Business email compromise is the fraud that costs property firms real money, and it almost never looks like a hack. There is no ransom note, no encrypted server, no downtime.

There is an email from a landlord you have paid for six years saying their bank has changed, or an invoice from the roofing contractor who did last month’s communal works, arriving on the right letterhead, in the right thread, quoting the right job number. Someone in accounts updates the payee record, the payment run goes out on Friday, and nobody discovers anything is wrong until the landlord rings on the 12th of the following month to ask where their rent went. That is business email compromise, and it is the most expensive email anyone in a property office will ever act on.

That gap — the days or weeks between the money leaving and anyone noticing — is what makes business email compromise so damaging in lettings and block management specifically. A managing agent does not make one payment a month. It makes hundreds: rent to landlords, contractor invoices against service charge accounts, deposit returns, insurance premiums, ground rent collections, utility payments on void properties. Every one of those is a payment where the recipient’s bank details are held in a system, communicated by email at some point, and changed occasionally for entirely legitimate reasons. Good cybersecurity hygiene helps, but this particular fraud is a process problem wearing a technology costume.

This guide is written for UK property management companies, letting agents and managing agents. It sits alongside our IT support guide for property management companies, our Microsoft 365 security checklist for property firms and our twenty-control cyber security checklist for managing agents. Those cover the support model, one platform and the full control baseline. This one covers a single attack in depth, because business email compromise is the one that turns a security incident into a hole in the client account.

What Business Email Compromise Actually Is in a Property Office

business email compromise property management b plain oval face mask

The term covers a family of frauds with one shared mechanic: the criminal uses email that the recipient trusts to redirect a payment or extract information. UK law enforcement and the banking industry more often call it payment diversion fraud or mandate fraud, and it is worth knowing all three names because your insurer, your bank and your IT provider will each use a different one.

The three business email compromise variants you will meet

The first is mailbox takeover, where an attacker has genuine access to a real mailbox — yours, a landlord’s or a supplier’s — and sends from it. Nothing is spoofed, because nothing needs to be. The second is lookalike domain impersonation, where the attacker registers a domain one character away from the real one and copies a live thread into it. The third is plain impersonation, where a free-mail address simply claims to be someone, relying on urgency rather than technical trickery. Business email compromise in property firms most often arrives as the first two, because the sums are large enough to justify the effort.

Why property management is a target-rich sector

Attackers pick sectors by the ratio of payment value to control maturity. Property management scores badly on both axes. Payments are high-value, frequent and scheduled. Bank detail changes are routine rather than exceptional — landlords remortgage, contractors incorporate, agents change client account providers. Staff turnover in property management is high, so the person processing a payment often has no personal relationship with the payee. And the sector runs on email to a degree that would surprise a bank: tenancy paperwork, works orders, statements and invoices all move as attachments. Business email compromise thrives wherever those three conditions overlap.

Payment flowTypical valueHow details reach youExposure
Monthly landlord rent remittance£600 to £8,000 eachOnboarding form, then email changesVery high — recurring and predictable
Contractor invoice, reactive repair£150 to £3,000Emailed PDF invoiceHigh — volume hides anomalies
Major works under Section 20£20,000 to £500,000Tender pack, then staged invoicesSevere — single large transfers
Deposit return at end of tenancy£800 to £3,000Tenant email or portalModerate — but reputationally toxic
Insurance and ground rent£2,000 to £60,000Broker or freeholder emailHigh — annual, low familiarity
Move-in monies from tenants£1,500 to £6,000Your own emailed instructionsHigh — victim is the tenant

The sums involved nationally

The FBI’s Internet Crime Complaint Center has tracked more than $55.5 billion in global business email compromise losses over the past decade, and puts the average loss per incident at around $137,000 — up from $74,723 in 2019, an increase of roughly 83%. In the UK, invoice and mandate scams reported by banks totalled £41.3 million across 2,305 cases in 2025. That works out at close to £17,900 per case, which is a meaningful number for a mid-sized agency and a survivable one for a bank. Neither figure captures what a business email compromise costs a firm in client confidence afterwards.

