Business Process Impersonation: How BEC Has Evolved Beyond Phishing in 2025
This style of attack — sometimes called vendor impersonation or invoice fraud — is not a new threat with a new name. It is a meaningful shift in how organized attackers now target small and mid-sized businesses. The 2025 advisories from CISA, combined with data from the FBI Internet Crime Complaint Center’s 2024 annual report, confirm the playbook has changed in ways most accounts payable teams are not ready for. If your invoice approval workflow lives in email — and for most businesses under 200 employees, it does — read this before your next payment cycle.
- What Changed: From Phishing Emails to Hijacked Business Processes
- The Lookalike Domain Problem Is More Sophisticated Than You Think
- Why Accounts Payable Is the Specific Target
- What This Attack Actually Looks Like
- Why It Works on Businesses That Think They Are Careful
- What a Well-Run IT Environment Has in Place
- Federal Guidance on Vendor Impersonation Threats
- The Bottom Line
What Changed: From Phishing Emails to Hijacked Business Processes
The crude “click this link” phishing email still exists. But the attacks that drove real losses in 2024 — business email compromise topped $2.7 billion in reported losses according to the FBI IC3 report — were not crude. They were carefully staged impersonations of normal business activity.
The shift is conceptual. Older attacks targeted individual users with suspicious messages. The goal: get one person to make one mistake. Modern vendor impersonation targets the process itself. Attackers study how your company sends and approves invoices, then insert themselves at the exact point where human verification is least likely to happen.
That distinction matters. It means employee awareness training alone is no longer a sufficient defense. You cannot train your way out of an attack designed to look exactly like Tuesday’s normal workflow.
The Lookalike Domain Problem Is More Sophisticated Than You Think

The infrastructure behind these attacks is built long before any email is sent. Attackers now routinely register domain names that are character-for-character nearly identical to real vendors your accounts payable team has paid for years. A company might register acme-suppl1es.com instead of acme-supplies.com, or use a Unicode character that renders identically in most email clients.
CISA’s 2025 advisories on vendor impersonation campaigns document a specific pattern: lookalike domains are registered weeks or months before an attack, complete with matching email infrastructure and sometimes fake invoice portals that mirror a real vendor’s branding — then left to age before the attack begins.
That delay is deliberate. A domain registered months ago looks more legitimate to email security tools that treat domain age as a trust signal. These are not opportunistic actors. They are running a patient, methodical operation.
Why Accounts Payable Is the Specific Target of Invoice Fraud Schemes
Accounts payable sits at the intersection of three things attackers value: money movement, email-based process, and predictable timing. Most businesses pay invoices on a cycle. Attackers who have done basic reconnaissance — sometimes from a prior data exposure, sometimes from your website or LinkedIn — can identify your vendors, approximate your payment schedule, and time a fraudulent invoice to arrive when your team is already expecting a real one.
The FBI IC3 data shows that the highest-loss business email compromise cases increasingly involve no compromised inbox at all — just a spoofed or lookalike-domain email that never touched your systems. No malware. No account takeover. A well-timed email from an address that looks right, with a PDF that looks right, asking your team to update banking details or approve a payment to a new account.
Your email security tools may never flag it. The sender domain clears a surface-level check. The content contains no malicious links. It reads like a business email — because it is designed to.
What This Attack Actually Looks Like in Practice
Here is how a typical invoice fraud campaign unfolds against a small or mid-sized company:
- An attacker identifies a recurring vendor relationship — a landscaping company, a staffing agency, a software subscription that invoices monthly.
- They register a lookalike domain and configure it with email authentication records designed to pass basic checks.
- They email your accounts payable contact, appearing to come from the vendor, explaining that banking details have changed and future payments should go to a new account.
- A few weeks later, a follow-up invoice arrives from the same lookalike domain. The amount is plausible. The invoice number follows a logical sequence.
- Your team, seeing a familiar vendor name and a payment amount consistent with prior invoices, processes it.
- The funds land in an attacker-controlled account, are moved within hours, and are frequently unrecoverable.
No one clicked a phishing link. No account was compromised. The entire attack ran through social engineering of a workflow — not a person in the traditional sense.
Why These Schemes Work on Businesses That Think They Are Careful
This is the part that unsettles most business owners. These attacks succeed most often at organizations with careful, well-intentioned employees. The failure point is process design, not individual error.
When a business has not documented how banking detail changes should be verified — by phone, using a number already on file, not a number provided in the email — there is no procedure for an employee to follow. They exercise judgment. And these schemes are engineered to look like a situation where judgment says “this is fine.”
When invoice approval happens entirely in email with no secondary confirmation step for payments above a threshold, there is no speed bump. The process runs. The money moves.
