{"id":203,"date":"2026-07-30T13:00:00","date_gmt":"2026-07-30T13:00:00","guid":{"rendered":"https:\/\/missiondefend.com\/blog\/?p=203"},"modified":"2026-07-31T19:55:31","modified_gmt":"2026-07-31T19:55:31","slug":"business-email-compromise-nonprofits","status":"publish","type":"post","link":"https:\/\/missiondefend.com\/blog\/business-email-compromise-nonprofits\/","title":{"rendered":"Business Email Compromise: How One Fake Invoice Drains an Account"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Your church is six months into a roof replacement. The contractor has invoiced twice already, both paid without incident. On a Thursday morning, the third invoice arrives from the same email address you&#8217;ve been corresponding with all spring.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The invoice looks right. Same logo, same layout, same project reference, correct amount. There&#8217;s one difference, and it&#8217;s mentioned in a single line of the email body:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p class=\"wp-block-paragraph\"><em>Please note we&#8217;ve changed banks &mdash; updated remittance details are on the invoice. Sorry for the inconvenience.<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Your bookkeeper updates the payee, sends $47,000, and files the confirmation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Eleven days later the contractor calls to ask when they&#8217;re getting paid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is business email compromise. It is the most expensive attack aimed at organizations your size, and it almost never looks like an attack while it&#8217;s happening.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What BEC actually means<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Business email compromise<\/strong> &mdash; you&#8217;ll see it shortened to BEC everywhere &mdash; is the category of fraud where someone uses email to impersonate a person you trust in order to redirect a payment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The name is slightly misleading, and the confusion matters, because the two versions call for different responses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Version one: nothing was compromised.<\/strong> The attacker registered a domain that looks like your contractor&#8217;s and sent mail from it. Your vendor is `midlandroofing.com`; the attacker owns `midiandroofing.com` &mdash; an <em>l<\/em> swapped for an <em>i<\/em>, invisible in most fonts at normal size. Or `midland-roofing.com` with a hyphen. Or `midlandroofing.co` dropping the <em>m<\/em>. Everything else in the email is copied from real correspondence. Nobody&#8217;s account was ever accessed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Version two: an account really was taken over.<\/strong> The attacker got into a mailbox &mdash; usually through a phished password &mdash; and is sending from the genuine address. This version is far more dangerous, because there is nothing to spot in the sender line. It&#8217;s genuinely the right address. Worse, the attacker can read the entire history first: they know your project, your invoice format, your payment cycle, who approves what, and how your bookkeeper writes. They often set up a quiet mail rule that moves the real vendor&#8217;s messages into an unread folder, so the two of you stop seeing each other&#8217;s emails while the attacker relays between you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second version is why &#8220;just look at the sender address&#8221; is necessary advice but not sufficient advice.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The scale of it<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The FBI&#8217;s Internet Crime Complaint Center recorded <strong>24,768 BEC complaints in 2025, totalling $3,046,598,558 in losses.<\/strong> That works out to an <strong>average reported loss of about $123,005 per complaint.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sit with that figure against a church budget. For most congregations, one successful BEC is larger than a quarter of total giving. For a small nonprofit, it can be existential.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And BEC is a rounding error away from being invisible. There&#8217;s no ransom note, no locked screen, no alarm. The first sign is almost always a vendor politely asking about an overdue payment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The five shapes it takes in a ministry<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The vendor bank change.<\/strong> The scenario above. Most common and most costly, and it spikes during building projects, capital campaigns, and any period when large payments to unfamiliar contractors are normal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The leadership wire request.<\/strong> An email that appears to come from your pastor or executive director, asking the bookkeeper to send a payment urgently, usually with a reason it can&#8217;t be discussed by phone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The payroll redirect.<\/strong> A staff member appears to email HR asking to update their direct deposit details. We&#8217;re covering this one in full tomorrow, because it works differently enough to deserve its own post.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The invoice that was never real.<\/strong> A plausible bill for something a church actually buys &mdash; copier maintenance, website hosting, denominational dues, a directory listing &mdash; from a company you can&#8217;t quite remember but probably use. Small enough to approve without scrutiny. Often repeated monthly until someone notices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The data request.<\/strong> No money at all. Someone asks for the staff list, W-2 information, or the donor database. That data becomes the ammunition for the next attack, aimed at a different organization.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why churches are good targets for this specifically<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Three things, none of them a failing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Approval is informal.<\/strong> In a five-person office, the person who receives the invoice is often the person who pays it. There&#8217;s no purchasing department, and adding one would be absurd. But it means a single deceived person completes the whole transaction.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Large, irregular payments are normal.<\/strong> A church might make three $40,000 payments a year and hundreds of $200 payments. The big ones don&#8217;t recur often enough for anyone to develop an instinct about them, and they cluster in exactly the periods &mdash; building projects, campaigns &mdash; when everyone is busy and moving fast.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Your relationships are public.<\/strong> Your bulletin thanks the contractor. Your newsletter names the architect. Your board minutes list the vendors. An attacker doesn&#8217;t have to guess who you&#8217;re paying.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The one control that stops it<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There is a single procedure that defeats every version of this attack, and it costs nothing:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Any change to payment details is verified by voice, using a phone number you already had, before the payment goes out.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every word in that sentence is load-bearing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Any change<\/em> &mdash; not just large ones. The threshold approach fails, because attackers learn thresholds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>By voice<\/em> &mdash; not by email. If the attacker controls the email thread, every confirmation you receive is written by them. This is the part people get wrong most often: replying to the message and getting a reassuring answer feels like verification, and it is the opposite of verification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>A number you already had<\/em> &mdash; from a signed contract, a previous invoice, or your own contacts. Never the number in the email or on the new invoice. Attackers put their own number on the document precisely so you&#8217;ll &#8220;verify.