Business Email Compromise (BEC)

What it is

Business Email Compromise is a type of cybercrime where fraudsters gain access to a genuine email account belonging to a business, supplier, or senior employee. Once inside the mailbox, they monitor ongoing conversations and wait for the perfect moment to intercept or alter payment instructions. They then send realistic looking emails, from the legitimate account, asking for a change in bank details or urgent payment. Because the email comes from a real address and often uses the same writing style as the genuine sender, this scam can be extremely difficult to detect. The payment is then sent to a bank account controlled by criminals.

How it works

1
Inbox is compromised; criminals watch invoice threads.
2
They send a legitimate looking email with changed bank details.
3
Money is sent to the wrong account; inbox rules hide traces.
Warning Signs and Red Flags
Sudden change in bank details combined with a sense of urgency.
Email appears suspicious, such as unusual domain, spelling mistakes, or poor formatting.
Pressure applied to process payments quickly.
Supplier later claims that “payment was not received”.
What to do now
Verify independently: call a known number; never rely on the email.
Use dual control for bank detail changes.
Alert your bank immediately if payment was sent.

Real cases in Malta

Report a Scam

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.

Report a Scam Now

Other Scam Types

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.