Introduction
Business email compromise (BEC) is a growing threat to South African small and medium-sized businesses. Unlike noisy ransomware or mass phishing campaigns, BEC is often targeted, quiet and financially damaging. For SMEs in Johannesburg, Pretoria and across Gauteng, recognising early warning signs is essential to prevent costly mistakes and downtime. This guide explains common indicators of BEC, practical prevention measures suitable for local businesses, and steps to take if you suspect compromise.
What is business email compromise?
Business email compromise is a type of cybercrime where attackers gain access to legitimate business email accounts or convincingly spoof them to defraud a company. Their typical goals include wire transfer fraud, invoice diversion, payroll manipulation or harvesting credentials for further access. Because BEC attacks frequently impersonate trusted colleagues, suppliers or executives, they can bypass basic defences.
Common warning signs of BEC
Timely detection often depends on staff vigilance. Teach your team to look for subtle anomalies rather than obvious malware alerts.
Unusual payment requests or urgent financial demands
- Requests to change banking details for recurring suppliers.
- Emails demanding immediate payment or asking to bypass normal approval processes.
- Last-minute “urgent” invoices with pressure to transfer funds.
Sender anomalies and spoofing indicators
- From addresses that look similar but contain slight misspellings (for example, finance@acme-co[.]za vs finance@acmeco[.]za).
- Display names that match senior staff while the actual email domain differs.
- Unexpected forwarding rules or auto-replies set by the sender.
Requests for sensitive information
Emails asking for employee tax numbers, ID details, banking credentials or password resets are red flags. BEC actors often harvest personal data to bypass two-factor authentication or social-engineer further access.
Strange language, tone or writing style
- Messages that deviate from the sender’s usual tone or contain awkward phrasing.
- Generic greetings instead of personalised salutations.
- Uncharacteristic urgency, threats, or over-politeness intended to manipulate.
Irregular email behaviour and technical signs
- Large volumes of outbound email from a user who normally sends few messages.
- Unexpected login notifications, especially from foreign IP addresses or unusual locations.
- New mail rules created to delete or divert responses.
Why South African SMEs are attractive targets
SMEs often have limited IT resources and mature processes, making them appealing to attackers. Additionally, local business practices—such as relying on email for payment instructions and informal approval chains—can be exploited. For companies operating in Gauteng, where many suppliers and clients are interconnected, fraud can spread quickly through networks of trust.
Practical prevention steps for SMEs
Protection doesn’t need to be complicated or expensive. Focus on layered controls, staff training and clear financial procedures.
Technical controls
- Enable multi-factor authentication (MFA) for all accounts, including administrators.
- Use modern email filtering and anti-spoofing technologies: SPF, DKIM and DMARC.
- Monitor login activity and implement conditional access where possible.
- Keep systems patched and maintain device endpoint protection.
Policy and process
- Require dual authorisation for payments above defined thresholds—set thresholds in rand appropriate to your business size.
- Verify bank account changes through a secondary channel such as a phone call to a known number.
- Limit public exposure of staff email addresses and organisational charts on the website.
Staff training and culture
Regular, practical training helps staff recognise suspicious messages. Simulated tests are useful, but pair them with coaching and clear reporting paths so employees feel safe raising concerns without blame.
How to respond if you suspect a compromise
Act quickly to contain damage and gather evidence. A calm, methodical response improves chances of recovery.
Immediate containment steps
- Isolate affected accounts: force password resets and revoke active sessions.
- Disable any suspicious mail forwarding rules and review send-as permissions.
- Notify your bank immediately if payments were redirected and request a recall if possible.
Investigate and document
- Collect headers and logs to determine origin and timeline of the incident.
- Identify any data exfiltration, credential theft or additional compromised accounts.
- Preserve evidence for potential police or banking investigations.
Report and recover
- Report fraudulent transactions to your bank and file a case with the South African Police Service if funds were lost.
- Notify affected clients or suppliers where appropriate, with factual guidance on next steps.
- Review and update controls to prevent recurrence, including changes to policies and technical settings.
Case scenario: invoice diversion in a small Gauteng supplier
A Pretoria-based supplier received what appeared to be an email from a long-term customer requesting payment to a new account. The accounts clerk did not verify via phone and the supplier paid R120,000. The transaction was later flagged as fraudulent. Recovery depended on rapid bank engagement and a police case. The business then implemented mandatory two-person authorisation for all payments above R10,000 and enabled MFA for finance accounts.
Key takeaways
- BEC relies on trust and subtlety—train staff to question unusual requests.
- Technical controls like MFA and SPF/DKIM/DMARC reduce risk significantly.
- Clear financial procedures, verification steps and rapid incident response limit damage.
FAQ
- Q: What immediate sign should trigger an investigation?
A: Any unexpected request to change banking details or an urgent payment request that bypasses normal approvals should be investigated immediately.
- Q: Can email filtering stop all BEC attacks?
A: No. Filtering helps but BEC often uses legitimate accounts or carefully crafted spoofing. Combine filtering with MFA, verification processes and staff training.
- Q: How quickly should we act if we detect suspicious activity?
A: Immediately. Reset passwords, revoke sessions, notify your bank and preserve logs. Early action improves chances of stopping transfers and recovering funds.
- Q: Is MFA enough to prevent BEC?
A: MFA significantly reduces risk but is not foolproof. Attacks that use social engineering or SIM swapping underline the need for layered controls.
- Q: Who should handle BEC incidents in an SME?
A: Ideally a small incident response team: a senior manager, the IT lead and a finance representative. External technical support can help preserve evidence and restore security.
Conclusion
Business email compromise is a realistic threat for South African SMEs, but it is manageable. By recognising warning signs, reinforcing technical defences and enforcing sound financial procedures, businesses can reduce risk and respond effectively when incidents occur. RandTech IT focuses on fast, experienced response and practical controls so your team can get back to business with minimal disruption.
If you suspect a compromise or want to strengthen your email defences, contact RandTech IT for practical, experienced assistance tailored to South African SMEs.

