Business Cybersecurity
Business Email Compromise (BEC) in 2026: The Miami Business Owner's Prevention Playbook
Miami-Fort Lauderdale is a top-three U.S. metro for BEC losses. This 2026 field guide from Cybrvault breaks down exactly how business email compromise works today (AI voice clones, vendor takeovers, title-company wire fraud), the 12 controls that actually stop it, and the first 72 hours if you're already hit.

In every quarter of the last three years, business email compromise (BEC) has been the single most expensive cybercrime in Florida — and Miami-Fort Lauderdale sits in the top three U.S. metros for losses, per FBI IC3 reporting. When a Miami business owner calls Cybrvault in a panic, seven times out of ten it's a BEC event: a wire that shouldn't have moved, a vendor payment redirected, a title-company closing hijacked at the finish line, or a payroll batch redirected to an attacker-controlled account.
The uncomfortable truth is that BEC almost never looks like the phishing emails you see in training videos. There's no misspelled domain, no fake FedEx tracking link, no Nigerian prince. It looks like a normal email from someone you already trust — because it usually is. Somebody's mailbox has been compromised, the attacker has read weeks of context, and the malicious instruction is quietly injected into a real conversation you're already having. That's why traditional 'security awareness training' has not slowed BEC losses at all.
This is Cybrvault's 2026 field guide to preventing business email compromise for Miami business owners. It's what we install for private clients — the exact technical controls, the exact human process, and the exact 72-hour response plan. If you'd rather have us implement it, book a free 30-minute consult at /contact or see our Miami cybersecurity services.
What is business email compromise, actually?
Business email compromise is a class of attack in which a criminal uses email — usually from inside a legitimate mailbox — to trick an organization into moving money, changing banking information, or releasing sensitive data. It is the highest-ROI cybercrime on the planet: no ransomware payload, no lateral movement, no exploit development. Just a well-timed email that costs a Miami business six or seven figures in a single transaction.
The FBI's Internet Crime Complaint Center (IC3) has tracked over $55 billion in BEC losses globally since it began tracking the category. In the most recent reporting year, Florida ranked #2 nationally by BEC dollar losses, with Miami-Dade, Broward, and Palm Beach counties responsible for the majority of the state's total. Real estate, law, construction, medical practices, and family offices are the highest-frequency Miami victims — the common thread is high-dollar wires that move on tight timelines.
The six BEC playbooks hitting Miami right now
Every BEC event we respond to in South Florida maps to one of six patterns. If you recognize your last near-miss in this list, that's not coincidence — it's the industry.
1. CEO / owner impersonation ('the fake boss' wire)
The attacker registers a lookalike domain (cybrvualt.com vs cybrvault.com), spoofs the owner's display name, or compromises the owner's actual mailbox, then emails the controller or CFO with an 'urgent, confidential' wire request. Often timed for Friday afternoons or when the owner is known to be traveling. The AI-voice-clone follow-up call — 'yes, please push it through, I'm about to board' — is now standard.
2. Vendor email compromise (VEC) — the invoice redirect
Your vendor's mailbox is compromised. The attacker reads the AP thread, then sends 'updated banking information' from the vendor's real email address. Your next 30–90 days of invoices route to the attacker before anyone notices the vendor never got paid. This is the most common Miami pattern in construction, wholesale, medical supply, and law firm trust accounts.
3. Title-company wire fraud (real estate closings)
Miami-Dade real estate is a top-three U.S. target. Attacker compromises either the buyer's realtor, the title company, or the escrow attorney's mailbox, then sends fraudulent wire instructions 24–48 hours before closing. Buyer wires life-changing money to the attacker. Recoveries are rare — most funds are pulled out to overseas accounts within hours.
4. Payroll direction fraud
Attacker spoofs an employee (usually a highly-paid one) and emails HR or payroll asking to update direct deposit to a new account 'starting next pay period.' The next paycheck lands in the attacker's account. Cheap and easy — sub-$10k losses that many companies never bother reporting, so the true frequency is underreported.
5. Attorney/M&A impersonation
Higher-end variant: attacker impersonates outside counsel during a live transaction (acquisition, real estate deal, litigation settlement) and pushes an 'urgent, confidential — don't discuss with anyone' wire. Preys on the deal urgency and the attorney-client privilege framing. Common against Miami family offices and real estate holding companies.
6. Data-only BEC (W-2 / KYC theft)
No money moves — instead the attacker asks HR for all employee W-2s, or asks finance for the company's banking KYC package, or asks IT for the entire org's Microsoft 365 user list. The stolen data fuels the next month of tax fraud, account-takeover attacks, and follow-on BEC against the same company.
Why traditional defenses are failing in 2026
- Email security gateways (Proofpoint, Mimecast, Microsoft Defender for Office 365) catch mass phishing, not surgical single-target emails from legitimate compromised accounts.
