By Leah Price
Updated May 2026
Business Email Compromise is one of the most expensive forms of corporate fraud in operation today, and a meaningful share of it is tied to networks based in Nigeria. The category does not look like the cybercrime most companies prepare for. There is no malware alert, no system intrusion notification, no IT incident to escalate. There is just one altered payment instruction, processed by a finance team that believed it was paying a known supplier, that ends up in an account no one in the company has ever heard of. By the time the supplier calls asking about non-payment, the funds are usually already moving.
Companies dealing with a suspected BEC incident often work with a private investigator in Nigeria as part of a broader response, typically run as a scam and fraud investigation alongside bank notification and counsel. The investigation question is usually not whether fraud occurred — by the time the call comes in, that’s clear — but where the funds went, who controlled the receiving infrastructure, and what evidence package supports recovery, insurance, and law enforcement reporting.
TL;DR
Nigeria-linked BEC operations target supplier payments, vendor relationships, and executive workflows rather than IT systems. The most common patterns are supplier payment redirection, compromised vendor email accounts, and executive impersonation. Recovery becomes meaningfully harder after 24-72 hours, and once funds clear into crypto conversion, options narrow sharply. EFCC and FBI cooperation has produced large-scale takedowns, but individual cases still depend on company-side speed.
Key Facts
- FBI IC3 reported approximately $2.9 billion in BEC losses for 2023 across roughly 21,000 complaints, making it one of the highest-loss complaint categories the bureau tracks each year.
- EFCC (Economic and Financial Crimes Commission) is Nigeria’s primary law enforcement body for financial crime, and has cooperated with the FBI on multiple large BEC takedowns — including Operation reWired (2019), which resulted in 281 arrests across multiple countries.
- BEC is engineered to bypass technical defenses entirely — the point of attack is the finance workflow, not the email server, which is why traditional cybersecurity tooling often misses it.
- Nigeria is dominant but not exclusive — BEC operations also run from other West African countries, Eastern Europe, and parts of Asia, frequently using shared mule and crypto-conversion infrastructure across jurisdictions.
Why BEC Operations Concentrate in Nigeria
BEC has been a documented specialty of Nigeria-linked cybercrime networks for over a decade, and the operational reasons are practical rather than cultural. The country has a large English-speaking population with strong written-English fluency — essential for impersonating Western executives and vendors convincingly. There is significant exposure to international banking through the diaspora and remittance economy, which provides familiarity with the rails BEC exploits. And the same EFCC enforcement actions that have generated takedowns also document the persistence of the underlying operations, which adapt and reorganize after each disruption.
It is worth being explicit about what this is and isn’t. The networks are organized criminal operations actively pursued by Nigerian law enforcement, not a description of Nigeria as a country or its business culture. EFCC has been one of the more aggressive financial-crime enforcement agencies in West Africa, and the FBI has publicly acknowledged ongoing cooperation across multiple cases. The scam is real, the geography is real, and the enforcement push from inside Nigeria is also real.
The Three Patterns That Cover Most Cases
Supplier payment redirection is the most common variant. The operation monitors active vendor relationships — often through a compromised inbox on the supplier side — and waits for an invoice cycle. When an invoice is due, a modified version arrives in the buyer’s inbox with the bank details changed and everything else identical: same logo, same signature block, same formatting, same payment history language. The buyer’s AP team processes what looks like a routine payment to a familiar vendor, and the funds land in an account that has nothing to do with the actual supplier.
Compromised vendor accounts take this further. Instead of spoofing a vendor’s email, the operation gains access to the real vendor’s mailbox through credential reuse, phishing, or stolen credentials sold on dark-web markets. The fraudulent emails come from the legitimate domain, with intact thread history and language patterns that match the real vendor’s writing style — often because the operation has been reading prior emails for weeks before acting. None of the technical signals that a finance team might be trained to watch for are present, because nothing technical is wrong with the email itself.
Executive impersonation and payroll fraud is the third pattern. A look-alike domain (the classic example: replacing a lowercase “l” with a “1” or registering a .co domain instead of .com) gets paired with a forged display name and an urgent message to a finance employee. The request is for a same-day wire transfer, a payroll redirect, or a confidential payment that “the CEO doesn’t want discussed in the chain.” The pressure to act fast and the seniority of the apparent sender combine to short-circuit the verification process the company would otherwise run.
How Targets Get Selected
BEC is research-intensive, not opportunistic. Operations build target profiles from publicly available sources: LinkedIn for org charts and reporting lines, procurement portals for active vendor relationships, job postings for accounting software and tooling clues, financial filings for payment cycle indicators, and breached credential databases for inbox access. The reconnaissance phase often runs for weeks before any fraudulent email is sent, because the goal is a payment instruction that fits cleanly into the company’s existing workflow rather than one that triggers verification.
Mid-sized companies with established vendor relationships are particularly exposed. Small enough that finance controls may be informal, large enough that wire amounts are meaningful, and structured enough that workflow predictability gives the operation what it needs to insert itself at the right moment. Manufacturing, logistics, construction, healthcare, and SaaS companies appear repeatedly in case patterns, partly because their vendor structures are predictable and partly because their payment volumes make the math work for the operation.
