Serving Plant City, Tampa & Central Florida 📞 (508) 243-7410 ✉ brendan@beardedbytes.com

Business Email Compromise: The Wire Fraud Scam Hitting Florida SMBs

Business email compromise tricks Florida small businesses into wiring money to fraudsters posing as vendors or bosses. Here's how it works and how to stop it.

Illustration of a spoofed email overlapping a wire transfer form with a red warning flag, representing business email compromise fraud targeting small business

Here’s the uncomfortable truth: the scam that’s cost small businesses the most money over the last few years isn’t ransomware. It’s not even close. It’s a fraudster sending one convincing email from an address that looks almost right, asking your bookkeeper to wire money somewhere new. No malware, no encrypted files, no ransom note. Just a well-timed lie and a wire transfer that can’t be undone.

It’s called business email compromise, or BEC, and I’ve now sat across the table from three Florida small business owners who lived through it. Two of them got some money back after weeks of bank disputes and FBI paperwork. One didn’t. If you run a business in Plant City, Tampa, or anywhere in Central Florida and you move money by email approval — invoices, payroll, vendor payments, wire transfers — this is the scam I’d want you to understand before it happens to you, not after.

What business email compromise actually looks like

BEC doesn’t look like the phishing emails everyone’s learned to squint at. There’s no urgent “your account has been suspended” banner, no obviously sketchy link, no attachment full of malware. It’s quieter and smarter than that, which is exactly why it works.

The most common version I see plays out like this: your vendor’s email account gets compromised — not yours, theirs. The attacker sits inside that mailbox quietly for a week or two, reading real invoice threads, learning your vendor’s tone, learning your payment schedule. Then, right when an actual invoice is due, they send you an email that looks like it’s continuing that same thread, from that same real vendor, saying something like “quick note — we’ve switched banks, please send this month’s payment to the new account below.” The invoice amount matches what you actually owe. The email thread is real. The only thing that’s fake is the bank account number.

A second version targets the business owner directly. The attacker registers a domain that’s one character off from yours or a vendor’s — a swapped letter, an extra hyphen, a .co instead of a .com — and emails your office manager or bookkeeper pretending to be you. “Hey, I’m in a meeting and can’t talk, but I need you to send a wire for [amount] to this account today, it’s time-sensitive, I’ll explain later.” It’s short, it’s urgent, and it’s designed to be read on a phone between meetings, not scrutinized on a desktop.

A third version goes after payroll: the attacker impersonates an employee and asks HR to update their direct deposit information to a new account. Nobody notices until payday, when the real employee calls asking where their paycheck went — except now it’s sitting in a stranger’s account.

Why this hits small businesses in Florida especially hard

Florida has a dense population of exactly the kind of businesses BEC targets: real estate and title companies, construction firms, property management outfits, medical and dental practices, and professional services firms that regularly move five and six-figure sums by wire. Real estate closings are a favorite target nationally, and Florida’s real estate market gives attackers plenty of targets — a compromised title company email and a spoofed wire instruction at the wrong moment can wipe out someone’s entire home down payment in one transfer.

Small businesses are also just easier marks than large ones. A 10-person company usually doesn’t have a dedicated finance team with a mandatory second sign-off on every wire. It’s often one bookkeeper or office manager who has the authority — and the trust — to move money on a single email request. That’s not a criticism of how you run your business; it’s just a reality attackers know how to exploit.

The single control that stops almost all of these

If you take away one thing from this post, make it this: never change payment details based on an email alone. Full stop. If a vendor says they’ve switched banks, if your “boss” asks for an urgent wire, if an employee wants new direct deposit info — pick up the phone and call a known number to confirm it. Not a number from the email signature, which the attacker controls. A number you already had on file, or one you look up independently.

This one habit, treated as a non-negotiable rule rather than a suggestion, blocks nearly every version of this scam. It costs you two minutes and an awkward “sorry, just confirming” phone call. It costs a successful BEC attack tens of thousands of dollars and, more than once in my experience, a business relationship or a job.

What else actually reduces your risk

A few other things I’d put in place, roughly in order of impact:

Require a second approval on wires above a set dollar threshold. Doesn’t have to be complicated — even “any wire over $2,500 needs a verbal okay from the owner” closes most of the gap. The point is that no single email, to any single person, can move money on its own.

Turn on multi-factor authentication for every email account, not just the owner’s. A compromised vendor mailbox is usually how this starts. If your own email gets compromised the same way, you become the launching point for the next attack against your customers. I wrote about this exact gap in Microsoft 365’s default security settings — MFA is one of the five changes I’d make on day one for any Florida small business.

Set up email authentication (SPF, DKIM, DMARC) on your domain. These are technical settings, but they matter here specifically: DMARC makes it much harder for someone to send email that appears to come directly from your domain, which protects both you and everyone you email.

Watch for lookalike domains. If you’re worried about a specific vendor or partner, it takes five minutes to check whether someone’s registered a near-identical version of their domain. It won’t stop every attack, but it catches the sloppy ones.

Train whoever touches money on what this looks like — not just once, but as a recurring five-minute conversation. I’ve found that a single onboarding mention doesn’t stick. A quarterly reminder with a real example does. This overlaps with the phishing awareness training I recommend for every team, but BEC deserves its own specific callout because it doesn’t look like the phishing examples people expect.

If it happens to you anyway

Speed is everything. If you discover a fraudulent wire within hours, there’s a real chance your bank can still recall it before the receiving bank releases the funds — sometimes even same-day if you move fast. Call your bank immediately, tell them it’s suspected wire fraud, and ask them to initiate a recall. Then file a complaint with the FBI’s Internet Crime Complaint Center (IC3.gov) — they coordinate with banks on recovery more often than people expect, and Florida’s data breach notification requirements may apply depending on what data was exposed alongside the fraud. I covered those notification obligations in more detail in an earlier post on Florida’s breach law.

What I wouldn’t do is treat this as purely a “the bookkeeper made a mistake” problem after the fact. The email looked real. That’s the entire design of the scam. The fix isn’t blaming the person who got fooled — it’s building a verification step into the process so the next well-crafted email doesn’t have the same shot at succeeding.

Where this fits into your broader security setup

BEC prevention isn’t really a standalone project — it’s part of the same email security and access control foundation that protects you from ransomware, data breaches, and every other threat on this list. If you’re not sure where your business actually stands on MFA coverage, email authentication, or whether your team would recognize one of these emails if it landed in their inbox today, that’s exactly the kind of gap assessment we do for clients across Plant City and the Tampa Bay area as part of our cybersecurity services.

If you want a second set of eyes on your email security setup before it costs you a wire transfer instead of an afternoon, reach out for a free consultation. It’s a lot cheaper to find the gap now than to explain it to your bank later.

Tags: #business email compromise#wire fraud#phishing#small business#florida#email security

Need help with this in your business?

Bearded Bytes provides on-site IT support, cybersecurity, and managed services across Plant City and the Tampa Bay area. Book a free consultation.

Talk to Brendan →