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Before the payment goes out<\/em> &mdash; because after is a recovery problem, not a prevention one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two additions make it stronger. Require <strong>two people<\/strong> for any payment over a threshold your board sets &mdash; one to initiate, a different one to release. And <strong>read the bank details aloud<\/strong> during the verification call, digit by digit, rather than asking &#8220;did you change banks?&#8221; A yes-or-no question invites a yes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Write the rule down. Give it to everyone who touches a payment. And state plainly that no one will ever be criticized for making the call, including when the request appears to come from the senior pastor. In a small church, the person most likely to be defrauded is the one who feels least entitled to question leadership.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Hardening the email side<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The procedure is the main defense. Three technical measures reduce how often you&#8217;re tested.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Multi-factor authentication on every mailbox.<\/strong> This is the extra step after your password &mdash; a code from an app, or a tap on your phone. It&#8217;s what prevents version two of this attack, where an account is genuinely taken over. Microsoft&#8217;s research finds MFA blocks more than 99.2% of account compromise attacks. It&#8217;s free on Microsoft 365 and Google Workspace.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>External sender warnings.<\/strong> Ask whoever manages your email to enable the banner reading <em>&#8220;This message came from outside your organization.&#8221;<\/em> When a message claiming to be from your executive director carries that banner, the contradiction is visible immediately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Check for mail rules you didn&#8217;t create.<\/strong> After any suspected compromise &mdash; and once a quarter regardless &mdash; look in each mailbox&#8217;s settings for forwarding rules and filters. Attackers routinely add a rule that forwards everything to an outside address, or that files messages containing &#8220;invoice&#8221; or &#8220;payment&#8221; into an obscure folder. It&#8217;s the most common thing left behind, and it&#8217;s the thing people forget to check after changing a password.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">If it already happened<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Speed is nearly everything. The recall window on a fraudulent transfer is measured in hours.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Call your bank&#8217;s fraud line first.<\/strong> Before you investigate, before you email anyone, before you&#8217;re certain. Ask them to attempt a recall. If you have the number ready in advance rather than searching for it, that alone can be the difference.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Report to the FBI at ic3.gov immediately,<\/strong> and say the words <em>business email compromise<\/em> and <em>fraudulent wire transfer<\/em>. This is not a formality. The FBI&#8217;s Recovery Asset Team can initiate what&#8217;s called the Financial Fraud Kill Chain &mdash; a process to freeze funds before they&#8217;re moved onward. In 2025 it ran 3,574 domestic cases and froze <strong>$507,042,623.<\/strong> It works far better within the first 24\u201372 hours.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Don&#8217;t reply to the fraudulent thread<\/strong>, and don&#8217;t delete anything. The mailbox is evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Change passwords from a different device<\/strong> and revoke active sessions &mdash; in Microsoft 365 and Google Workspace there&#8217;s a &#8220;sign out everywhere&#8221; option. Changing a password alone doesn&#8217;t kick out someone who&#8217;s already signed in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Then check the mail rules<\/strong>, as above.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>And tell your insurer.<\/strong> Many cyber liability policies cover funds transfer fraud, and most impose short notification deadlines.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What to do this week<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Write down the verification rule and circulate it to everyone who can initiate or approve a payment. One paragraph. Then find your bank&#8217;s fraud number and put it somewhere that doesn&#8217;t require logging into a computer &mdash; taped inside a cabinet door is fine.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That&#8217;s an afternoon&#8217;s work against the single most expensive attack aimed at organizations your size.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you&#8217;re ready to see where else you stand, MissionDefend&#8217;s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then gives you a baseline score and a ranked list of priorities.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-35f06ea7 wp-block-buttons-is-layout-flex\">\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/missiondefend.com\/#notify\" style=\"border-radius:999px\">Join the launch list &rarr;<\/a><\/div>\n\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">No spam and no sales calls &mdash; just one email when it&#8217;s live.<\/p>\n\n\n\n<h2 class=\"wp-block-heading md-related\">Related reading<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><a href=\"https:\/\/missiondefend.com\/blog\/payroll-diversion-direct-deposit-scam\/\">the version aimed at a staff member&#8217;s paycheck<\/a><\/li>\n\n\n<li><a href=\"https:\/\/missiondefend.com\/blog\/cyber-liability-insurance-churches\/\">whether funds transfer fraud is covered by your policy<\/a><\/li>\n\n\n<li><a href=\"https:\/\/missiondefend.com\/blog\/secure-microsoft-365-google-workspace\/\">the mail settings that make impersonation harder to pull off<\/a><\/li>\n\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\"><em>MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Sources:<\/strong> FBI Internet Crime Complaint Center, <a href=\"https:\/\/www.ic3.gov\/AnnualReport\/Reports\/2025_IC3Report.pdf\" target=\"_blank\" rel=\"noopener\">2025 Internet Crime Report<\/a>; Microsoft, <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/authentication\/concept-mandatory-multifactor-authentication\" target=\"_blank\" rel=\"noopener\">mandatory multifactor authentication guidance<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>BEC cost an average of about $123,000 per report in 2025. Here&#8217;s how the fake-invoice scam works against churches and nonprofits, and the control that stops it.<\/p>\n","protected":false},"author":1,"featured_media":109,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[17,19,20,18],"class_list":["post-203","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threats-scams","tag-business-email-compromise","tag-finance-controls","tag-invoices","tag-wire-fraud"],"_links":{"self":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts\/203","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/comments?post=203"}],"version-history":[{"count":3,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts\/203\/revisions"}],"predecessor-version":[{"id":340,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts\/203\/revisions\/340"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/media\/109"}],"wp:attachment":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/media?parent=203"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/categories?post=203"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/tags?post=203"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}