How Business Email Compromise Runs, Stage by Stage

business email compromise property management c telephone handset receiver

Understanding the sequence matters because each stage leaves a different signal, and the controls that stop business email compromise are distributed across all four. Firms that focus only on the final stage — the payment itself — end up catching the fraud that a diligent bookkeeper would have caught anyway.

Stage one: getting into a mailbox

Modern mailbox takeover rarely involves guessing a password. The dominant technique is adversary-in-the-middle phishing: the victim clicks a link, lands on a proxy that relays the real Microsoft or Google login page, enters credentials and completes multi-factor authentication normally, and the proxy captures the session token issued afterwards. Because that token is a bearer credential, it can be replayed from anywhere, and refresh tokens can stay valid for weeks.

Analysis of Microsoft’s 2025 Digital Defense Report attributes around 80% of MFA-bypass breaches to session token theft rather than credential guessing. Microsoft’s security researchers documented a multi-stage “code of conduct” phishing campaign in May 2026 that ended in exactly this outcome, and the FBI issued a public warning in May 2026 about a phishing-as-a-service platform called Kali365, first seen in April 2026, built specifically to hijack Microsoft 365 access tokens. Every one of those campaigns is a business email compromise waiting for a payment run to land in.

Stage two: watching quietly

Once inside, the attacker does nothing loud. They read. They search the mailbox for terms like “invoice”, “remittance”, “bank details”, “completion” and “BACS”. They learn your house style — whether you sign off “Kind regards” or “Many thanks”, whether statements go out on the 5th or the 15th, which landlords are abroad. Very often they create an inbox rule that moves messages from a specific contact into a rarely-read folder such as RSS Feeds or Conversation History, so the genuine party’s replies never reach the real user.

That rule is one of the highest-value detections available, and most property firms are not looking for it. Catching a business email compromise here is far cheaper than catching it at the bank.

Stage three: the switch

At the chosen moment the attacker either replies from inside the compromised mailbox or moves the thread to a lookalike domain and continues it. The message is not a cold approach; it is a continuation of a conversation you have been having. It contains a plausible reason for the change — a new business bank account, a factoring arrangement, a company restructure — and often pre-empts the objection by saying “I know we’ve used the old account for years”. Business email compromise succeeds at this stage because the request is boring, not because it is clever.

Stage four: the silence afterwards

Money moves through mule accounts within minutes. The discovery window is the whole game: a payment caught within hours may be recallable, one caught after a fortnight almost never is. In lettings, the natural discovery event is a landlord chasing a missing remittance, which by design happens weeks later. The economics of business email compromise depend entirely on that delay.

StageWhat the attacker doesSignal available to youControl that breaks it
1. AccessAiTM phishing, token theftImpossible-travel and unfamiliar sign-in alertsPhishing-resistant MFA, token protection
2. ReconnaissanceSearches mailbox, sets hiding rulesNew inbox rule creation in audit logAlert on rule creation and forwarding
3. The switchSends new bank details in threadAny change of payee details, everOut-of-band callback on a known number
4. PaymentReceives funds, moves them onName mismatch at the bankConfirmation of Payee, dual authorisation
5. SilenceWaits out the discovery windowUnreconciled remittance, landlord chasingSame-day reconciliation, statement alerts

The Landlord Payment Run: Where Business Email Compromise Hurts Most

business email compromise property management d curved dam wall barrier

The monthly remittance run is the single most attractive target in a lettings business, and it is worth walking through why in concrete terms rather than in general warnings about business email compromise.

The email that changes everything

A landlord writes from the address you have always used. The message references the correct property, uses the landlord’s usual sign-off and says the account details need updating before this month’s payment because they have moved bank. There is no urgency, no threat, no misspelling. If the landlord’s own mailbox has been taken over, the message is genuine in every technical sense — it will pass SPF, DKIM and DMARC checks perfectly, because it was sent by the real account. This is the version of business email compromise that no email filter has ever stopped.