Why Recovery Is So Hard
The recovery window is a function of how the rails work, not how good the response is. International wire transfers finalize quickly. Once funds settle into the receiving account, the bank-to-bank cooperation needed to claw them back depends on the receiving bank’s policies, the jurisdiction’s mutual legal assistance treaties, and how fast the originating company moves — often within hours, not days. After the first hop, mules typically withdraw cash or move funds to a second account, then a third. Each hop reduces recovery options.
Crypto conversion is where most cases become unrecoverable. Once funds are converted to USDT or BTC and routed through mixers or offshore exchanges, the wallet activity remains traceable but the funds themselves usually do not come back. That tracing has real value — it supports law enforcement reporting, insurance claims, and the linkage of individual cases to wider operations — but it does not reverse the loss in the way an early bank recall sometimes can.
The hardest cases are the ones where the fraud is discovered after the supplier flags non-payment, which is often a week or more after the wire went out. By that point the funds have moved through several accounts, the receiving infrastructure has rotated, and the realistic outcome is documentation rather than recovery.
What an Investigation Actually Does
Email header and server analysis establishes the actual origin of the fraudulent communication, including whether the company’s own systems were compromised or whether the breach was on the vendor side. Compromised account timeline reconstruction surfaces when access began, what was read, and which prior communications informed the eventual fraudulent message — important both for understanding the breach and for assessing the company’s own security exposure.
Bank account ownership tracing maps where funds went and who controlled the receiving accounts. Wire routing analysis follows the path through correspondent banks. If crypto conversion occurred, on-chain wallet analysis maps the post-fiat flow and tests for clustering with previously reported addresses — that linkage often connects a single case to a wider operation visible in IC3 and EFCC reporting. Mule network identification surfaces the individuals whose accounts received the funds, which is legally relevant for both criminal complaints and civil recovery.
The output is an evidence package designed to support the company’s bank in any recall attempt, the company’s cyber insurance carrier in a claim, and law enforcement (typically IC3 in the US, EFCC in Nigeria, and equivalent bodies in the EU) in case referral. None of that is dramatic. It is the structured documentation that makes recovery and reporting actually work.
What Companies Should Do Right Now
If a transfer has already gone out and the situation is unfolding live, contact the originating bank immediately — within the same day, ideally within the same hour — and request a SWIFT recall. Banks can sometimes hold funds before they settle into the receiving account. Notify the company’s cyber insurance carrier. Preserve all email evidence including full headers, do not delete anything, and avoid forwarding the suspect emails (forwarding can alter headers in ways that complicate analysis). File an IC3 report — IC3 has direct relationships with the FBI BEC task force and routes complaints to the right unit.
Verify any pending payment requests through a known phone number — not a number contained in the suspect email — before processing. Lock down the inboxes that may have been compromised, rotate credentials, and review login history for unusual access patterns. If a vendor relationship is involved, notify the vendor through a known channel and treat their inbox as potentially compromised until proven otherwise.
External Reference Points
For broader context, three resources are worth reviewing: the FBI Internet Crime Complaint Center, which publishes annual data on BEC losses and trends and routes complaints to the FBI BEC task force; the Economic and Financial Crimes Commission, Nigeria’s primary financial-crime enforcement body, which has prosecuted multiple BEC cases and cooperated with the FBI on large-scale takedowns; and the Europol Cybercrime Centre, which tracks the same operations from the European law enforcement side.
FAQ
Is BEC usually an inside job?
Almost never. The vast majority of BEC cases involve external compromise — stolen credentials on the vendor side, look-alike domains, or compromised inboxes — rather than employee collusion. Internal investigations sometimes start with that suspicion, but the evidence trail typically points outward.
Can banks reverse BEC payments?
Sometimes, if the bank is notified before the funds settle and clear into the receiving account. The window is narrow — often hours, not days — and depends on cooperation from the receiving bank. After the first hop, recovery options drop sharply, and after crypto conversion they narrow further.
Should we pay a “reversal fee” if someone offers to recover the funds?
No. Unsolicited offers to recover lost funds in exchange for an upfront fee are a separate category of fraud that specifically targets BEC victims. Legitimate recovery happens through banks, law enforcement, and counsel — not through anonymous services that surface in a Google search after the loss.
How long does a BEC investigation take?
Initial tracing can begin within 24 hours of engagement and is the highest-value period. Full mapping of the email compromise, fund flow, and mule network typically takes one to three weeks depending on complexity, jurisdictions involved, and how quickly bank and crypto exchange cooperation comes through.
Final Thoughts
BEC succeeds because it hides inside normal business processes. The email looks right. The thread looks right. The payment instruction looks right. There is no malware to detect and no system failure to escalate, just a single altered routing detail that the AP team has no reason to question. Companies that treat supplier verification as a security control rather than an administrative formality — out-of-band confirmation for any banking change, dual approval on wires above a threshold, and a known-good callback number for every active vendor — significantly reduce their exposure.
If a transfer is already out and the situation is live, time is the variable that matters most. Contact Teser Investigations for a confidential quote and we will scope a BEC investigation, fund tracing, and evidence package to your case — initial tracing can begin within 24 hours, no obligation.
About the Author: Leah Price is the author behind Teser Investigations’ international fraud and verification content. She writes about romance scams, background checks, identity verification, and cross-border investigative issues, with a focus on helping clients verify claims before travel, financial support, or major personal commitments. Her articles reflect the kinds of risks clients face in Russia, Ukraine, Colombia, West Africa, and other international jurisdictions where deception, hidden relationships, and fraud often intersect.
