to new accounts.
This procedural layer is often what separates businesses that catch BEC attempts from those that lose six figures.
Mailbox Monitoring and Anomaly Detection
Monitoring tools can detect the telltale signs of BEC: unusual mail rules being created, login from unfamiliar locations, bulk email forwarding, or access from suspicious IP addresses. Microsoft Defender for Office 365 and third-party security platforms can flag these behaviours automatically.
At DVG Systems, we configure and monitor these alerts as part of our network security service for clients across Thunder Bay and Northwestern Ontario.
Security Awareness Training
Your team needs to recognize phishing emails before they click. Regular, realistic training reduces click rates significantly. The KnowBe4 Phishing by Industry Benchmarking Report (2024) found that organizations with ongoing security awareness training reduced phishing susceptibility from 33% to under 5% within 12 months.
Protect Your Business Today
BEC wire fraud is not a theoretical risk. It is happening to Canadian businesses right now, including small and mid-sized businesses that assume they are too small to be targeted. The Canadian Centre for Cyber Security National Cyber Threat Assessment (2023-2024) explicitly identified BEC as one of the top threats to Canadian small businesses.
Here is where to start:
- Implement DMARC on your domain today. Our email security guide walks you through it.
- Enable phishing-resistant MFA across your Microsoft 365 tenant using Microsoft Entra ID conditional access policies.
- Establish payment verification procedures and train every person who handles payments.
- Monitor your inboxes for suspicious mail rules, forwarding, and anomalous login activity.
- Test your team with simulated phishing to find gaps before attackers do.
One compromised inbox. A few weeks of patience. A single wire transfer. That is all it takes. The defences exist. The question is whether you put them in place before or after the loss.