Risk in Plain Language
Real-World StoriesPart 2 of 5

The Email That Cost Everything

Business email compromise is the most financially damaging cybercrime category in the US. Here is how it actually happens, who it happens to, and what would have stopped it.

6 min read

Most people picture a cyberattack as something dramatic: alarms going off, screens going dark, servers exploding in a Hollywood data center. The attack that is actually devastating small businesses and nonprofits right now looks nothing like that.

It looks like an email.

It arrives in a normal inbox. It uses the right name, the right tone, sometimes even the right email address. It asks for something that, on its own, does not seem unreasonable. And by the time anyone realizes what happened, the money is gone.

This is business email compromise, or BEC. According to the FBI's 2024 Internet Crime Report, it generated $2.77 billion in reported US losses in a single year, making it the most financially damaging cybercrime category in the country. The average wire transfer request in early 2025 was $24,586. And only about 25 cents on the dollar is ever recovered.

The three incidents below are real. The organizations are not named to protect them, but the attack mechanics, the dollar amounts, and the outcomes are drawn directly from documented cases and verified public reporting. If you read these and think "that would never happen here," that is exactly the response these attacks are designed to produce.

$2.77B BEC losses reported to the FBI in 2024
73% of all reported cyber incidents involve email compromise
37% surge in BEC attacks from May 2024 to June 2025

Three incidents. Three organizations that thought it would not happen to them.

Incident 1

The nonprofit that lost $1 million to a phishing email

Regional food bank / human services organization
Loss: $1,000,000

Philabundance, a Philadelphia food bank, lost $1 million in a sophisticated phishing attack. A cybercriminal impersonated a contractor the organization had an existing relationship with. The fraudulent emails were convincing enough that finance staff redirected a large payment to an account controlled by the attacker.

The money moved before anyone identified the discrepancy. By the time the fraud was discovered, the funds had been transferred multiple times and were effectively unrecoverable. A food bank built to serve people facing hunger lost a seven-figure sum that had been designated for exactly that work.

This is not an isolated case. A security expert quoted in recent reporting described seeing "a pretty significant rise in nonprofits being targeted" because most nonprofits are required to post their financial disclosures online. Form 990 reports are public record. A motivated attacker can quickly identify which organizations are holding substantial assets without doing any technical work at all.

What would have stopped this

A single out-of-band verification step: before any payment is redirected to new banking details, a staff member calls the vendor directly using a phone number from the organization's own records, not a number provided in the email. That phone call takes two minutes. It would have cost this organization nothing.

Incident 2

The town that lost half a million dollars to a hijacked invoice thread

Municipal government / public-sector organization
Loss: ~$500,000

In June 2024, the Town of Arlington, Massachusetts lost nearly half a million dollars when attackers hijacked an active construction invoice thread. The attackers inserted themselves into an existing email conversation, impersonated the vendor, and redirected four payments in sequence.

Because the emails appeared within the legitimate thread, they carried the implicit credibility of the prior conversation. Staff had no reason to question the payment details. Four transactions went through before the fraud was detected.

This variant of BEC, sometimes called vendor email compromise or VEC, is rising fast. Reports show VEC attacks increased 66% in the first half of 2024. Attackers are increasingly targeting not just executives inside an organization, but trusted vendor relationships that employees have been conditioned to trust over time.

What would have stopped this

A written policy requiring independent verification of any banking detail change, regardless of how the request arrives or who it appears to come from. Even a simple internal rule, "we call to confirm all new payment instructions before processing," breaks this attack every time.

Incident 3

The small business that paid the same invoice twice

Professional services firm / small business
Loss: $90,000

A California accounting firm suffered a $90,000 loss when an attacker spoofed a vendor's email address. The fraudulent invoice matched the vendor's prior formatting exactly, used the correct vendor name, and referenced a real services relationship. Staff paid the invoice without question because everything about it looked right.

The firm then still owed the actual vendor the same amount. They paid the same bill twice and had to cover the loss out of pocket. The real vendor was never involved and had no idea their identity had been used. There was no breach of the vendor's systems; the attacker simply sent an email from an address that looked close enough to the real one.

This is the low end of the BEC cost spectrum, and it is devastating for a small firm. At $90,000, a loss like this is the equivalent of several months of revenue for many professional services businesses. For some, it is existential.

What would have stopped this

Training staff to look at the actual sender domain, not just the display name. The display name can say anything. The underlying email address is where spoofing shows up. "Acme Consulting" displayed as the sender name can be sent from acme-consulting-invoicing.ru. One second of scrutiny on the actual address would have flagged this immediately.

The pattern is the same in every case

Read those three incidents and you will notice they share a structure. None of them required sophisticated hacking. None involved zero-day exploits or compromised servers. Each one exploited something simpler: a human being in a normal workflow, processing a request that looked like it fit.

The attacker did research. They identified a real relationship, a real vendor, a real transaction pattern. They timed the contact to a moment when it would seem plausible. They created just enough urgency to short-circuit the instinct to double-check.

The honest truth: These attacks work because organizations have not built the habit of verifying payment instructions through a second channel. Not because employees are foolish. Not because the organization lacks technology. Because there was no policy, and no one had been told what to look for.

That is a problem you can fix without buying anything.

Three things every organization should do this week

You do not need a security team or a budget to start addressing this risk. You need a decision and a conversation.

  • Establish a verbal confirmation rule for all wire transfers and payment detail changes. Any email requesting a new bank account, a change to existing payment instructions, or a wire transfer over a threshold you define requires a phone call to confirm using a number you already have on file. Put this in writing, even if it is just an email to your team.
  • Show your team how to check the actual sender email address. Most email clients display a name, not the address. Teach everyone to click or hover to see the real address. Spend five minutes on this in your next staff meeting. It is one of the highest-return training investments that exists.
  • Enable multi-factor authentication on all email accounts. Many BEC attacks begin with a compromised email account. If an attacker has your staff member's email password, MFA is the barrier between reconnaissance and a realistic impersonation. Most email platforms offer this at no additional cost.
For nonprofit leaders specifically: Your Form 990 is public. Your leadership names and titles are public. Your major funders are often public. Attackers use this information to craft targeted requests that reference real people, real relationships, and real dollar amounts. The attack against your organization does not start with a guess. It starts with a Google search.

The incidents that do not get reported

The numbers above are striking, but they represent only what organizations actually report to the FBI. Researchers estimate the real losses could be three times higher. Many organizations absorb a BEC loss quietly, without filing a complaint, because they are embarrassed, because they do not think reporting will help recover the money, or because they want to avoid the reputational exposure of publicizing that a staff member was deceived.

That silence means the organizations around them never learn what happened. It means the same attack works again at the next organization with the same gaps. And it means the true scale of this problem is almost certainly larger than any publicly available figure captures.

The most useful thing any organization can take from these incidents is not fear. It is clarity: these attacks succeed because of specific, addressable gaps in process and awareness. The organizations that do not become the next story are not the ones with the biggest security budgets. They are the ones that built a habit of pausing before sending money.

Not sure what your actual exposure looks like?

A 30-day Security Business Review identifies your highest-priority gaps and gives you a practical roadmap you can act on. No enterprise complexity. No vendor pitches.

Start a Conversation
Business Email Compromise Real-World Incidents Nonprofit Security Small Business Phishing Wire Fraud