Skip to main content
FMB Logo Header Desktop
Scroll To Top

NEWS

Thursday, September 10, 2026

Imagine this, you’re a business owner who just received an email from a vendor—from an email that, at a glance, looks like the vendor’s usual email address—asking if you received their verification request, and informing you that they can’t process checks right now, could you pay them using ACH instead? The thing is, you already sent the payment via check. You tell the vendor this, and they ask if you could cancel the check—after all, they can’t process checks right now, remember?

You want to be a good partner, and want people to be paid for their services, so you agree to a one-time ACH payment. The vendor gives you the necessary information, and you send an ACH payment for more than $30,000.

A month later, the vendor reaches out—they never received the check payment, or any payment at all. But…you paid them, right? You go back to the email exchange, and realize that the person you spoke to last month used the same email address as the vendor, but it ended in .us, instead of the vendor’s official .com address. You reach out to the receiving bank to see if you can get your money back, but it’s already too late.

This scenario is based on a real customer story involving Business Email Compromise (BEC), and it could happen to you. Anyone can fall victim to a scam.

So, how does this scam work? Here are the strategies Business Email Compromise scammers use to lull their targets into a false sense of security:

  1. Impersonation and spoofing
    The scammer pretends to be a known vendor and uses an email that is extremely similar to the real vendor’s email to make their request seem legitimate.
  2. Creating a believable business reason
    The scammer opens the conversation asking for verification and then creates a reason that traditional payment methods could not be used. This makes an unusual request seem routine and believable.
  3. Social engineering
    By saying they can’t process checks at the moment, the scammer makes the business owner feel a desire to help out a trusted vendor—an example of social engineering.
  4. Stopping an existing payment
    The business owner is told to cancel an existing check that was in the mail and send the ACH payment instead.
  5. Giving an alternate payment method
    The scammer provides details to a legitimate bank account—making the request seem even more believable. Scammers prefer ACH and other electronic payment methods because money can be moved or withdrawn more quickly and the money is harder to recover.

So how can you protect yourself, or your business, from potential Business Email Compromise scams? Here are a few tips to remember:

  • Always call a vendor to verbally confirm change requests
  • Carefully check email addresses on emails requesting payment change requests
  • Use a service like Positive Pay to track and approve checks and ACH payments
  • Check your accounts regularly to ensure all payments are up-to-date

If you or your business is a victim of business email compromise, report it immediately to your bank and to the authorities.