Risk and technology research
Business email compromise controls
The FBI's 2023 Internet Crime Report lists about $2.9 billion in reported losses tied to business email compromise. Rental operations are exposed when vendor bank details, owner distributions, deposits, refunds, or closing instructions can be changed from an email alone.
Published July 23, 2026 | Sources verified 2026-07-23 | 2,510 words
Fraud controls
$2.9 billion
Reported business email compromise losses in the FBI's 2023 Internet Crime Report
Key takeaways
- Treat every bank-detail change as a high-risk event regardless of sender familiarity.
- Use a known phone number or established portal, not contact details inside the request.
- Do not let urgency, secrecy, or executive names bypass approval rules.
- If funds move, contact the financial institution and law enforcement immediately; delay can reduce recovery options.
Key statistics and definitions
$2.9 billion
Sourced 2023 IC3 BEC reported-loss total
Independent callback
FBI-recommended verification through a known contact channel
Two roles
Editorial control: separate payment-detail entry from final approval where feasible
Methodology
Business email compromise controls uses 10 named public sources, each checked on July 23, 2026. The review starts with $2.9 billion, whose published meaning is reported business email compromise losses in the fbi's 2023 internet crime report. Source facts remain distinct from editorial operating recommendations throughout this fraud controls analysis.
For Business email compromise controls, editors compared publication dates, observation periods, covered populations, geography, units, exclusions, and revision notes. Figures were not blended when their definitions differed. The retained source list lets a reader reopen each publisher's material and assess the stated fraud controls use.
The Business email compromise controls table converts the source review into property records by naming request, verification, approval, release. Those rows are diagnostic prompts, not universal benchmarks. A manager should validate them against current systems, portfolio definitions, and jurisdiction requirements before adoption.
Every Business email compromise controls recommendation is an editorial application of cited evidence. Federal, state, local, program, lease, accounting, employment, safety, privacy, and legal requirements can change the correct procedure. Qualified authorized professionals should decide matters outside routine fraud controls reporting.
The fraud controls answer and its limits
The FBI's 2023 Internet Crime Report lists about $2.9 billion in reported losses tied to business email compromise. Rental operations are exposed when vendor bank details, owner distributions, deposits, refunds, or closing instructions can be changed from an email alone. The direct numeric answer for Business email compromise controls is $2.9 billion. Read it exactly as reported business email compromise losses in the fbi's 2023 internet crime report, rather than as an automatic target for a building or team.
Business email compromise controls belongs to the risk and technology group because its strongest use is comparative context. A portfolio still needs a local fraud controls numerator, denominator, observation date, inventory rule, and exception policy before a management decision can follow.
A sound Business email compromise controls briefing shows the outside figure and local count separately. It explains where geography, coverage, timing, or unit definitions diverge, then directs attention to records the operating team can actually correct.
- Treat every bank-detail change as a high-risk event regardless of sender familiarity.
- Use a known phone number or established portal, not contact details inside the request.
- Do not let urgency, secrecy, or executive names bypass approval rules.
- If funds move, contact the financial institution and law enforcement immediately; delay can reduce recovery options.
Use the FBI figure as complaint context
The FBI's 2023 Internet Crime Report lists about $2.9 billion in reported losses associated with business email compromise. The figure comes from complaints reported to IC3 under the report's definitions and period. It is not a property-management total, an average loss per event, or a probability that a rental operator will be targeted. Not every event is detected or reported, and complaint information can change as facts develop. The statistic establishes the scale of reported BEC loss nationally, while property-specific risk decisions require records from the organization's own payment and email workflows.
FBI business email compromise guidance describes schemes that use business communications to induce transfers or changes in payment instructions. In rental operations, relevant workflows may include vendor bank details, owner distributions, resident refunds, deposits, closing instructions, payroll, and other outbound funds. This list identifies review points, not evidence that any cited public source measured losses in each rental workflow. A familiar display name, prior email thread, copied signature, or plausible invoice does not authenticate a request when a mailbox or correspondence chain may be compromised.
CISA phishing and authentication materials, NIST cybersecurity and incident guidance, FTC security guidance, and CISA ransomware material add defensive context. They do not publish a universal payment limit, staffing model, recovery rate, or acceptable exception percentage for property managers. Local management may set thresholds and approval paths based on transaction exposure and available staffing, but should label them as internal controls. Do not present a two-person approval recommendation, independent callback, or release delay as an industry statistic merely because it is prudent for the operation.
Quarantine every payment-detail change
Create a change record before modifying a payee. Preserve the original request, received time, channel, sender address, relevant message metadata, requested account details in a restricted field, affected payee, pending payments, and staff member who opened the case. Do not overwrite the prior approved instructions. Mark the payee or payment as held under the internal process until verification and approval finish. Email should initiate review, not complete it. Replying in the same thread is not independent verification because a compromised mailbox may receive and answer the reply.
