Phishing has become a business-process problem as much as an email problem. Attackers imitate suppliers, directors, colleagues and Microsoft sign-in pages because a convincing request can bypass technology by persuading a legitimate employee to take the action for them.
Why payment fraud deserves its own training
A business can have spam filtering and endpoint security and still lose money when a genuine employee follows a convincing instruction. Training should therefore cover the human verification process around payments, supplier changes and urgent requests, not simply tell people to avoid suspicious links.
Teach staff to verify changes through a second channel
If a supplier asks for new bank details, the safest response is to verify the change using a trusted phone number or known contact route rather than replying to the same email thread. The same principle applies to unusual requests from directors and colleagues.
- Do not trust urgency as proof of legitimacy
- Verify bank-detail changes independently
- Treat unexpected MFA prompts as a security warning
- Use known contact details rather than details supplied in the suspicious message
- Escalate unusual payment requests before acting
Business email compromise can look completely legitimate
When an attacker controls a genuine mailbox, there may be no obvious spelling mistake or fake domain. They can read existing conversations, wait for an invoice and insert themselves at the right moment. Staff therefore need to recognise changes in behaviour and process, not just visual signs of a fake email.
MFA reduces risk but does not replace judgement
Multi-factor authentication is an important control, but staff still need to understand MFA fatigue, fake login pages and requests to approve a prompt they did not initiate. A user who understands why an unexpected prompt matters is more likely to report it quickly.
Finance and management teams should practise together
Payment fraud crosses departmental boundaries. A practical exercise involving finance, management and IT is more useful than training each team in isolation because it exposes gaps in verification, escalation and incident communication.
Turn the exercise into a written payment-control process
After training, document the rules for supplier changes, high-value payments, new beneficiaries and urgent requests. Clear controls make it easier for staff to challenge suspicious instructions without feeling that they are obstructing the business.
Frequently asked questions
What is business email compromise?
It is a form of fraud in which an attacker impersonates or compromises a trusted business email account to manipulate payments, information or access.
Can Microsoft 365 security stop all phishing?
No single control stops every attempt. Technical controls, strong identity protection and staff verification processes need to work together.
Who should receive payment-fraud training?
Finance staff, directors, executive assistants, operations teams and anyone who can change supplier details, release payments or approve sensitive requests should be included.