How Does Business Email Compromise Actually Happen?
September 16, 2026
From the first phishing page to the fraudulent invoice: the real kill chain behind a business email compromise, stage by stage.
Business email compromise looks like a single event to the victim — a bad invoice — but it is the last step of a patient process.
Stage 1: reconnaissance
The attacker maps the org from public sources: who approves payments, who reports to whom, who the suppliers are, when leadership travels. Nothing illegal happens yet.
Stage 2: access
Three common routes. A phishing page that harvests the password. An adversary-in-the-middle page that captures the session token and therefore defeats app-based MFA. Or credential reuse, where a password leaked elsewhere still works on your tenant.
Stage 3: persistence
Once inside, the attacker makes sure a password reset will not cost them access: an OAuth consent grant, an app password, their own MFA method, or mailbox delegation.
Stage 4: quiet observation
Days to weeks of reading. Learning your invoice format, your approval language, your payment cycle, the phrases your CFO uses. Meanwhile a hidden rule keeps the eventual fraud thread out of the owner's sight.
Stage 5: the pivot
Either they hijack an existing thread and reply with new bank details, or they register a lookalike domain and move the conversation off your tenant so containment does not interrupt them. Internal phishing from the trusted mailbox is a common side quest, expanding access before the payday.
Stage 6: the ask, and the exit
A precisely timed payment instruction. Once the money lands, it is dispersed within a day or two, which is why the recovery window is measured in hours.
Where to break the chain
Phishing-resistant MFA breaks stage 2. Alerting on consent grants and forwarding rules breaks stages 3 and 4. Out-of-band payment verification breaks stage 6 even when everything else failed. Defence in depth here is not a slogan — each layer catches a different stage. Our managed detection and response service is built around the middle stages, where dwell time makes detection possible.
Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.