Overseas and portfolio landlords are the softest targets

Landlords who live abroad, own several units or communicate infrequently are disproportionately hit. Nobody at the agency knows their voice. There is no natural reason to phone them. Time zones make verification feel like an imposition. And the plausible cover story is stronger: a landlord relocating genuinely might change bank. Any policy that says “call the landlord to verify” must specify calling the number held on file from before the request arrived, not one contained in the message. Almost every successful business email compromise against a landlord record fails at that single step.

A worked example of one bad month

Consider a firm managing 900 tenancies with an average monthly rent of £1,150, remitting roughly £1.03 million a month to landlords. Suppose an attacker successfully changes the details for just 1% of the landlord records ahead of a single run. That is nine landlords, and roughly £10,350 of rent redirected in one payment cycle. It is not catastrophic, but the firm still owes those landlords their money, must fund the shortfall from its own resources, and now has a reportable incident. Change the assumption to 3% and the figure passes £31,000. A business email compromise does not need to touch every record to hurt.

Rent redirected in one monthly run — 900 tenancies at £1,150 average rent
1% of landlord records altered £10,350
3% of landlord records altered £31,050
5% of landlord records altered £51,750

Why the client account makes this worse

Rent held pending remittance is client money, not the agency’s money. A business email compromise loss from a client account is therefore not simply a trading loss to be absorbed; it is a shortfall in funds held on trust, with all the regulatory attention that attracts. Firms in England holding client money have had to belong to a government-approved client money protection scheme since 1 April 2019, and those schemes exist to reimburse landlords and tenants where an agent misappropriates funds — which is not the same thing as covering a fraud loss caused by an external criminal.

Supplier Invoices: Business Email Compromise in Slow Motion

business email compromise property management e stopwatch blank round face

If the landlord run is the loud target, supplier payments are the patient one. Business email compromise against contractors is harder to spot because the volume is higher, the individual sums are smaller and the finance team has no relationship with most payees.

The invoice that is correct in every detail

The strongest version of this fraud does not fabricate an invoice at all. The attacker sits in the contractor’s mailbox, waits for a genuine invoice to be prepared, and intercepts it — changing one field. Job reference, dates, VAT number, description of works, the lot: all real. That is business email compromise at its most polished. In April 2026, a UK energy company lost £700,000 to a single redirected supplier payment handled exactly this way.

Framework contractors versus one-off trades

Your regular contractors are paradoxically safer, because a changed sort code on a payee you use weekly stands a chance of being questioned. The dangerous population is the long tail: the drainage specialist used twice a year, the asbestos surveyor engaged for one block, the scaffolder on a single Section 20 project. Those payees combine unfamiliarity with large values, which is exactly the combination a business email compromise looks for.

Service charge accounts multiply the damage

When a hijacked payment comes out of a service charge account, the loss belongs to the leaseholders of that block, not to the agency’s own balance sheet. Restoring it means either the agency funding the shortfall or explaining to a residents’ association why their reserve fund is short. Anyone who has attended that meeting will tell you the cost of business email compromise is not measured only in pounds. Strong vendor management discipline — a maintained supplier master, verified once and changed only through a controlled process — is the cheapest protection available here.

Purchase-ledger hygiene beats detection

The most effective supplier-side control is not clever software. It is a rule that bank details in the accounting system can only be created or amended by someone who cannot also approve a payment, and only after a verification call logged against the supplier record. That single separation removes the final step of a business email compromise even when every earlier stage has already succeeded.

Tenant-Facing Fraud: Deposits, Holding Fees and First Month's Rent

business email compromise property management f arched bridge two arches

Not every business email compromise loss lands on the agency’s books. A significant share of the harm in this sector falls on tenants, and it damages the agency anyway.

The intercepted move-in email

A prospective tenant is emailed payment instructions for a holding deposit and first month’s rent. If either mailbox is compromised, the attacker replaces the account details and the tenant pays a criminal. The tenant, who has often just scraped together several thousand pounds, has paid nothing to you, holds no tenancy, and blames the agent.

