Office employee reviewing a suspicious payment request email on a laptop to identify potential phishing and payment fraud risks.

The New Email Scam Costing Local Businesses Real Money

Post Author:

Bryan Nash

Date Posted:

September 3, 2026

Share This:

An email lands in the inbox of someone who pays your bills. It looks like it is from a vendor you have used for years, or maybe from an owner or manager on payment day, and it asks for a wire transfer or a change to banking details, right away. None of those people sent it. This is business email compromise, and across Kentucky and Southern Indiana it is quietly costing small businesses more money than almost any other type of fraud. The short version: business email compromise works by impersonating someone you already trust, not by breaking into your network, and the fix has more to do with slowing down and verifying than it does with buying new software.

What Business Email Compromise Actually Looks Like

Business email compromise starts with research, not hacking. Someone studies your company website, your LinkedIn page, and any public records to learn who signs checks, who your vendors are, and how your team talks to each other. From there, they either register a domain that looks almost like your vendor’s real one, or they get into an actual email account and wait for the right moment. Then they send a message asking for a wire transfer, a change to direct deposit, or a batch of gift cards, timed to look completely normal.

Why It Is Landing In London and Nearby Communities

Small and mid-sized businesses in London and around Kentucky and Southern Indiana are frequent targets because they often handle payables with a lean team and fewer layers of approval than a large company. That is not a criticism, it is just how efficient small businesses run, and it is exactly what makes a well-timed, well-written email so effective. The FBI’s Internet Crime Complaint Center logged more than 24,700 business email compromise complaints in 2025, totaling roughly $3.05 billion in reported losses, up from about $2.77 billion the year before, according to its annual report. Most of those cases involve exactly this kind of email, not a dramatic computer break-in.

The Warning Signs Worth Slowing Down For

A handful of details give away most of these emails before any money moves. Payment instructions that change without a phone call. Language that pushes urgency or secrecy, like asking you to skip the usual approval step “just this once.” A sender address that is close to correct but not quite right. A request that arrives right before a holiday or a weekend, when fewer people are around to double check. None of these signs require special training to spot, just a habit of pausing before you click send.

What Actually Stops It

Antivirus software will not catch business email compromise, because there is nothing malicious to scan, just a convincing message. What works instead is a callback policy: any request to change payment details or send a wire gets confirmed by phone, using a number you already have on file, not one in the email. Dual approval on outgoing wires helps too, along with basic email authentication checks that confirm a message actually came from the domain it claims to be from. Ongoing IT security monitoring and straightforward staff training round it out, and a managed IT provider can put most of this in place without adding much to anyone’s daily workload. If your business still calls someone only when something breaks, this is one more reason a steadier managed IT approach tends to catch problems like this one earlier than a break-fix setup does.

Here is the honest trade-off: a callback policy adds a few minutes to something that used to be a single click, and busy teams will feel that friction at first. That is a fair price for not wiring six figures to a stranger, but it is worth saying plainly instead of pretending the extra step is free.

What To Do If Your Team Already Clicked

Contact your bank immediately and ask about a wire recall, since minutes matter in the first hour after a fraudulent transfer. Loop in your IT support so they can check for any related account compromise. Report the incident and file a report with IC3. None of this requires embarrassment, since this scam is built specifically to fool careful people, and reporting it quickly gives your bank and investigators the best shot at recovering funds.

Kentucky and Southern Indiana businesses have leaned on the same idea since 1959: know your systems and know who you are dealing with before money changes hands. That habit still holds up, even against a scam that only started showing up in inboxes in the last few years. If you want a second set of eyes on how your team currently verifies payment requests, request a quote and someone will walk through it with you.

Frequently Asked Questions

What is business email compromise?

Business email compromise is a scam where someone impersonates a vendor, executive, or bank contact by email to trick your business into sending a wire transfer, gift cards, or updated banking details to the wrong place. It does not require hacking your network, just a convincing message sent at the right moment.

How can I tell if a payment request email is fake?

Look for payment instructions that change without a phone call, urgent or secretive language, a sender address that is close to correct but not exact, and requests that arrive right before a weekend or holiday. When in doubt, call the person using a number you already have on file, not one from the email.

Can antivirus software stop business email compromise?

Not on its own. These emails do not contain viruses or malicious attachments, so antivirus software has nothing to catch. What works better is a callback verification policy, dual approval on outgoing wires, and basic email authentication checks that confirm a message actually came from the domain it claims.

What should we do if someone already sent a payment based on one of these emails?

Call your bank right away and ask about a wire recall, since the first hour matters most. Loop in your IT support to check for any related account compromise, and report the incident to the FBI's Internet Crime Complaint Center. Acting quickly gives you the best chance of recovering the funds.

Does Duplicator Sales & Service help protect against it?

Yes. Duplicator Sales & Service has worked with businesses across Kentucky and Southern Indiana since 1959, and that includes setting up email authentication checks, staff training, and payment verification habits that make this scam much harder to pull off. Request a quote to see whether this fits how your team works.

post contents

Get the latest news & updates

subscribe to our newsletter