← Back to Blog Cybersecurity

Business Email Compromise: The Silent Profit Killer for South African SMBs

Published: 16 June 2026 | Updated: 20 July 2026 | CT Bedfordview

While ransomware makes headlines, a far more damaging and insidious threat is quietly draining bank accounts across Gauteng: Business Email Compromise (BEC).

Business email compromise warning on laptop showing fraudulent email

Unlike ransomware, BEC rarely triggers alarms or encrypts files. It works by deception. Criminals impersonate suppliers, executives, or trusted partners to trick employees into making fraudulent payments or disclosing sensitive information. In South Africa, these attacks have become one of the most expensive cyber threats facing small and medium businesses.

According to South African Police Service reports and banking sector data, BEC losses in South Africa now run into hundreds of millions of rand annually. Many incidents go unreported because companies feel embarrassed or fear reputational damage under POPIA.

Why South African SMBs Are Perfect Targets

Several local conditions make BEC particularly effective here:

In our work with Bedfordview and Germiston clients, we regularly see the same pattern: a well-crafted email that looks almost identical to normal supplier correspondence, only the banking details have been changed.

Real-World Impact

A typical BEC attack on a 25–80 employee company in Gauteng often results in losses between R180,000 and R1.2 million. One East Rand manufacturing client lost R874,000 in a single transaction after an attacker compromised a supplier's email and sent "updated banking details" for an upcoming large payment.

Even worse, many companies only discover the fraud weeks later when the real supplier follows up on the unpaid invoice. By then, recovery is extremely difficult. The Banking Association South Africa reports that less than 50% of BEC losses are ever recovered.

BEC attacks often follow a broader pattern of email security threats including phishing, and the same defences that protect against phishing — staff training, email filtering, and MFA — are your first line of defence against BEC.

Practical Defences That Actually Work

  1. Implement strict payment verification procedures. Never accept changed banking details via email alone. Always verify changes by phone using a number you have independently looked up — not a number provided in the suspicious email.
  2. Enable multi-factor authentication everywhere, particularly on Microsoft 365. Compromised email accounts are the most common entry point for BEC attacks.
  3. Use invoice approval workflows. Any payment above R50,000 should require dual approval. Implement a "three-way match" — purchase order vs goods receipt vs invoice — before any payment is processed.
  4. Deploy modern email security tools that detect domain impersonation. Solutions like Microsoft Defender for Office 365 can flag emails that spoof your domain or supplier domains.
  5. Train staff to recognise urgency as a red flag. Legitimate suppliers rarely demand immediate payment changes on a Friday afternoon. Create a culture where staff are rewarded for questioning suspicious requests.

The Strategic View

The most mature businesses in the East Rand no longer treat BEC as an "IT problem." They treat it as a financial control and business process risk. This means involving your finance team in security decisions, implementing segregation of duties in payment processing, and reviewing supplier payment processes for vulnerabilities.

Adding further protection, the principles of strong password security and multi-factor authentication are directly applicable — a compromised password can give attackers access to your email system, enabling a devastating BEC attack that bypasses all other controls.

BEC FAQ

Q: How do attackers find out who my suppliers are?

A: Attackers research businesses through publicly available information — your website lists suppliers, your staff post on LinkedIn about projects and partnerships, or they compromise a supplier's email system first. Once they know who you work with, they craft emails that look like they come from those suppliers. This is why verifying payment changes through a separate, trusted channel is so important.

Q: Does cyber insurance cover BEC losses?

A: Many cyber insurance policies cover BEC losses, but coverage varies significantly. Some policies specifically exclude social engineering fraud. Others require specific controls to be in place — like dual approval for payments and MFA on all email accounts — as a condition of coverage. We recommend reviewing your policy carefully with your broker and ensuring you meet all the conditions.

Take Control Before the Next Attack

If your business regularly makes payments to suppliers, the question is not whether you will be targeted, but when.

Contact CT Bedfordview for a confidential Business Email Compromise risk assessment. We'll show you exactly where your business is vulnerable — and how to fix it before attackers exploit it.