- MFA on the mailbox stops password reuse — but not session-token theft (AiTM phishing) or SIM-swap into SMS MFA. Passkeys and FIDO2 keys are the fix.
- Security awareness training teaches employees to spot fake domains. BEC in 2026 does not use fake domains — it uses real ones the employee already trusts.
- AI voice cloning has eliminated 'call the sender to verify' as a defense, unless the callback is to a previously-known number the employee already had.
- DMARC is deployed at p=none on ~60% of Miami small-business domains we assess — which does nothing. Only p=reject actually blocks spoofing.
The 12 controls that actually stop BEC
Do these in order. The first three, done properly, defeat the majority of BEC events we respond to.
1. The written callback rule (the single highest-ROI control)
No wire, no ACH change, no vendor banking update, no payroll direction change, no title-company wire instruction, no client trust account movement is executed without a verbal callback on a previously-known number to a known person on the other side. Not the number in the email — the number already in your contacts or accounting system. Zero exceptions. The owner is not exempt. Write it, sign it, post it above every AP workstation.
2. Passkeys or FIDO2 hardware keys on every mailbox
Passwords + SMS MFA are defeated by AiTM (adversary-in-the-middle) phishing kits like Evilginx, which are now sold as a service for $150/month. Passkeys and FIDO2 hardware keys (YubiKey, Google Titan) are not defeated by AiTM because the cryptographic challenge is bound to the origin. Every mailbox — owner's, controller's, AP clerk's, HR's — gets a hardware key or passkey. See our passkeys vs passwords guide.
3. SPF + DKIM + DMARC at p=reject on every domain you own
SPF lists who can send from your domain. DKIM cryptographically signs your outbound mail. DMARC tells receiving mail servers what to do when SPF/DKIM fail — and only p=reject actually blocks spoofed mail. Deploy DMARC at p=quarantine for two weeks (with a monitoring tool like Dmarcian, Valimail, or EasyDMARC), then move to p=reject. Do this on every domain you own, including domains you don't send from — attackers spoof unused domains too.
4. Impersonation + lookalike-domain protection on the mail gateway
Microsoft Defender for Office 365 (Plan 2), Proofpoint, Abnormal Security, or Mimecast can flag display-name impersonation ('CEO Name <random@gmail.com>') and lookalike domains registered in the last 30 days. Enable it. Route high-risk mail (external senders emailing the CFO/controller with wire-related keywords) into a supervisor queue for the first 90 days.
5. Conditional access — block legacy protocols and risky sign-ins
In Microsoft 365, block basic auth / legacy protocols (IMAP, POP3, SMTP AUTH) organization-wide — these bypass MFA entirely. Enable conditional access policies that block sign-ins from unfamiliar countries (attackers frequently sign in from Nigeria, Russia, and Vietnam even when the victim never leaves Florida), and require MFA re-verification for high-risk sessions. Google Workspace has the equivalent under Context-Aware Access.
6. Mailbox rule auditing (catch forwarding rules within minutes)
The first thing an attacker does after compromising a mailbox is set an inbox rule that auto-forwards or auto-deletes any email containing 'wire,' 'invoice,' 'bank,' or the CFO's name — so the real owner never sees the fraudulent thread. Enable audit alerts for new inbox rules in Microsoft 365 (Purview) or Google Workspace, and review them daily for the AP, controller, HR, and executive mailboxes.
7. Out-of-band verification for banking changes (customer + vendor)
Every time a vendor tells you their banking has changed, verify with a phone call to the number you already had on file — not any number in the email. Same rule for customers who ask you to change where their refund goes. Document the verification in your ERP/accounting system with the date, the person you spoke to, and the phone number used. This is your evidence trail if a bank recovery is needed.
8. Segregation of duties on wires and payment changes
The person who initiates a wire is not the person who approves it. The person who updates vendor banking details is not the person who releases the next payment. Two humans, two accounts, one wire. Every mid-sized Miami business we harden ends up here — small enough to hurt to add, big enough to save you seven figures the first time it triggers.
9. Dual controls in the banking portal itself
Ask your bank to enable dual approval on wires above a threshold — most business banking platforms (Chase, Bank of America, City National, Truist, Amerant, City National of Florida) support it. Wires initiated by one user require approval from a second user on a different device before they leave. This is a bank-side control the attacker cannot bypass even with a fully compromised mailbox.
10. Domain monitoring for lookalikes
Register the obvious typo variants of your domain yourself. Use a service (DomainTools, RiskIQ, or free tools like dnstwist) to monitor for new lookalike registrations weekly. When a new lookalike appears, file a takedown before the attacker uses it — most are used within 48 hours of registration.
