Online Safety

Business Email Compromise: Fake Boss and Fake Supplier Payment Requests

Updated 2026-08-20

Business Email Compromise (BEC) is a scam aimed at businesses and organizations rather than individuals. But if you handle payments, invoices, or approvals at work, even a small business or NGO, you are a target. The scammer impersonates someone you trust, such as your boss, a supplier, or a colleague, by email, and asks you to send money or change payment details.

How it works

  • The fake boss request. An email arrives that looks like it's from your manager or company director, often from a slightly altered address (an extra letter, a different domain ending), urgently asking you to make a payment or buy gift cards "before a meeting," stressing secrecy or urgency throughout.
  • The hijacked supplier invoice. A supplier's real email account gets hacked, or their domain is closely copied, and an "updated" invoice arrives with new bank details, routing a legitimate payment straight to the scammer's account instead.
  • The fake new employee or payroll change. An email pretending to be from HR or a staff member asks payroll to redirect a salary payment to a "new" bank account.
  • Compromised email threads. Sometimes scammers have actually broken into a real mailbox and reply inside a genuine, ongoing conversation, making the request look completely legitimate because it matches real context, names, and past messages.

Warning signs

  • Unusual urgency, secrecy, or pressure to bypass the normal approval process ("don't call me, I'm in a meeting, just send it").
  • A request to change bank account details for an existing supplier or employee, especially if it arrives only by email.
  • Slight differences in an email address or domain name compared to the real one (check the full address, not just the display name).
  • A change in writing style, tone, or grammar compared to how that person normally writes.
  • Requests to pay via gift cards, cryptocurrency, or an unfamiliar account. Legitimate businesses rarely ask for these.

How to protect your business

  • Always verify payment or bank-detail changes by phone, using a number you already have on file. Never use a number provided in the same suspicious email.
  • Set a rule that large or unusual payments need a second person's sign-off, done through a separate channel than email.
  • Check the sender's full email address, not just the name shown, before acting on any financial request.
  • Be extra cautious around anything urgent, secret, or outside the normal process. These pressure tactics are the biggest tell.
  • Use unique, strong passwords and two-factor authentication on all business email accounts to make them harder to hijack in the first place.

If a fraudulent payment has already been sent

  1. Contact your bank or mobile money provider immediately. The faster you act, the higher the chance of stopping or reversing the transfer.
  2. Notify your organization's leadership and IT/finance contacts right away.
  3. Report the incident to the Uganda Police Cyber Crime Unit.
  4. Preserve the original emails (including full headers) as evidence. Don't delete anything.