Security
Business email compromise prevention
Business email compromise prevention on Google Workspace rests on 3 layers: technical controls that block display-name spoofing and alert on new forwarding rules, a payment process requiring callback verification on any bank detail change, and a supplier verification step that never uses contact details taken from the requesting message.
| Display-name spoof blocking | Impersonation of directors in the From header |
|---|---|
| External sender banner | Lookalike domains posing as internal staff |
| Forwarding rule alerts | Silent exfiltration after compromise |
| Payment callback rule | Bank detail changes from real supplier mailboxes |
| Dual authorisation | Single-approver payments above threshold |
| Median detection gap | 11 days between compromise and fraud attempt |
The technical layer, and its ceiling
Gmail can block inbound mail spoofing your own domain, warn on employee-name impersonation from external addresses, flag lookalike domains, and stamp external senders with a banner. Turning all of that on is an afternoon of work and it removes the cheap end of the attack entirely.
The ceiling is reached the moment the attacker is inside a genuine supplier mailbox. The message is authentic, aligned, from a domain with good reputation, and the request is plausible because it references a real invoice. Nothing in the mail layer will stop it, and vendors implying otherwise are selling against a threat model that no longer applies.
Alerting on the behaviour that precedes fraud
Compromise is usually quiet for days before money is requested. During that window the attacker reads mail, learns the invoice cycle, and sets up a filter so the real user does not see the replies. Alert rules on filter creation, forwarding to external addresses, delegate additions and unusual login geography catch that period.
These alerts have a low false-positive rate in most organisations because ordinary staff rarely create forwarding rules. Where they do — a shared role mailbox, a departing employee's redirect — the exceptions are few enough to allowlist by name rather than by rule.
- Alert on any new external forwarding address
- Alert on new mailbox filters that delete or archive on match
- Alert on mail delegation being granted
- Alert on login from an unexpected country for privileged accounts
- Review OAuth grants weekly for anything with Gmail send scope
The process layer, which is where it is actually stopped
One rule prevents the majority of loss: no change to bank details is actioned without a voice callback to a number already held in the supplier record, made by someone other than the person who received the request. Not a number in the email signature, and not a number in the attached letterhead.
Add a payment threshold above which two named approvers are required, and a monthly reconciliation that lists every changed payee. These are finance controls rather than IT controls, which is exactly why they are so often missing — nobody owns the boundary, and the IT audit stops at the mailbox.
If it has already happened
Suspend the account rather than resetting the password first, because a password reset leaves existing sessions and application-specific access alive. Then revoke sessions and OAuth tokens, remove filters and forwarding, and export the audit log before the retention window closes on the period of interest.
Contact the receiving bank within hours: recovery rates fall sharply after the first day and to near zero after a week. Report to Action Fraud in the UK or the IC3 in the US, notify the supplier whose mailbox may be the actual point of compromise, and record the timeline while people still remember it.
What we see that others don't say
In the compromises we investigate, the attacker's first action is almost never the fraudulent request; it is a mail filter that files replies from the finance team into an obscure label, so the legitimate owner never sees the conversation happening in their own mailbox.
What this doesn't cover
- No mail control stops a fraudulent instruction sent from a genuinely compromised supplier mailbox. That is prevented by payment process, not by filtering.
- We are not a forensic investigation firm. We preserve logs and produce a timeline; a formal forensic report for insurers or litigation needs a specialist.
- We do not recover transferred funds. Recovery is a matter for your bank and law enforcement, and speed decides it.
- Payment authorisation rules require a decision from your finance function; we can write and rehearse them but cannot impose them.
Get a fixed price for this
Send your seat count, current platform and deadline. You get a fixed price and an available cutover date, usually within one working day, from the engineer who would run the work.
Prefer to talk? Call +44 20 7183 3436 (Mon–Fri 08:00–18:00 GMT), or message WhatsApp +44 7403 423563.
Questions we get asked
- What is the single most effective BEC control?
- A voice callback on any bank detail change, to a number already held in the supplier record, made by someone other than the recipient of the request. It stops the attack the mail layer cannot see.
- How do we detect compromise before money moves?
- Alert on new forwarding rules, filters that archive or delete, delegation grants and unexpected login geography. Those precede the fraudulent request by days in most cases.
- Does DMARC enforcement prevent BEC?
- It stops attackers spoofing your own domain, which is one route among several. It does nothing about lookalike domains or genuinely compromised third-party mailboxes.
How this page is verified
Reviewed by Workspace Migration Services security desk, Workspace security and compliance reviewers. Last checked .
- Alert rule availability reflects the Google Workspace admin console alert centre as of 2026-08-06.
- Detection-gap observations come from Workspace Migration Services incident engagements to 2026-08-06.
- Reporting routes reference Action Fraud (UK) and IC3 (US) as published on 2026-08-06.
Sources you can check
Cite this page
Free to reuse with attribution. Copy whichever form your publication needs.
Plain citation
Workspace Migration Services, "Business email compromise prevention", https://workspacemigration.services/security/business-email-compromise-prevention (last checked 2026-08-06).HTML with source link
<p>Creating a mailbox filter or forwarding rule is the most reliable early indicator of Google Workspace account compromise, and it is visible in the admin audit log before any fraudulent payment is requested. Source: <a href="https://workspacemigration.services/security/business-email-compromise-prevention">Business email compromise prevention</a> — Workspace Migration Services.</p>Embed this table
<table>
<caption>Business email compromise prevention — Workspace Migration Services, 2026-08-06</caption>
<tr><th>Display-name spoof blocking</th><td>Impersonation of directors in the From header</td></tr>
<tr><th>External sender banner</th><td>Lookalike domains posing as internal staff</td></tr>
<tr><th>Forwarding rule alerts</th><td>Silent exfiltration after compromise</td></tr>
<tr><th>Payment callback rule</th><td>Bank detail changes from real supplier mailboxes</td></tr>
<tr><th>Dual authorisation</th><td>Single-approver payments above threshold</td></tr>
<tr><th>Median detection gap</th><td>11 days between compromise and fraud attempt</td></tr>
</table>
<p><a href="https://workspacemigration.services/security/business-email-compromise-prevention">Business email compromise prevention</a> — data maintained by Workspace Migration Services.</p>Related pages
Close the invoice-fraud gap
We turn on the spoofing and forwarding alerts, write the callback rule with your finance team, and rehearse the first hour of a compromise so nobody improvises.