Verify through a trusted route established before the change, such as a known phone number or controlled portal record. Do not use a phone number, link, or contact name supplied only in the change request. Capture the verifier, date and time, contact route, person reached, questions completed under the approved procedure, and result. If verification fails or the known party denies the request, retain that outcome and escalate the event under the incident plan. Avoid placing full bank details in general notes, email subjects, or broad dashboards where additional copying increases exposure.
Apply separation between entering changed details and approving release where staffing permits. The approval record should identify the prior and proposed instruction, verification evidence reviewed, transaction or batch affected, approver, decision, and timestamp. If a small team cannot separate roles, management should document a compensating control such as a transaction limit, delayed release, or independent post-entry review. These alternatives are local recommendations, not a guarantee of equivalent protection. An emergency or executive request should follow the same evidence path rather than creating an unrecorded bypass.
Preserve the release and response trail
At release, compare the payment record with the approved payee instructions and retain the operator, approver, amount, destination token or masked reference, transaction identifier, and release time. Review rejected, redirected, first-time, and recently changed payees according to the internal risk rule. A routine invoice approval does not necessarily approve new banking instructions, so those decisions should remain distinct. Post-release monitoring can identify unusual returns or confirmations, but it cannot replace pre-release verification. The evidence should show which instruction was used and why it was considered approved at that moment.
If money may have been sent fraudulently, contact the financial institution's fraud channel immediately, preserve communications and system evidence, and activate the organization's incident plan. FBI guidance emphasizes rapid reporting and contact because delay can affect recovery options, but the source does not promise recovery. Record discovery time, transaction, bank contact, recall or hold request, IC3 or other report reference when made, recovered amount, remaining confirmed loss, and current owner. Keep attempted diversion, transferred funds, frozen funds, and recovered funds as separate values.
For possible mailbox compromise, preserve relevant sign-in, forwarding, inbox-rule, privilege, and message evidence available under the organization's systems and plan. Revoke sessions or credentials and contain connected access as directed by the incident process. Identify other payment changes, sensitive messages, and delegated users that may need review. Do not declare a sender malicious solely because a payment request was wrong, and do not close the payment case merely because mailbox access was reset. Financial recovery, account containment, data-scope review, required communications, and corrective actions are separate workstreams.
Audit exceptions and improve the payment path
Maintain an exception register for unverified requests, denied changes, policy bypass attempts, failed callbacks, changed payees, duplicate instructions, and suspected compromises. Each entry needs status, owner, next action, due date, and closure evidence. Review patterns by workflow and control step rather than naming individuals in broad reports. A rise in rejected changes may indicate attack activity, but it may also reflect a new verification rule or better reporting. The local denominator should match the question, such as all bank-detail changes reviewed, not all invoices paid.
A control test should sample change records from request through verification, entry, approval, and release. Confirm that the trusted contact route predates the request, the verifier did not rely on supplied details, historical instructions remain available, and the released payment matches the approved record. Also sample urgent and executive-labeled requests because pressure is part of the exposure. Record population, sample period, defects, corrective owner, and retest result. A signed policy without transaction evidence does not demonstrate that the payment path operated as designed.
Use the findings to decide where to add holds, improve trusted-contact records, narrow payment permissions, strengthen authentication, or retrain roles. Do not use the FBI loss figure to estimate savings, set public pricing, or claim that one control prevents BEC. The article's boundary is deliberate: public evidence defines reported national loss and recognized scam patterns, while local operating evidence shows whether a particular instruction was verified and released correctly. Questions about reporting obligations, contractual responsibility, or a disputed payment require current facts and approved qualified review, not a dashboard conclusion.
Fraud controls record sampling scenarios
Use request as a case test for Business email compromise controls. The expected fraud controls evidence is quarantine the change from routine payment processing linked with original message and system metadata, while the fraud controls instruction is: Treat every bank-detail change as a high-risk event regardless of sender familiarity. In a Business email compromise controls sample, select one ordinary fraud controls record, one unresolved fraud controls record, and one changed fraud controls entry. Trace each fraud controls case from original evidence through fraud controls classification and final reporting. Compare the fraud controls meaning first with FBI, Business Email Compromise, then use CISA, More Than a Password only for the separate fraud controls context it supplies. A fraud controls reviewer should explain every exclusion, confirm who approved any fraud controls correction, and preserve the prior value. This request exercise gives Business email compromise controls an auditable result without pretending that a public statistic diagnoses an individual property.
Use verification as a case test for Business email compromise controls. The expected fraud controls evidence is contact the known party through an independent route linked with verifier, time, number, and result, while the fraud controls instruction is: Use a known phone number or established portal, not contact details inside the request. In a Business email compromise controls sample, select one ordinary fraud controls record, one unresolved fraud controls record, and one changed fraud controls entry. Trace each fraud controls case from original evidence through fraud controls classification and final reporting. Compare the fraud controls meaning first with FBI, Internet Crime Complaint Center Annual Reports, then use NIST, Cybersecurity Framework 2.0 only for the separate fraud controls context it supplies. A fraud controls reviewer should explain every exclusion, confirm who approved any fraud controls correction, and preserve the prior value. This verification exercise gives Business email compromise controls an auditable result without pretending that a public statistic diagnoses an individual property.
