The Industrialized Fraud Hiding in Plain Sight | Kroll

Cyber

August 12, 2026

The Industrialized Fraud Hiding in Plain Sight

To read more on this story and the significance of Business Email Compromise (BEC), visit The Wall Street Journal where Dave Burg was interviewed (subscription required).

A few months ago, scammers hijacked a routine infrastructure project in Surfside Beach, South Carolina, costing the small town $545,000. The scheme stemmed from a single spoofed email sent from a lookalike domain, instructing the town to switch payment from check to ACH. The result was a devastating financial loss—and a stark reminder that business email compromise (BEC) remains a pervasive threat.

As the world’s largest and most digitally connected economy, the United States experiences a disproportionate share of BEC activity. Typical BEC attacks involve anything from vendor invoice fraud, as in this case, to email thread hijacking and even executive impersonation. The FBI estimates BEC scams caused more than $3 billion in reported losses in 2025 alone, with the actual financial impact likely much higher. Kroll operates one of the world’s largest digital forensics and incident response practices, investigating hundreds of BEC incidents each year, and the pattern is strikingly consistent. These attacks succeed not through advanced technical capability, but by systematically exploiting routine business processes, trusted relationships and predictable human behavior.

BEC attacks enable threat actors to exploit trust and typically follow a familiar lifecycle, starting with phishing or compromised credentials. Attackers often bypass multi-factor authentication (MFA), which is widely viewed as a trusted safeguard against account hijacking, not by hacking or breaking MFA itself, but by stealing or abusing the authentication process after the user successfully completes the authentication process. This enables attackers to get inside the target’s email environment and move to reconnaissance. They spend time studying the organization, learning payment procedures, identifying key personnel and understanding the typical communications cadence.

Next comes a carefully timed request—typically for a wire transfer or ACH payment—designed to create urgency while appearing legitimate. Once funds move, the attacker disappears but often leaves behind a foothold. Remediation must go deeper to truly eliminate a lingering threat, with forensic investigators who are trained to identify and eliminate the persistent mechanisms that victims routinely miss on their own.

Importantly, artificial intelligence is accelerating the attack cycle, but it is also occasionally tipping targets off and enabling them to catch an attack through subtle clues. With employees increasingly familiar with AI-generated language, jargon and syntax, an employee who is paying close attention might sense that something isn’t quite right or catch a small context error and escalate a phishing inquiry before a breach occurs. On the flip side, AI is improving and small clues can go unnoticed when employees are busy, trust established processes or simply don’t know they’re being targeted.

What sets BEC apart from many other cyber threats is that it exploits trust and process rather than relying on malware. In Surfside Beach, attackers used lookalike domains—replacing a lowercase “l” with a capital “I” for one party and adding an “s” for the other—to quietly intercept and redirect communications, with neither party realizing the conversation had been compromised until 45 days later, long after the money was gone. That delay matters: every day of undetected compromise makes recovery less likely. Organizations that have an incident response plan and response partner in place beforehand stand a far better chance of recovering funds.

The lessons from Surfside Beach are universal, and they map to where organizations most need support. Organizations must harden identity controls, monitor cloud and mailbox activity, secure remote access, detect misuse of legitimate tools and build incident response readiness before an incident—not after.

Above all, one of the most effective safeguards remains the simplest: human verification. A single phone call confirming a payment request could have prevented the Surfside incident. BEC succeeds not because attackers are exceptionally technical, but because they are patient and exploit trusted processes. Defending against these attacks requires the same discipline, and when prevention fails, remediation speed is critical. Whether investigating an active compromise, recovering from a loss or strengthening defenses before attackers strike, Kroll brings the forensic depth and incident response experience of thousands of cases to every engagement.

Find out more about Kroll's Reactive Services

Stay Ahead with Kroll

Cyber and Data Resilience

Kroll merges elite security and data risk expertise with frontline intelligence from thousands of incident responses and regulatory compliance, financial crime and due diligence engagements to make our clients more cyber- resilient.

Business Email Compromise (BEC) Response and Investigation

With decades of experience investigating BEC scams across a variety of platforms and proprietary forensic tools, Kroll is your ultimate BEC response partner.