The conveyancing profession has faced this exact form of business email compromise for years — the Solicitors Regulation Authority has estimated around £10 million a year lost to email modification fraud, including one case where a buyer was defrauded of £640,000. The mitigation the legal sector settled on transfers directly to lettings: tell clients in writing, at the outset, that your bank details will never change by email.

Cloned agents and portal listings

A related fraud does not require compromising anyone’s email at all. Criminals advertise properties they do not control, impersonate a real agency including its branding and claimed memberships, and collect holding deposits. In June 2026 the BBC reported a case of a London flat listed by an agency claiming a Propertymark membership it did not hold. Firms should monitor for lookalike domains and check periodically whether their brand is being used on listings they did not place. Treat it as business email compromise by other means.

What to put in the tenant pack

One paragraph, in bold, in the first email of every applicant journey: our bank details are printed here and will never change; if you receive an email saying they have changed, telephone this number before paying anything. Cheap, unglamorous and consistently effective against every business email compromise variant described above.

Who Pays for Business Email Compromise When the Money Is Gone

This is the part most property firms get wrong, and the part where assumptions carried over from personal banking are actively dangerous.

Mandatory reimbursement does not cover most agencies

Since 7 October 2024 the Payment Systems Regulator has required banks to reimburse victims of authorised push payment fraud up to £85,000, normally within five business days. Critically, that regime covers consumers, micro-enterprises and small charities only. A micro-enterprise employs fewer than ten people and has annual turnover or a balance sheet total not exceeding €2 million. A property management company with twenty-five staff sits outside the scheme entirely. So does one with eight staff and turnover above the threshold. Losing £60,000 to business email compromise as a consumer is a reimbursement claim; losing it as a mid-sized managing agent is a negotiation.

VictimIn the reimbursement regime?Practical outcome
Individual landlord or tenantYes, as a consumerUp to £85,000, usually within 5 business days
Agency with fewer than 10 staff, under €2mYes, as a micro-enterpriseSame protection as a consumer
Agency with 25 staffNoRecovery depends on speed and goodwill
Residents’ management companyUsually not, unless it qualifiesLeaseholder funds at risk
Registered charity, income under £1mYesCovered as a small charity

Client money protection is not fraud insurance

Client money protection schemes reimburse landlords and tenants where an agent misappropriates client money. They are a consumer safeguard and a condition of trading, not a policy that pays out when an external criminal redirects a payment you authorised in good faith. Read your scheme rules and your crime or cyber policy together, and ask your broker one specific question: does the policy respond to a payment made voluntarily by an employee who was deceived? Many standard covers exclude precisely that, which is why social engineering fraud cover is usually a separate extension, and why a business email compromise loss so often falls between two policies.

The failure to prevent fraud offence

The Economic Crime and Corporate Transparency Act 2023 created an offence of failure to prevent fraud, in force since 1 September 2025.

It applies to large organisations — meeting two of: turnover above £36 million, total assets above £18 million, or more than 250 employees — and carries an unlimited fine, with a defence of having reasonable fraud prevention procedures in place. Most agencies are below that threshold. But the six principles in the Home Office guidance published on 6 November 2024 (top-level commitment, risk assessment, proportionate procedures, due diligence, communication and training, monitoring and review) are a perfectly good structure for documenting your own business email compromise defences whatever your size.

The data protection dimension

A mailbox takeover is not only a payment problem. If an attacker has read a mailbox containing tenant identity documents, bank details and tenancy correspondence, that is a personal data breach. Where it is likely to result in a risk to individuals it must be reported to the Information Commissioner’s Office within 72 hours, and affected individuals told without undue delay where the risk is high. Our data governance framework guide covers the record-keeping side of that duty in more detail, and it applies the moment a business email compromise involves a mailbox rather than just a bank transfer.

Business Email Compromise by the Numbers — and What They Hide

Headline figures on business email compromise in the UK are improving, and it would be easy to read that as a reason to relax. It is not.

