Business email compromise remains one of Singapore's costlier scam categories, but the headline number worth knowing is not the one still circulating from 2022. An SPF advisory issued that May recorded at least S$70.8 million lost across 149 victims since January of that year, a roughly four-month window rather than an ongoing multi-year total. More recent SPF reporting for the period since 1 January 2026 puts one common variant, requests to change a vendor's payment account details, at more than 66 cases with losses exceeding S$19 million, and the Police's own 2025 Annual Scam and Cybercrime Brief notes a significant decrease in amounts lost to business email compromise specifically, within an overall national scam and cybercrime loss figure that fell from S$1,112.4 million in 2024 to S$913.1 million in 2025.
That vendor-variant figure is far from the full 2026 picture. In April, the Anti-Scam Centre stepped in after the CEO of a Singapore-based company received a WhatsApp call from a scammer posing as the chairman of the firm's headquarters, and instructed his CFO to arrange funding for a supposed acquisition. Between 13 and 17 April, US$36.3 million moved out of the company's Luxembourg subsidiary and Singapore entity, US$27.1 million and US$9.7 million respectively, into two local bank accounts, before the deception was uncovered when the CEO verified the request with the actual chairman. Police seized the US$9.7 million domestically before the remaining US$26.5 million reached accounts in Hong Kong, and a further US$11.1 million was later recovered from Hong Kong bank accounts and cryptocurrency wallets through cross-border cooperation. That single case, an impersonated executive giving a verbal instruction rather than a lookalike email, moved more on its own than the entire vendor-variant total reported for the rest of the year. The pattern that matters for most SMEs is not the size of the largest cases, it is that no malware or network breach is required at all. Someone inside the business acts on a message that looked legitimate enough to act on, and by the time anyone questions it, the money has already moved.
How Business Email Compromise Actually Works
Business email compromise generally follows one of two patterns. In the first, the attacker registers a domain that is one character off the real one, a swapped or substituted letter, an extra hyphen, a different top-level domain, and emails from it impersonating a supplier, executive, or business partner. SPF's own reporting describes both variants in real Singapore cases: a 2024 case where an attacker replaced a single letter in the genuine supplier's domain, an “i” swapped for an “l”, and a 2026 case where a commodity trading firm transferred US$6.6 million to a fraudulent account in Oman after two letters in a supplier's domain were transposed rather than substituted. Both were close enough that staff processing the payment did not catch it. In the second pattern, and increasingly the more common of the two, the attacker has already compromised a real email account through a separate phishing or credential-theft attack, and is emailing from inside it. This defeats most of the visual cues people are trained to look for, since the sender address, signature, and writing style are all genuinely correct.
Both patterns converge on the same ask, usually timed for maximum plausibility: change a bank account number ahead of a routine payment, approve an urgent transfer while the usual approver is travelling or unreachable, action a request before someone senior is available to double check it. Singapore police reporting has specifically noted that scammers often exploit business relationships involving overseas dealings, where email is already the primary channel and a request for a changed account number does not automatically read as unusual.
Why Phishing Remains a High, Steady Threat
Phishing volume remains high in absolute terms, though the trend is closer to steady than sharply rising. The Anti-Phishing Working Group recorded 3.8 million unique phishing sites globally in 2025, against 3.76 million the year before, roughly a 1% increase that APWG itself describes as activity holding at a high but steady pace rather than accelerating. What has changed more than the volume is the quality: a meaningful and growing share of phishing emails are now written with AI assistance, which removes the awkward phrasing and obvious grammatical errors that used to be the easiest tell for a suspicious recipient. Steady volume combined with rising quality is arguably a more dangerous combination than a sharp spike would be, since it does not trigger the same heightened alertness a visible surge tends to produce.
Phishing also increasingly functions as the first step in a longer attack chain rather than the end goal itself. A successful phishing email harvests credentials or session tokens, which are then used for account takeover, which is in turn used to launch the actual business email compromise attempt from a genuine, trusted account. Treating phishing and BEC as separate problems with separate defences misses this connection.
The Email Security Controls That Actually Reduce This
- A callback policy for any change to bank details or payment instructions, made to a phone number already on file, never one supplied in the email itself, with no exceptions for requests marked urgent.
- A rule that payment instructions are never actioned from an email alone, regardless of who appears to have sent it or how senior they are.
- Mail flow rules and domain monitoring that flag lookalike domains before a message reaches an inbox, catching the impersonation pattern before a human has to.
- Multi-factor authentication enforced on every account with mailbox access, since Microsoft's own research shows MFA reduces account compromise risk by over 99%, including in cases where the password has already leaked.
- Regular, specific staff briefing on what a real BEC attempt looks like in your own business, rather than generic phishing awareness training that rarely reflects how the attack actually shows up in practice.
None of these require significant capital spend. What they require is that they are actually enforced, consistently, including under time pressure, rather than existing as a policy document nobody has been specifically asked to follow when an urgent-sounding request lands on a Friday afternoon.
Microsoft 365 Security and the BEC Connection
Business email compromise very often involves a Microsoft 365 tenant somewhere in the chain, either as the compromised account or as the platform the fraudulent request travels through. A properly configured tenant, MFA enforced without exception, admin access reviewed on a schedule, alerts turned on for new mail forwarding rules and unfamiliar login locations, closes off the majority of the easy paths in. A forwarding rule quietly added to a compromised mailbox is one of the most common ways an attacker maintains visibility into a target's correspondence for weeks before acting, and it is also one of the easiest things to alert on if anyone has configured the tenant to flag it.
Most of that configuration is already included in the Microsoft 365 licence a business is paying for. It is simply not switched on by default, and default settings on a platform this widely used are, by definition, the settings attackers already know how to work around.
Is your email and identity layer configured properly?
Email and identity security are covered in our MAS TRM readiness check for smaller firms.
Sources: Singapore Police Force advisories (May 2022; vendor payment-detail variant, 2026); SPF news releases on Operation Frontier III cases (April and May 2026) and the 2024 Timor-Leste case; SPF Annual Scam and Cybercrime Brief 2025, reported via Eftsure Payment Fraud Index; Anti-Phishing Working Group 2025 figures; Microsoft MFA effectiveness research.