Business Email Compromise: Fake Boss and Fake Supplier Payment Requests
Updated 2026-08-20
Business Email Compromise (BEC) is a scam aimed at businesses and organizations rather than individuals. But if you handle payments, invoices, or approvals at work, even a small business or NGO, you are a target. The scammer impersonates someone you trust, such as your boss, a supplier, or a colleague, by email, and asks you to send money or change payment details.
How it works
- The fake boss request. An email arrives that looks like it's from your manager or company director, often from a slightly altered address (an extra letter, a different domain ending), urgently asking you to make a payment or buy gift cards "before a meeting," stressing secrecy or urgency throughout.
- The hijacked supplier invoice. A supplier's real email account gets hacked, or their domain is closely copied, and an "updated" invoice arrives with new bank details, routing a legitimate payment straight to the scammer's account instead.
- The fake new employee or payroll change. An email pretending to be from HR or a staff member asks payroll to redirect a salary payment to a "new" bank account.
- Compromised email threads. Sometimes scammers have actually broken into a real mailbox and reply inside a genuine, ongoing conversation, making the request look completely legitimate because it matches real context, names, and past messages.
Warning signs
- Unusual urgency, secrecy, or pressure to bypass the normal approval process ("don't call me, I'm in a meeting, just send it").
- A request to change bank account details for an existing supplier or employee, especially if it arrives only by email.
- Slight differences in an email address or domain name compared to the real one (check the full address, not just the display name).
- A change in writing style, tone, or grammar compared to how that person normally writes.
- Requests to pay via gift cards, cryptocurrency, or an unfamiliar account. Legitimate businesses rarely ask for these.
How to protect your business
- Always verify payment or bank-detail changes by phone, using a number you already have on file. Never use a number provided in the same suspicious email.
- Set a rule that large or unusual payments need a second person's sign-off, done through a separate channel than email.
- Check the sender's full email address, not just the name shown, before acting on any financial request.
- Be extra cautious around anything urgent, secret, or outside the normal process. These pressure tactics are the biggest tell.
- Use unique, strong passwords and two-factor authentication on all business email accounts to make them harder to hijack in the first place.
If a fraudulent payment has already been sent
- Contact your bank or mobile money provider immediately. The faster you act, the higher the chance of stopping or reversing the transfer.
- Notify your organization's leadership and IT/finance contacts right away.
- Report the incident to the Uganda Police Cyber Crime Unit.
- Preserve the original emails (including full headers) as evidence. Don't delete anything.