The direction of travel

UK Finance’s Annual Fraud Report 2026 recorded £1.28 billion of payment fraud in 2025, up 4% on the previous year, across 4.06 million confirmed cases. Authorised push payment losses grew 19% to £576.4 million gross over 248,070 cases, and £354.3 million — around 61% of losses — was returned to victims. Against that, invoice and mandate scams fell to £41.3 million from 2,305 cases, the lowest level recorded, down from 4,721 cases in 2020. In the first half of 2025 alone the category was down 24% year on year, which reads like good news for business email compromise victims.

Invoice and mandate scam cases reported by UK banks (malicious redirection)
2020 4,721 cases
2025 2,305 cases
2025 value £41.3m

Why a falling national number is not your number

Three things sit behind that decline, and none of them protect a managing agent. Bank-side controls have improved for the payment types consumers use. Confirmation of Payee now catches crude name mismatches. And reporting is bank-centric: losses absorbed by a business, settled with a landlord out of the firm’s own funds, or never reported to a bank at all do not appear in these statistics. A firm that quietly makes a landlord whole from working capital has recorded no fraud anywhere. The aggregate figure for business email compromise is therefore a floor, not a measurement.

The regulatory backdrop is tightening

The Government’s Fraud Strategy 2026 to 2029 sets out a broader push against economic crime, including mandating electronic invoicing for all VAT invoices from April 2029 with a roadmap due at Budget 2026. That will eventually remove the emailed PDF invoice — the single most abused artefact in this whole category — from the process. Until then, business email compromise controls are on you.

Nine Controls That Stop Business Email Compromise

These are ordered by ratio of protection to effort. A firm that does the first four properly removes most of its exposure; the remaining five are what turn a good position into a defensible one. None of them requires a business email compromise specialist to implement.

1. Phishing-resistant multi-factor authentication

SMS and app-approval MFA both fall to adversary-in-the-middle proxies, because the user genuinely completes the challenge. Passkeys, FIDO2 security keys and Windows Hello for Business bind the authentication to the legitimate domain, so the proxy has nothing to relay. Start with finance, directors and anyone with delegated mailbox access, then extend. This is the single highest-value change available against business email compromise.

2. Conditional access and token protection

Restrict sign-in to compliant or managed devices for accounts that touch payments, and shorten session lifetimes for risky sign-ins. Token protection binds a refresh token to the device it was issued on, so a stolen token replayed elsewhere fails. Combined with sign-in risk policies, this closes most of the value of a stolen session.

3. Alert on inbox rules and forwarding

Every mailbox rule that moves, deletes or forwards mail should generate an alert to someone who will act on it. Disable automatic external forwarding tenant-wide unless there is a documented exception. This is the detection that most reliably catches business email compromise in its reconnaissance stage, before any money moves, and it costs nothing but configuration.

4. A written bank-detail change procedure

No payee bank details change on the strength of an email, ever. The change is verified by telephone on a number held in the system before the request arrived, made by a second person, logged with the date, time, number called and name of the person spoken to, and the payee record is updated by someone who cannot approve payments. Write it down, put it in induction, and audit it quarterly.

5. Dual authorisation on the payment run

Separate the person who maintains payee records from the person who releases payments, and require two approvers above a threshold — many firms use £5,000, some go lower. Where the same two people always approve, rotate. The control is worthless if the second approver clicks through without looking, so make the payee-change report the thing they actually review — that report is where a business email compromise becomes visible.

6. Confirmation of Payee and a test payment

Confirmation of Payee checks the account name against the sort code and account number before a payment is sent, returning a full match, close match, no match or unable to check. Treat anything other than a full match as a stop. For new or changed payees above a threshold, send £1 first and have the payee confirm receipt with the reference you chose, not one they suggest.

7. Impersonation protection and external tagging

In Microsoft 365, anti-phishing policies in Defender for Office 365 offer user and domain impersonation protection, mailbox intelligence and a first-contact safety tip that flags senders you rarely hear from. Protect your directors and your busiest landlord and supplier domains explicitly. Add an external sender banner, and configure it so it is not so ubiquitous that staff stop seeing it.

