“Please pay this urgently, I’m in a meeting and can’t talk” — if your company’s accountant has ever received a message like this, they’re not alone. It’s one of the most profitable types of fraud in the world: Business Email Compromise (BEC). Scammers don’t hack a bank or steal a card — they simply convince someone with access to company funds to transfer the money themselves.
Why accounting teams are the main target?
An accountant or finance lead is, by the nature of their role, expected to respond quickly to payment requests from leadership. That exact trait is what gets exploited — scammers aren’t breaking through security, they’re exploiting a workflow.
How the attack typically unfolds?
The scammer gathers publicly available information about the company — website, social media, LinkedIn — to learn the director’s name, company structure, and communication style.
An email address is created that closely resembles the real director’s address: one letter changed ([email protected] → [email protected]), or a similar-looking domain used instead (.com instead of .kg, an extra letter in the name).
The email is sent to the accountant at a moment when the director is plausibly hard to reach quickly: “I’m on a flight,” “in a meeting,” “unreachable until tonight.”
The message contains an urgent request to pay a “new vendor’s” invoice or to change the payment details for an existing one.
The tone mimics the real executive’s writing style — sometimes based on previously leaked correspondence the scammer has studied.
Red flags to watch for
- A combination of urgency and secrecy — “pay now, don’t mention it to anyone yet”
- A change in payment details arriving exactly at the moment of an urgent request
- A request to skip the normal approval process “just this once”
- Small discrepancies in the sender’s address that are easy to miss at a glance
- Emotional pressure — urgency, fear of letting the boss down, eagerness to help
What to do if you receive an email like this?
Never confirm a payment or a change in payment details based on an email alone — use a second communication channel: call the director on a number you already know, not one listed in the email
Don’t rush — a genuine request will hold up to a 10–15 minute check; a fraudulent one usually relies on there being no time for that
Check the actual sender address, not just the display name — hover over the email to see the full address
Establish a simple company rule: any change to payment details requires confirmation from a second employee, no exceptions
Why this isn’t about distrusting the director?
The second-channel rule isn’t about the accountant distrusting leadership. It’s a standard process safeguard that works the same way for everyone — including cases where the request really is from the director, but their own email account has been compromised.
These attacks fit into a broader pattern: according to Verizon’s DBIR, the human element is involved in 62–68% of all breaches. The encouraging part is that this specific type of risk isn’t reduced by technology — it’s reduced by a simple, clear internal process.