11. Vendor cyber posture in AP onboarding
Add three questions to your new-vendor onboarding: (a) do you enforce MFA on all employee mailboxes? (b) is your domain DMARC-enforced at p=reject? (c) if your mailbox is compromised and used to redirect our payments, will you make us whole? Vendors with mature answers get standard payment terms. Vendors with 'we'll get back to you' get callback-verified banking on every invoice.
12. Written incident response plan — rehearsed
A one-page IR plan naming who calls the bank, who calls the FBI, who preserves evidence, and who talks to insurance — with phone numbers, taped to the wall next to the CFO. Rehearsed once a quarter with a tabletop drill. Companies that rehearse recover 3–4x more BEC losses than companies that improvise on day one.
AI voice clones and deepfakes: the 2026 escalation
In late 2024 we started seeing AI voice-clone follow-up calls on Miami BEC events. In 2025 they became standard. In 2026 they are the norm — every serious BEC operator now has a 30-second sample of the target owner (scraped from an Instagram Reel, a podcast interview, or a Zoom recording posted on YouTube) and a $30/month voice-cloning subscription. The clone is convincing enough that the controller's 'I called him to verify' does not defeat it.
The only defense is the callback rule as written above: the verification call is placed by the controller, to a number the controller already had, and reaches the real person. An impromptu inbound call to verify — 'the CEO just called me back and confirmed' — is worthless in 2026. See our AI voice scams guide and what is vishing for the phone-based social engineering context.
The first 72 hours if you're already hit
- 1Call your bank's fraud desk immediately — do not email, do not wait for business hours. Ask specifically for a Financial Fraud Kill Chain (for international wires) or an ACH recall (for domestic). Under 24 hours has meaningful recovery odds; 24–72 hours is a coin flip; after 72 hours recovery collapses to near zero.
- 2File at ic3.gov within the first 24 hours. IC3 routes serious cases to the FBI's Recovery Asset Team (RAT), which coordinates with U.S. and correspondent banks — it materially improves recovery on wires over $50k.
- 3Preserve evidence before you touch anything: full email headers (not just the body), mailbox audit logs, sign-in logs, any inbox rules created in the last 90 days, and screenshots of the fraudulent instruction thread. Do not delete anything. Do not wipe the compromised device.
- 4Force sign-out and reset MFA on the compromised mailbox(es). Rotate all passwords, enroll passkeys/hardware keys during the rotation, and remove any inbox rules, delegate access, or app passwords the attacker created.
- 5Notify your cyber insurance carrier within 72 hours — most policies require it, and late notice is a common denial reason. Involve your broker before you make statements to the carrier.
- 6Notify affected vendors, customers, or counterparties. If a vendor's mailbox was the source, they need to know so they can contain their side. If your mailbox was the source, your customers need to know so they don't get hit on the next invoice cycle.
- 7Engage professional incident response. Cybrvault runs Miami incident response for BEC events on a 24-hour emergency basis, including bank-desk coordination, evidence preservation, and insurance-carrier defensible reporting.
- 8File a local police report with Miami-Dade PD (or your city's PD). You'll need the report number for insurance, some bank recovery workflows, and any subsequent civil action against the receiving-bank account holder.
Common BEC objections we hear from Miami owners
- 'Our bank will just reverse it.' No — U.S. wires are near-final. Reversal requires the receiving bank's cooperation, which requires the funds to still be there, which they usually are not after 24 hours.
- 'Our cyber insurance covers this.' Sometimes. Many policies have BEC sublimits ($100k or $250k when your overall limit is $2M) and exclude losses where MFA wasn't enforced or callback procedures weren't followed. Read your policy before you need it.
- 'We're too small to be targeted.' The average successful BEC loss in Florida for small businesses is in the six figures. Attackers scrape SunBiz, LinkedIn, and property records — you are on lists.
- 'We already trained everyone.' Training helps for phishing. It does not help against a legitimate compromised vendor mailbox injecting a real thread with a real invoice with new banking info. Process controls (callback rule, dual approval) are what stop it.
- 'This will slow down our AP.' Yes — by roughly two minutes per wire. That two minutes has saved every Cybrvault client the first time it triggered.
The Cybrvault BEC hardening engagement for Miami businesses
For clients who want it done rather than DIY, we run a 30-day BEC hardening: DMARC deployment to p=reject, mail gateway impersonation rules, passkey/FIDO2 rollout on every mailbox, conditional access policies, mailbox audit-rule alerting, written callback and dual-approval policies, and a live tabletop drill with the owner, controller, and AP team. Followed by ongoing monitoring and quarterly reviews.
Book a free 30-minute assessment at /contact or read more about our Miami cybersecurity, ethical hacking / social engineering testing, and 24/7 monitoring services.