8. Enforced SPF, DKIM and DMARC

Publish SPF and DKIM for every domain you send from, including marketing and portal platforms, then move DMARC to a reject policy. This does not stop a genuine compromised mailbox, but it stops others impersonating your domain to your landlords and tenants — the variant where your brand is the weapon and your clients pay. Watch the reports for a month before enforcing.

9. Same-day reconciliation and payee-change reporting

Run a report of every payee bank detail changed in the last seven days and review it weekly. Reconcile remittances the day they go out rather than at month end. Shortening the discovery window from four weeks to four days changes the recovery odds materially, because funds recalled within hours are sometimes still there. Most business email compromise losses become permanent through delay, not through sophistication.

ControlTypical costEffort to deployStops which stage
Phishing-resistant MFA£20 to £45 per key, one-offMedium1 — access
Conditional access and token protectionIncluded in Business PremiumMedium1 — access
Inbox rule alertingConfiguration onlyLow2 — reconnaissance
Bank-detail change procedureStaff time onlyLow3 — the switch
Dual authorisationStaff time onlyLow4 — payment
Confirmation of Payee and test paymentUsually free with the accountLow4 — payment
Impersonation protectionIncluded in Business PremiumLow3 — the switch
DMARC at reject£0 to £2,000 with toolingMedium3 — the switch
Same-day reconciliationStaff time onlyMedium5 — recovery window

The Human Layer: Scripts, Permission and the Awkward Phone Call

Technology narrows the attack surface; people close it. Every business email compromise that succeeds passes through a moment when somebody could have picked up the phone and did not.

Give staff a script, not a warning

“Be vigilant” is not a control. A script is. Something like: “Thanks — before I can change those details I need to verify them on the number we hold. I’ll call you back on that number now.” It is polite, it is standard practice across the industry, and it works equally well whether the person on the other end is a genuine landlord or a criminal. Print it. Put it beside the phone. A script beats awareness training at stopping a business email compromise every time.

Make stopping a payment career-safe

The most under-rated control in any firm is whether a junior member of staff genuinely believes they can halt a payment run without being blamed for the delay. If the culture punishes friction, the control fails silently. Say explicitly, in writing and from the top, that no one will ever be criticised for pausing a payment to verify it, and mean it the first time somebody stops a legitimate one. Firms that get this wrong discover it only after a business email compromise succeeds.

Train on your own scenarios

Generic phishing training does not prepare a property manager for a mid-thread reply from a landlord they have emailed for years. Build simulations from your own workflows: a remittance query, a contractor invoice for a real block, a deposit return. Measure whether people call, not whether they click, because a business email compromise rarely contains anything to click on. Firms that also pursue Cyber Essentials certification get a useful external checkpoint on the technical half of this.

Remember the parties outside your walls

Landlords, leaseholders and contractors are part of your attack surface and receive none of your training. Send a short annual note explaining that your bank details never change by email, that you will always verify theirs by phone, and giving the number to call. It costs one email a year and removes the plausibility every business email compromise depends on.

The First 24 Hours After a Business Email Compromise

Speed determines outcome. Write this down before you need it, because nobody composes a good business email compromise plan at 4:40pm on a Friday. Our guide to writing a business email compromise playbook covers the roles, severity tiers and message templates that belong in that document.

Hour zero to one: the bank

Telephone the bank’s fraud line immediately and request a recall of the payment. Do not email. Get a reference number. Ask the bank to contact the receiving bank directly — that is the step that occasionally recovers funds after a business email compromise, and every minute reduces the odds.

Hour one to four: contain the mailbox

Assume the mailbox is still compromised. Revoke active sessions and refresh tokens rather than only resetting the password, because a stolen token survives a password change. Our Microsoft 365 business email compromise response plan sets out that containment sequence tenant by tenant. Remove any attacker-created inbox rules and forwarding, re-register multi-factor authentication, and check delegate and mailbox permissions. Preserve evidence — do not delete the fraudulent emails.

Hour four to twenty-four: scope, report, notify

Pull the audit log and establish what was accessed and when, which is what tells you whether this is a payment incident or also a personal data breach. Report to Action Fraud and to your insurer within the policy’s notification window. If personal data was likely exposed, start the 72-hour clock for the Information Commissioner’s Office. Tell the affected landlord, leaseholder or tenant directly and early — they will find out anyway, and hearing it from you is the only version of that conversation that preserves the relationship.