When email authentication is correctly configured on your own domain but not monitored for inbound lookalike traffic, you are protected against spoofing of your domain — not against impersonation of your vendors’.
None of these gaps indicate a careless organization. They indicate one whose security posture was built for the previous generation of threats. That describes most organizations.
What a Well-Run IT Environment Has in Place to Counter These Attacks
Addressing this threat requires controls at multiple layers. No single control stops this category of attack. The goal is to make the attack chain fail at more than one point, so a single lapse does not result in a loss. Here is what that looks like in practice:
- Email authentication enforcement: Your domain should have strict email authentication policies so no one can send email appearing to come from your domain. This does not stop lookalike domain attacks on its own, but it closes the simpler spoofing vector and is table stakes.
- Lookalike domain monitoring: Active monitoring for newly registered domains that closely resemble your organization’s domain or your key vendors’ domains. When a lookalike appears, your team knows before the attack begins.
- Inbound email analysis: Email security tooling that flags first-time senders, domain age anomalies, and subtle character substitutions in sender addresses — before a message reaches your accounts payable inbox.
- Payment verification procedures: This is a process control, not a technology control. Any request to change banking or payment details must require verbal confirmation using a phone number independently verified — not the one provided in the email. Documented. Enforced. Not optional.
- Approval thresholds: Payment requests above a defined dollar amount trigger a secondary approval step that happens outside the original email thread.
- Employee awareness calibrated to current threats: Not generic phishing awareness — specific training on what these invoice fraud schemes look like, with examples drawn from current attack patterns.
For a closer look at how we structure these defenses for businesses in South Jersey and the greater Philadelphia area, the cybersecurity services page outlines the framework we apply across our managed client base. Our broader managed IT services page explains how these controls integrate into a fully supported environment.
None of these controls work in isolation. Strong email authentication without a payment verification procedure still leaves you exposed. Excellent employee training without inbound email analysis still leaves you exposed. The controls work as a system — not as individual checkboxes.
We have maintained a zero-client-breach record across every organization we have served since 2004. That record is not the result of any single tool or policy. It reflects a layered, process-aware approach — applied consistently, audited annually, and updated as threats evolve. The GTIA Cybersecurity Trustmark we hold, assessed each year by a CREST-accredited auditor against CIS Critical Security Controls, exists to verify that these layers are real and current.
Federal Guidance on Vendor Impersonation and Invoice Fraud Threats
Federal agencies have increasingly formalized guidance around this category of threat. The CISA advisory framework specifically addresses vendor impersonation campaigns, noting that the sophistication of lookalike domain infrastructure has outpaced many legacy email security tools. The FBI IC3 2024 annual report reinforces this, identifying business email compromise — with its most advanced form being this style of process-level attack — as the costliest cybercrime category by dollar loss for the fifth consecutive year.
The NIST Cybersecurity Framework provides a structured way for organizations to assess their exposure. The Identify and Protect functions map directly to the controls described above: understanding your vendor relationships, payment processes, and email infrastructure is a prerequisite to protecting them. NIST is explicit that process controls and technical controls must be built together — exactly the argument this post makes about why no single layer is sufficient.
The practical takeaway from federal guidance is consistent: organizations most at risk are those whose security programs were designed around perimeter defense and user-behavior training, with no specific attention to the process-level attack surface that these schemes exploit. Closing that gap is not a dramatic undertaking — but it requires deliberate action.
The Bottom Line
The threat of business process impersonation represents a maturation of BEC that most small and mid-sized businesses have not yet calibrated their defenses to meet. Attackers have moved up the sophistication curve. They are no longer trying to trick employees into clicking a bad link. They are inserting themselves invisibly into normal workflows — and the 2024 and 2025 federal data confirms they are succeeding at scale.
The honest assessment for most business owners: if your invoice approval workflow runs through email, and you have not specifically reviewed your controls for lookalike domain and vendor impersonation threats, you have real exposure. Not hypothetical. Documented, well-funded, methodical exposure from actors who have studied how businesses like yours actually operate.
The businesses that come through this threat intact are not the ones with the largest security budgets. They are the ones with a calm, consistent, well-maintained security posture and clear process controls around money movement. Building that posture costs considerably less than recovering from a six-figure wire fraud event.
If you want to know exactly where your exposure sits, Book a Free Cybersecurity Strategy Call. It is a 20-minute conversation with our team — no obligation, no sales pressure, no homework required on your end.
Frustrated With Your Current IT Provider?
If your current MSP isn’t catching the things this post describes, that’s a signal worth acting on. Book a strategy call and we’ll walk through what an honest IT partnership looks like for a business your size.