September 26, 2026
The ₹2.16 Crore Email That Almost Cost a Company Everything: Inside a Business Email Compromise
No malware. No hacking of your bank. Just one convincing email asking to change a payment. This is how companies lose crores, and how one…
By Drivesyncinfotechpvtltd
5 min read
No malware. No hacking of your bank. Just one convincing email asking to change a payment. This is how companies lose crores, and how one got it all back.
A Drivesync Infotech case study on Business Email Compromise, the quiet giant of corporate cyber fraud.
There was nothing dramatic about the email.
It looked like a normal message from a known business contact, about a payment that was genuinely due. The only new detail was a small one. The bank account for the payment had changed. Please use the updated details for this invoice.
In a busy finance department, this happens all the time. The payment was processed. More than two crore rupees left the company for what everyone believed was a trusted supplier.
Except the email was fake, and the money was gone.
This is Business Email Compromise, or BEC. It rarely makes headlines the way dramatic hacks do, yet it quietly causes some of the largest financial losses in corporate cyber fraud. In one documented case, a pharmaceutical company nearly lost about 2.16 crore rupees this way, and remarkably, recovered the entire amount. The difference between total loss and full recovery came down to one thing, which we will get to.
Let us understand how BEC works, and why it is so dangerous.
What Business Email Compromise Really Is
BEC is a scam that targets organisations by exploiting business email and the trust that flows through it.
There is often no malware and no obvious break in. Instead, the criminal either takes over or convincingly imitates a trusted email account, and uses it to trick an employee into sending money or sensitive information.
It does not attack your technology. It attacks your processes and your people. And because the request comes from a familiar name about a normal business matter, it slips past defences that would stop an obvious hack.
Stage One: The Watching
A good BEC attack begins quietly, with research.
The criminals study the target. They learn who handles payments, who approves them, and which suppliers or executives are involved. If they have compromised an email account, they may sit silently inside it for days or weeks, reading conversations, learning the language people use, and noting when big payments are due.
By the time they act, they know exactly who to imitate, who to target, and what a normal request looks like. That is what makes their fake so convincing.
Stage Two: The Disguise
There are two main ways the criminal wears a trusted identity.
- Account takeover. They gain access to a real email account, often through a stolen password or phishing, and send the fraudulent request from the genuine address.
- Look alike domains. They register an email address that looks almost identical to the real one, with a tiny change most people never notice, and send from there.
Either way, the message appears to come from someone the target already trusts. A senior executive, a regular vendor, or a professional partner.
Stage Three: The Request
Now comes the ask, and it is almost always about money or a change to where money goes.
Common versions include:
- A supplier saying their bank account has changed, please update it for the next payment.
- A senior executive urgently instructing a finance staff member to make a payment quietly and quickly.
- A fake invoice that matches a real, expected one.
The request is designed to feel routine, urgent, or both. Urgency discourages double checking. Routine discourages suspicion. Together they get the payment approved.
Press enter or click to view image in full size
Stage Four: The Payment and the Escape
The employee, believing the request is genuine, sends the money to the account provided. It goes straight to an account the criminals control.
From there, the familiar laundering process begins. The money is quickly moved through other accounts, split, and converted, so that even when the fraud is discovered, tracing and recovering it becomes hard.
Unless, that is, the alarm is raised fast.
The Save: Why This Company Got Its Money Back
In the documented pharmaceutical case, the outcome was different from most, and the reason is worth studying.
The fraud was noticed quickly, and the company acted at once. By reporting the fraudulent transfer to the bank and the authorities within the crucial early window, the money was still traceable and had not yet vanished through the laundering chain. As a result, the full amount, about 2.16 crore rupees, was recovered.
The lesson is the same one that runs through every fraud story. Technology did not save the money. Speed did. A fast, decisive response in the first hours turned what could have been a devastating loss into a complete recovery.
Why BEC Is So Effective
BEC succeeds because it hides inside normal business life.
- It uses trust. The request comes from a familiar name.
- It needs no malware. There is often nothing for security software to catch.
- It exploits process. Busy teams processing many payments are the perfect target.
- It uses authority and urgency. A message that looks like it is from the boss, marked urgent, pressures staff to act without questioning.
This is social engineering at a corporate scale. The weak point is not the firewall. It is the moment a human decides to trust an email.
The Common Types of BEC
You will see BEC appear in a few recognizable forms.
- Vendor or invoice fraud. A supplier's account details are changed to divert a payment. This is one of the most common and costly.
- CEO fraud. A message pretending to be a senior leader instructs an urgent transfer.
- Payroll diversion. A request to change an employee's salary account.
- Professional impersonation. A fake message from a lawyer or consultant demanding a confidential, urgent payment.
How Businesses Can Protect Themselves
The good news is that BEC is highly preventable with simple discipline.
- Verify on a second channel. Any change to bank details or any urgent payment request should be confirmed by a phone call to a known number, never by replying to the email.
- Use dual approval for payments above a set amount.
- Be suspicious of urgency and secrecy. Real executives rarely demand secret, rushed transfers.
- Check email addresses carefully, letter by letter, for look alike domains.
- Train your finance and admin teams, because they are the front line.
- Protect email accounts with strong passwords and two factor authentication to prevent takeover.
A single verification call would stop the vast majority of these attacks.
What to Do If You Are Hit
- Contact your bank immediately and ask them to recall or freeze the transfer.
- Report to the authorities at once. Call 1930 and file on the national cyber crime portal.
- Preserve the emails and transaction records as evidence.
- Alert the impersonated party, whether it is your vendor or your executive, so they can secure their systems.
- Move fast. As the pharmaceutical case shows, early action is what makes recovery possible.
The Bottom Line
Business Email Compromise is proof that the most expensive cyber frauds do not always involve dramatic hacking. Sometimes all it takes is one believable email and one trusting click.
The defence is not more technology. It is a habit. When money or bank details are involved, verify on a separate channel before you act. And if a fraudulent payment does slip through, treat it as an emergency and report it within the hour.
One company followed that instinct and recovered 2.16 crore rupees. The email fooled them for a moment. Their speed saved them in the end.
Written by Drivesync Infotech Private Limited. Share this with anyone who approves payments. One verification call can save a fortune.