WindowActionOwner
0 to 60 minutesBank fraud line, recall request, reference numberFinance lead
1 to 4 hoursRevoke sessions and tokens, strip inbox rulesIT provider
4 to 12 hoursAudit log review, scope of mailbox accessIT provider
4 to 24 hoursNotify insurer, report to Action FraudDirector
Within 72 hoursICO report if personal data was likely exposedCompliance lead
Day 2 to 5Client communication, payee record re-verificationProperty manager

A 90-Day Business Email Compromise Plan for Property Firms

Nobody implements nine controls at once. This sequence front-loads the cheap, high-impact items and leaves the projects for last, and it assumes a firm with no prior business email compromise work behind it.

Days 1 to 30: close the obvious gaps

Turn on inbox rule and forwarding alerts. Disable automatic external forwarding. Write the bank-detail change procedure and brief everyone who touches payments. Enable Confirmation of Payee checks in your banking platform and agree a threshold for test payments. Send the annual note to landlords and contractors. None of this needs budget approval, and together these items remove the two stages a business email compromise cannot skip.

Days 31 to 60: harden identity

Roll out phishing-resistant multi-factor authentication to finance, directors and anyone with delegated mailbox access. Configure conditional access for payment-touching accounts. Enable impersonation protection for your directors and your top twenty landlord and supplier domains. Introduce dual authorisation above your chosen threshold, and start the weekly payee-change report.

Days 61 to 90: prove it works

Move DMARC to reject after a month of monitoring. Run a targeted simulation built from your own workflows. Rehearse the first 24 hours as a tabletop exercise with your IT provider in the room. Review your crime and cyber policy wording for social engineering cover, and confirm in writing with your provider who is monitoring the identity alerts out of hours, because a business email compromise is timed for precisely those gaps. Firms without in-house capacity usually fold this into a managed IT services arrangement rather than hiring for it.

PhaseFocusBudget neededExposure removed
Days 1 to 30Process and detectionNoneStages 2 and 3
Days 31 to 60Identity and authorisationLow — keys and timeStages 1 and 4
Days 61 to 90Assurance and rehearsalLow to moderateStage 5 and recovery

Frequently Asked Questions About Business Email Compromise

Will our bank refund us if we are tricked into paying a criminal?

Only if you qualify as a consumer, micro-enterprise or small charity under the reimbursement rules that took effect on 7 October 2024. Most property management companies with more than nine employees do not, so a business email compromise loss is recovered only if you call fast and the funds are still in the receiving account.

Does multi-factor authentication stop this?

It stops password-only attacks and it is essential, but app-approval and SMS codes do not stop adversary-in-the-middle phishing, which is now the dominant route into a mailbox. Phishing-resistant methods such as passkeys and FIDO2 keys do. Treat standard MFA as the floor, not the ceiling, if business email compromise is the threat you are defending against.

Is business email compromise a reportable data breach?

The payment loss itself is not. But if the attacker had access to a mailbox holding tenant or landlord personal data, that access is a personal data breach and the 72-hour reporting duty may apply. Assume every business email compromise is reportable until your audit log review says otherwise.

Our IT is outsourced — is this their problem?

Half of it. Identity hardening, alerting and mailbox forensics belong to your provider. The bank-detail change procedure, dual authorisation and reconciliation cadence are yours, and no provider can implement them for you. Agree in writing who watches identity alerts outside office hours, because business email compromise is timed for exactly those hours.

How is this different from ordinary phishing?

Ordinary phishing wants a credential. This wants a payment. The email that costs you money in a business email compromise usually contains no link and no attachment at all, which is precisely why filtering alone never catches it.

What is the single cheapest thing we can do this week?

Turn on alerting for mailbox rule creation and external forwarding, and ban bank-detail changes by email in writing. Neither costs anything, and together they break the two stages the fraud cannot skip.

References