Related reading
// frequently asked
Questions teams ask us
What is business email compromise (BEC)?+
Business email compromise is a class of cyberattack in which a criminal uses email — usually from inside a legitimate mailbox they've compromised — to trick an organization into moving money, changing banking information, or releasing sensitive data. It differs from traditional phishing because the malicious email typically comes from a real, trusted mailbox (yours, a vendor's, or a title company's) and is injected into an existing conversation, so it evades both technical filters and trained users. The FBI's IC3 ranks BEC as the single most expensive cybercrime category in the United States, with billions lost annually.
How common is business email compromise in Miami?+
Very. Florida ranks in the top three U.S. states for BEC losses every year the FBI IC3 has tracked the category, and Miami-Fort Lauderdale is consistently a top-three metro. The most-targeted Miami industries are real estate (closing wire fraud), law firms (trust account wires), construction (vendor payment redirection), medical practices, and family offices — anywhere large-dollar wires move on tight timelines. Cybrvault responds to BEC events across South Florida weekly.
How do you prevent business email compromise?+
The single highest-ROI control is a written callback rule: no wire, ACH change, vendor banking update, or payroll direction change is executed without a verbal callback on a previously-known phone number to a known person on the other side — not any number in the email. Layer that with passkeys or FIDO2 hardware keys on every mailbox, DMARC at p=reject on every domain you own, mail-gateway impersonation and lookalike-domain protection, mailbox audit-rule alerting, dual approval on banking wires, and a rehearsed incident response plan. Those seven controls stop the vast majority of BEC events we investigate in Miami.
Can I recover money lost to a BEC attack?+
Sometimes — and time is the entire game. Call your bank's fraud desk within 24 hours and specifically request a Financial Fraud Kill Chain (for international wires) or an ACH recall (for domestic). File at ic3.gov the same day so the FBI's Recovery Asset Team can coordinate with the receiving bank. Recoveries are meaningfully possible under 24 hours, a coin flip between 24 and 72 hours, and near zero after 72 hours. Preserve email headers, sign-in logs, and any attacker-created inbox rules as evidence — do not wipe devices or delete emails.
Does cyber insurance cover business email compromise?+
It depends on the policy — read yours before you need it. Many policies include BEC coverage under 'social engineering fraud' or 'funds transfer fraud,' but frequently with a sublimit ($100k–$250k) that is much lower than the overall policy limit. Common exclusions or denial triggers include: MFA not enforced on the compromised mailbox, no written callback procedure, no dual approval on wires, and late notice to the carrier (most require notification within 72 hours). Ask your broker to specifically confirm BEC sublimits, required controls, and notification deadlines in your policy.
What is the difference between BEC and phishing?+
Phishing is a mass, low-effort attack that sends the same malicious email to thousands of recipients hoping a small percentage click. BEC is a targeted, high-effort attack against a specific organization or individual, usually launched from inside a legitimate compromised mailbox after the attacker has read weeks of email context. Phishing is defeated primarily by email security gateways and user training; BEC is defeated primarily by process controls (callback rule, dual approval), mailbox hardening (passkeys, DMARC, audit alerts), and rehearsed incident response. Most Miami owners who feel confident about phishing defenses are underprepared for BEC.
How do AI voice clones change BEC risk?+
Significantly. A 30-second sample of an owner's voice — scraped from an Instagram Reel, a podcast interview, or a Zoom recording — is enough to produce a convincing real-time clone using off-the-shelf tools. Attackers now routinely follow a fraudulent wire email with a phone call from the 'owner' confirming the transfer. This defeats the old advice to 'call the sender to verify' unless the verification call is placed outbound by the controller to a phone number they already had (not any number in the email or provided during the call). The written callback rule remains effective; ad-hoc verification does not.
// miami, fl services
Cybersecurity built for South Florida
// need help applying this?
Book a free, confidential consultation.
Our engineers can map this to your environment in 30 minutes.
Get secured// keep reading
Related articles

Personal Cybersecurity
Personal Cybersecurity for Miami Business Owners (2026): The Playbook Attackers Don't Want You to Have
In Miami, attackers stop targeting your company and start targeting you — the owner. This 2026 field guide from Cybrvault walks South Florida founders, executives, and family offices through the exact personal cybersecurity stack (devices, accounts, MFA, home network, family, travel, and wire-fraud defense) that stops the attacks we actually respond to every week.

Regional
The Miami Cybersecurity Landscape: Why South Florida Is a Target
International banking, crypto, maritime trade and high-net-worth residents make Miami one of the most heavily targeted metros in the United States. Here's what we see from the ground — and what local businesses should actually do about it.

Threats & Scams
Social Engineering Attack Examples: 12 Real Scams Hitting Miami Businesses in 2026
Social engineering is behind more than 74% of breaches. This 2026 guide walks through 12 real social engineering attack examples — from CEO wire-fraud emails and vishing calls hitting Brickell finance teams to QR-code phishing in Wynwood coworking spaces — with the exact red flags, sample scripts, and Miami-specific defenses your team needs.
