← Back to Blog

August 21, 2026 · Backgrounder Team

Why Invoice Fraud and Business Email Compromise Still Works

We've seen an uptick in business email compromise among our customers lately, and it's worth explaining why this keeps working — even with all the security Google and Microsoft build into Workspace and Office 365.

Every mainstream email security tool answers "is this message bad?" by scanning content, links, and sender history. BEC has no payload to scan, so it slips right past.

Why the giants miss it

Google/M365 native tools, Abnormal, Proofpoint — they all work the same way: analyze the message on the gateway, before or after delivery, looking for something malicious to flag. BEC defeats that model because it's pure identity impersonation with nothing to detonate.

Gmail and Google Workspace

  • Google's filters are trained on bulk phishing and malware. A single targeted email with no payload triggers none of those models.
  • Google has no way to know a legitimate, authenticated email from vendor@realsupplier.com is fraudulent — the domain is real, DMARC passes, and the account is genuinely compromised.
  • Lookalike domains often pass if they haven't been flagged yet, since new domains have no reputation history to draw on.

Outlook and Microsoft 365

  • Microsoft Defender for Office 365 has BEC detection, but it leans on behavioral baselines that take time to build — and attackers who move slowly and mimic normal behavior can slide under them.
  • Legacy protocols like IMAP, SMTP AUTH, and POP3 skip modern authentication entirely. If they're not blocked, credentialed attackers get in without tripping conditional access policies.
  • Stolen session tokens look like valid authenticated sessions to Microsoft — it sees a legitimate token, not an attack.
  • A compromised account already has sender reputation built up, so its outbound fraud emails don't get flagged.

Traditional email security tools

  • No malicious payload to scan. These tools are built for URL and attachment sandboxing. A plain-text wire transfer request has nothing to detonate.
  • Lookalike domain detection is imperfect. Proofpoint and similar tools catch some lookalikes, but attackers register domains weeks or months ahead to build reputation, use different TLDs, or add plausible subdomains.
  • Internal traffic often skips scrutiny. If the attacker is operating from inside a compromised mailbox, mail can route internally and bypass the gateway — or get a lighter look than external mail would.

A different question

Backgrounder's Ask Carmen mobile app and browser extension take a different approach to business email compromise and impersonation. Instead of asking whether a message looks malicious, we ask: is the person, vendor, or company this email claims to be actually real?

Not ready to hand over your whole inbox? You don't have to — automate full analysis, or choose which messages to send for review.

Mail comes in through three ingestion paths — Gmail/Graph API watch, ARC-aware MX forwarding, and native Report-to-Workspace Alert Center — into our agentic-researcher engine, which checks identity against 60+ OSINT sources: domain age and WHOIS, GLEIF/SEC/FINRA registries, OpenSanctions, people-verification, and reputation feeds. That produces a verdict, both passively and on demand.

Set it and forget it, or investigate case by case. The output lands as an adjudication email, an IR/SOC alert, a SIEM webhook, or a case timeline — whatever fits how your team works.

Want to see it in action? Get in touch and we'll set up a demo.

Stay one step ahead of scams

Spot red flags early and protect yourself, your family, and your business

Try for free