Business Email Compromise (BEC) fraud continues to be one of the most damaging cyber threats facing organizations today.
According to the FBI’s Internet Crime Complaint Center (IC3), reported cybercrime losses exceeded $20 billion in 2025, with BEC schemes accounting for more than $3 billion in financial losses, making it one of the costliest forms of cybercrime. Fraud involving wire transfers and ACH payments was responsible for nearly 86% of the funds lost through these attacks.
“Companies like ours encounter these scam emails, but we are trained to handle them effectively,” says John Feaman, IPS President.
Cybercriminals may send emails that appear to come from a trusted source and direct recipients to a fake login page for their email provider. Once credentials are compromised, attackers can access company email accounts and initiate seemingly legitimate communications.
One of the most common BEC schemes involves criminals requesting a change for an employee’s direct deposit information. If processed without proper verification, payroll funds can be redirected to accounts controlled by fraudsters, often making recovery difficult.
“Preventing payroll fraud starts with verifying every request,” adds Feaman. “Even when an email appears legitimate, it’s important to confirm sensitive changes directly with the employee. Our team is committed to maintaining secure payroll practices and adheres to strict protocols whenever direct deposit or payroll information is updated.”
To reduce risk, organizations should:
- Establish clear procedures for handling payroll and banking changes, including multi-factor authentication, independent verification of requests, and ongoing employee cybersecurity training.
- Ensure that employees regularly review their bank accounts and pay statements to quickly identify missing deposits or unauthorized changes.
For more information on effective strategies to combat payroll fraud and protect your organization from business email compromise attacks, contact your IPS representative.