Use approval as a case test for Business email compromise controls. The expected fraud controls evidence is apply separation of duties and limits linked with named approvers and decision, while the fraud controls instruction is: Do not let urgency, secrecy, or executive names bypass approval rules. In a Business email compromise controls sample, select one ordinary fraud controls record, one unresolved fraud controls record, and one changed fraud controls entry. Trace each fraud controls case from original evidence through fraud controls classification and final reporting. Compare the fraud controls meaning first with CISA, Recognize and Report Phishing, then use NIST, Computer Security Incident Handling Guide only for the separate fraud controls context it supplies. A fraud controls reviewer should explain every exclusion, confirm who approved any fraud controls correction, and preserve the prior value. This approval exercise gives Business email compromise controls an auditable result without pretending that a public statistic diagnoses an individual property.
Use release as a case test for Business email compromise controls. The expected fraud controls evidence is confirm payee data and monitor exceptions linked with payment record and post-release check, while the fraud controls instruction is: If funds move, contact the financial institution and law enforcement immediately; delay can reduce recovery options. In a Business email compromise controls sample, select one ordinary fraud controls record, one unresolved fraud controls record, and one changed fraud controls entry. Trace each fraud controls case from original evidence through fraud controls classification and final reporting. Compare the fraud controls meaning first with CISA, More Than a Password, then use FTC, Start with Security only for the separate fraud controls context it supplies. A fraud controls reviewer should explain every exclusion, confirm who approved any fraud controls correction, and preserve the prior value. This release exercise gives Business email compromise controls an auditable result without pretending that a public statistic diagnoses an individual property.
Fraud controls implementation sequence
For Business email compromise controls, approve one written definition and one reporting period first. Map source fields, identify exclusions, reconcile the population, sample normal and exception records, and obtain accountable approval before automating the calculation.
Next, create a Business email compromise controls runbook with source links, extraction steps, calculation logic, cutoff time, quality checks, correction handling, retention, backup ownership, and escalation contacts. Ask a second operator to reproduce the fraud controls output from retained inputs.
After two comparable Business email compromise controls cycles, remove fields that did not support a decision and add evidence only for a defined question. More columns increase collection and privacy burden when they do not clarify fraud controls action.
Use the site's property management services and resources to organize recurring Business email compromise controls records. Keep final legal, accounting, housing, employment, privacy, and safety decisions with qualified authorized professionals familiar with the applicable facts.
Reference table
| Step | Required action | Evidence |
|---|---|---|
| Request | Quarantine the change from routine payment processing | Original message and system metadata |
| Verification | Contact the known party through an independent route | Verifier, time, number, and result |
| Approval | Apply separation of duties and limits | Named approvers and decision |
| Release | Confirm payee data and monitor exceptions | Payment record and post-release check |
Sources
- FBI, Business Email Compromise Accessed 2026-07-23.
- FBI, Internet Crime Complaint Center Annual Reports Accessed 2026-07-23.
- CISA, Recognize and Report Phishing Accessed 2026-07-23.
- CISA, More Than a Password Accessed 2026-07-23.
- NIST, Cybersecurity Framework 2.0 Accessed 2026-07-23.
- NIST, Computer Security Incident Handling Guide Accessed 2026-07-23.
- FTC, Start with Security Accessed 2026-07-23.
- CISA, Cybersecurity Performance Goals Accessed 2026-07-23.
- NIST, Digital Identity Guidelines Accessed 2026-07-23.
- CISA, StopRansomware Guide Accessed 2026-07-23.
Frequently asked questions
Why is replying to the email not verification?
A compromised mailbox can answer. Verification needs a trusted channel obtained independently of the change request.
Does a familiar writing style make a request safe?
No. Attackers can study real correspondence or use a compromised account. Follow the payment-change process every time.
What if a payment was just sent?
Contact the financial institution's fraud channel immediately, preserve evidence, notify the FBI or IC3 as appropriate, and activate the incident plan.
Should one person ever change and release a payment?
Separation is safer where feasible. If staffing makes it difficult, use documented compensating controls such as limits, delayed release, and independent review.
Related research
- Cybercrime loss statistics for property operations
$16 billion+ is the direct numeric answer for this source review. The FBI's 2024 Internet Crime Report recorded more than $16 billion in reported losses. It is a complaint-based national total, not an estimate for rental companies, but it gives operators a defensible reason to protect payments, resident records, email, and vendor access.
- Rental data privacy inventory guide
The FTC Safeguards Rule requires covered financial institutions to notify the FTC about certain events involving at least 500 consumers. Coverage is fact specific, but the threshold shows why a rental operator should know what personal data it holds, where it moves, and who can retrieve it.
- Property management software adoption scorecard
6 functions is the direct numeric answer for this source review. NIST Cybersecurity Framework 2.0 is organized around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. A property software scorecard can borrow that disciplined coverage while measuring whether leasing, ledger, maintenance, inspection, document, and reporting workflows finish accurately.