
Key Takeaways
- IC3 recorded 21,442 business email compromise complaints in 2024, with $2,770,151,146 in losses
- That averages $129,193 a complaint, second only to investment fraud among IC3 categories
- Progress billing gives an attacker a predictable date, amount, and recipient to imitate
- CMMC Level 2 is the 110 requirements of NIST SP 800-171 Rev 2, including awareness training
- Simulate the payment-change request your firm really receives, drawn from your own mail
Your project accountant receives an email from a subcontractor that your firm has paid 11 times this year. On that email the bank details have changed, the invoice matches the schedule of values, and the sender address looks right. Approving those details takes one click and moves a progress payment to somebody else's account.
Requests of that kind are what make an engineering firm attractive to attackers. Their progress billing runs to a predictable calendar, the amounts are large, and the people approving them handle dozens of similar instructions a month. An attacker imitating those instructions needs to break nothing technical to get paid.
So the control that matters is the one nearest the approval, which is where phishing simulation software earns its budget. Your gateway filters a great deal, and every message that survives it arrives with somebody holding payment authority. That person is the last control standing between the request and the payment.
What the Numbers Say About This Category
Those approvals are worth counting, and the FBI's Internet Crime Complaint Center recorded 21,442 business email compromise complaints in 2024, carrying $2,770,151,146 in reported losses. That is an average of $129,193 for every complaint filed, which is second only to investment fraud across IC3's categories. Very few categories cost that much per incident.
Those complaint figures cover a single year, and scale over time explains why the technique persists. IC3's own public service announcement puts the global exposed loss from that technique at $55,499,915,582 between October 2013 and December 2023. A loss of that size accumulates because the method keeps working, and a better firewall does not change it.
BEC also does not lead on volume, and that is the part worth understanding. Phishing and extortion generate far more complaints, so BEC attracts less attention while costing more per incident than almost anything else listed. Volume and severity point in opposite directions for this category.
Stage | What the attacker relies on | What stops it |
|---|---|---|
Vendor bank change | A plausible email and a busy week | Callback on a number already held |
Progress billing | A predictable date and amount | Matching against the contract record |
Change order | Urgency near a milestone | A second approver on the change |
Final retention release | A large single payment | Verification outside email |
Train the People Who Approve the Payment
Run simulations built from the payment-change requests your firm really receives, so recognition is practised before it is needed.
Why Simulation Works Where a Policy Does Not
Those losses explain why a written policy is not enough on its own, because a policy tells somebody what to do when they already suspect a payment request. Recognizing that a request deserves suspicion is a different skill, and it is the one that fails under time pressure near a milestone. Simulation is how that recognition gets practiced before it matters.
How realistic that simulation is decides whether the practice transfers to the real request. A generic prize email teaches your team to spot a generic prize email. A simulated bank-detail change from a subcontractor you pay monthly teaches them to pause on the request they will really see.
Realistic scenarios also produce results that tell you where to spend the next hour. A click rate across the whole firm is a number, and a click rate among the 9 people who can release a payment is a risk register. Those 2 populations need different training and usually get the same.

What Federal Work Adds to the Requirement
Beyond that commercial risk, firms doing defense work carry a documented obligation as well. DFARS clause 252.204-7012 requires adequate security for covered defense information and flows down to subcontractors at every tier. That flow-down is why a 20-person specialist consultancy inherits the same expectations as the prime.
CMMC turns that expectation into something measurable. Level 2 consists of the 110 security requirements of NIST SP 800-171 Revision 2, incorporated by 32 CFR Part 170, and awareness and training is one of the families inside them. Security awareness gets assessed there, which is a different standard from being mentioned in a handbook.
That assessment carries one footnote worth knowing before you plan against it. NIST withdrew Revision 2 in May 2024 in favour of Revision 3, while CMMC continues to point at Revision 2 by rule. Your assessment runs against Revision 2 until that rule changes.
How to Build a Simulation Program That Changes Behavior
Meeting both the commercial and the contractual side takes 7 decisions, and the first of them does most of the work, because everything after it depends on knowing who is in scope:
- List everyone who can approve, release, or change a payment instruction
- Build scenarios from your own vendor correspondence, month by month
- Include a bank-detail change, since that is the request that really arrives
- Time one simulation near a real billing milestone, when pressure is highest
- Measure click rate for the payment-authority group separately from the firm
- Route a click straight into a short module on verification, the same day
- Repeat quarterly, because the population with payment authority keeps changing
Of those 7, line 5 is the one that changes what you do next. A firm-wide rate of 4% feels reassuring until you learn that 3 of the 9 people who can release funds were among the clicks. That breakdown is available from the same simulation and rarely gets asked for.
How KnowledgeCity Supports Payment-Approval Security
Those 7 decisions describe what KC Phishing runs, reporting results by group, so the payment-authority population is visible on its own. Scenarios come from the correspondence patterns your own firm already receives. A click routes the person into follow-up training the same day.
Training and evidence belong together for anyone under a flow-down clause, and KC LMS holds those completions against the version of the procedure in force. Our guide to compliance training covers the wider program. Both records end up supporting the same assessment conversation with an auditor.
Start by counting the people at your firm who can change a vendor's bank details. Whoever runs construction and engineering security training will usually find the list longer than finance expects. That count is where your next simulation should point.
Frequently Asked Questions
1. How large is business email compromise as a category?
IC3 recorded 21,442 complaints in 2024 with $2,770,151,146 in reported losses, an average of $129,193 each. That per-complaint figure is second only to investment fraud. Cumulative global exposed loss reached $55,499,915,582 between October 2013 and December 2023.
2. Why are engineering and construction firms targeted?
Progress billing runs to a predictable calendar with large amounts and familiar counterparties. An approver handling dozens of similar instructions a month is working from pattern recognition, which is exactly what a well-built imitation defeats.
3. What makes a simulation effective?
Scenarios drawn from your own correspondence. A simulated bank-detail change from a subcontractor you pay monthly rehearses the decision your team will really face. A generic prize email rehearses a decision nobody makes.
4. Does federal work change the requirement?
DFARS 252.204-7012 requires adequate security for covered defense information and flows down to subcontractors at every tier. CMMC Level 2 consists of the 110 requirements of NIST SP 800-171 Revision 2, incorporated by 32 CFR Part 170, and includes awareness and training.
5. Which number should we track?
Click rate among the people who can approve or change a payment, reported separately from the firm-wide number. A 4% firm-wide rate can still mean a third of your payment-authority group clicked. That breakdown is what decides the next action.
References
- Federal Bureau of Investigation, Internet Crime Complaint Center. 2024 Internet Crime Report.
- Federal Bureau of Investigation, Internet Crime Complaint Center. Business Email Compromise: The $55 Billion Scam.
- Legal Information Institute, Cornell Law School. 48 CFR 252.204-7012, safeguarding covered defense information.
- National Institute of Standards and Technology. SP 800-171 Rev. 2, Protecting Controlled Unclassified Information.
- Electronic Code of Federal Regulations. 32 CFR Part 170, Cybersecurity Maturity Model Certification Program.