Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Threats
Threats

Vishing and business email compromise: when the call is from 'IT' and the invoice is real-looking

Voice phishing and email impersonation cons staff into approving payments and handing over MFA codes — the FBI's loss leader — and the defense is out-of-band verification, not better spam filters.

Brandi Reed, · June 29, 2026 · 4 min read
ShareXFacebookLinkedInTelegramEmail
Finance employee taking a suspicious urgent call about a wire transfer

Business email compromise (BEC) and its voice-based sibling vishing are cons, not hacks: an attacker impersonates a boss, vendor, or IT technician — by email, phone, or both — and talks a real employee into wiring money, buying gift cards, or reading out a multi-factor code. These schemes cause the largest direct reported losses of any internet crime category in the FBI's IC3 statistics, exceeding ransomware year after year, because they exploit trust and process rather than software. The defense that works is procedural: out-of-band verification for every payment or credential change, and a hard rule that nobody legitimate ever needs your MFA code.

How do BEC attacks work?

The classic patterns are stable:

The credential access that powers mailbox-takeover BEC comes from infostealer logs and phishing; once inside a real mailbox, the attacker reads the thread and replies within it — the reply-to address is genuine, the domain is genuine, and no filter flags it because the email is technically real.

Where does vishing come in?

Voice adds immediacy and authority. The recurring enterprise version: a caller claiming to be IT support, often referencing a real ticket or the company's actual tooling, walking an employee through "enrolling a new MFA device" — in practice approving a push prompt or generating an MFA-enrollment that hands over the second factor. Help-desk impersonation targeting password resets works the same way, exploiting the exact staff whose job is to be helpful. The AI-voice era has lowered the production cost of convincing audio — a cloned executive voice is now minutes of work, as our deepfake-call guide covers — but the core mechanics were working with ordinary human voices for years.

Why do technical defenses miss these?

Because there is nothing technical to catch. BEC emails usually come from legitimate or lookalike accounts with no malware and no malicious links; the malicious part is the payment instruction, which no scanner evaluates. Filters catch the crude lookalike domains; they cannot judge that a genuine email from a genuinely compromised vendor mailbox contains a false bank account. The controls that actually function are human-process ones: verification channels, payment thresholds, and drilled reflexes.

What protects an organization?

  1. Out-of-band verification for money and credentials: any bank-detail change, new payee, urgent wire, or MFA enrollment is confirmed through a previously known channel — call the vendor's number on file, walk to the executive's office. The callback habit alone defeats most BEC.
  2. MFA-code hygiene: a standing rule, trained until boring, that no legitimate IT, bank, or service will ever ask for a code or a prompt approval you did not initiate — and that requests to do so are reported, not complied with.
  3. Payment process friction: delays built into new-payee setups, dual approval above thresholds, and a culture where a CFO accepts "I called to verify" as praise rather than insubordination.
  4. Mailbox hardening: MFA and sign-in alerts on executive and finance mailboxes, banners on external mail, and removal of legacy protocols that bypass MFA.
  5. Rehearse it: run the scenario in training — the first time an employee hears a convincing fake-IT call should be in a drill.

What should individuals watch for?

The consumer versions arrive as bank fraud calls, fake employer onboarding, and marketplace cons: anyone creating urgency around a payment, a code, or remote access to your device. The same rules apply: hang up and call back on the number you look up; never read codes to anyone; and treat "stay on the line" as a red flag in itself. If a payment went through, the response speed decides recovery — the bank's fraud line, the FBI's IC3 at ic3.gov, and for businesses the FBI's Recovery Asset Team, which has a strong record on wire recalls when notified within days.

Frequently Asked Questions

What is vishing?
Voice phishing — a phone call impersonating IT support, a bank, or an executive to extract credentials, MFA codes, or payments. In enterprises, fake-IT calls that "help" employees approve MFA enrollments are the recurring pattern.
Why does BEC cause bigger losses than ransomware?
Per FBI IC3 statistics, business email compromise exceeds ransomware in reported direct losses every year. The scams exploit trust and payment processes rather than software, so there is no technical vulnerability to patch and no malware for filters to catch.
What single control stops most BEC?
Out-of-band verification: any bank-detail change, new payee, or urgent payment is confirmed through a known channel — a phone number on file, a walk down the hall — before money moves. The callback habit defeats the con at its only weak point.
What should I do if a wire was sent to a fraudster?
Immediately contact the sending bank's fraud line to request a recall, file with the FBI's IC3 — businesses should reference the Recovery Asset Team, which has strong results on wires reported within days — and preserve every email and phone detail.