Business email compromise doesn't look like hacking. There's no ransomware, no dramatic breach notification. It looks like an email from your CEO asking accounts to urgently transfer funds to a new supplier. By the time anyone realises it's fraud, the money is gone.
CERT NZ's annual reports consistently identify BEC as one of the highest-financial-impact threats facing NZ businesses. Unlike mass phishing campaigns, BEC is targeted — attackers research the business, identify the right people to impersonate, and time their approach carefully.
How BEC attacks work
The mechanics vary, but the common patterns are:
CEO fraud / invoice redirection — The attacker impersonates a senior executive or a known supplier and requests a payment to a new bank account. The email looks legitimate because the attacker has done their research: they know the company's tone, who the finance contact is, and often when regular payments are due.
Account takeover — The attacker gains access to a real email account (often through a phishing attack or credential stuffing) and uses it to intercept or redirect payment requests. Because the emails come from a legitimate account, they pass spam filters and look completely genuine.
Supplier impersonation — The attacker creates a domain that looks like a real supplier (acme-nz.com instead of acme.co.nz) and sends invoices with updated bank details.
Payroll diversion — HR or payroll receives a request from an "employee" asking to update their bank account details before the next pay run.
Why NZ businesses are targeted
Small and mid-sized NZ businesses are attractive targets for several reasons:
- They often have less formal payment authorisation processes than large corporates
- Senior staff are identifiable on LinkedIn and company websites
- They frequently transact with Australian and international suppliers, making unusual payment requests less suspicious
- Response times to fraud reports are slower than in larger markets with dedicated fraud teams
The CERT NZ 2023 Annual Report reported over $6.6 million in financial losses from BEC and related scams in that year alone — and that's only the reported cases.
What makes BEC so hard to detect
Standard email security tools don't catch most BEC attacks because:
- The emails often come from legitimate accounts or convincing lookalike domains
- They don't contain malware or phishing links that would trigger filters
- They're socially engineered to match the target's normal communication patterns
- They create urgency ("I'm in a meeting, please process this immediately") that discourages double-checking
What actually stops BEC
Technical controls help but aren't sufficient on their own. The most effective defences are process-based:
Dual authorisation for payments — No single person should be able to initiate and approve a payment above a set threshold. This is the single most effective BEC control.
Out-of-band verification — Any request to change bank account details or make an unusual payment should be verified by phone (using a number from your own records, not the email) before processing. Not by reply email.
Email authentication (DMARC, DKIM, SPF) — Configure these on your domain so attackers can't easily spoof your email address. CERT NZ's DMARC guidance walks through the setup.
Domain monitoring — Know when lookalike domains are registered that could be used to impersonate your business.
Staff training — Finance, HR, and executive assistants are the highest-risk targets. They need to recognise BEC patterns and feel empowered to pause and verify — even if the request appears to come from the CEO.
Practical takeaway
Implement these controls before you need them:
- [ ] Dual authorisation on all payments above your risk threshold
- [ ] Written policy: any bank account change requires phone verification
- [ ] DMARC, DKIM, and SPF configured on your email domain
- [ ] Regular BEC awareness training for finance and HR staff
- [ ] Clear escalation path when something feels wrong — no penalty for pausing
- [ ] Incident response contact for CERT NZ: cert.govt.nz/report
Training your team
Technical controls close some gaps, but BEC targets people. Your finance and HR teams need to understand what these attacks look like and have a clear process to follow when something doesn't feel right. SecureAZ training modules cover BEC patterns, verification procedures, and real NZ case examples so your team recognises the threat before it costs you. If BEC leads to an account takeover, weak second factors are often what lets attackers persist — see SMS-Based MFA Is Not Enough for what to do about it. Start a free account to see what's included.