September 9, 2026

The Invoice That Looked Completely Ordinary: Business Email Compromise in Philippine SMEs

No malware, no suspicious link, and a sender who genuinely is who they claim to be. How business email compromise unfolds, the Microsoft 365 controls that detect it, and the payment process change that stops it.
A thread of identical messages with one carrying different account digits

Business email compromise does not rely on malware, so there is nothing for your antivirus to catch. An attacker gets into a mailbox, reads months of correspondence, learns how your company writes, waits for a genuine invoice thread, and changes the bank details. The email that costs you the money looks exactly like every other email in that thread.

The short answer

Two controls stop most of it. Enforce multifactor authentication so the mailbox is harder to enter, and require a callback to a previously known number before any bank detail change is actioned. The second one costs nothing and stops the attack even when the first one has already failed.

How it actually unfolds

The compromise and the theft are separated by weeks. That gap is what makes this difficult to detect and easy to underestimate.

Access. Credentials arrive from a phishing page, a password reused from a breached site, or a spray against a legacy protocol that never asked for a second factor. No malware is involved, so nothing is installed and nothing is quarantined.

Observation. The attacker reads. Who approves payments, which suppliers invoice monthly, how your finance team phrases a payment confirmation, when your accounts run. This is often silent for four to eight weeks. Frequently a mailbox rule is created that moves messages containing words like "invoice" or "payment" to an obscure folder, so the legitimate owner never sees the thread that is being hijacked.

Insertion. When a real invoice arrives, the attacker replies in the existing thread. Correct subject line, correct history quoted beneath, correct tone. One detail differs: the account number.

Collection. Payment is made. The funds move through a receiving account and out within hours. Recovery depends almost entirely on how quickly the transfer is reported.

Why the usual defences do not see it

Antivirus inspects attachments and links. There are none.

Anti-spoofing checks whether the sender is who they claim to be. The sender genuinely is who they claim to be, because the attacker is inside that mailbox.

Staff training tells people to look for poor spelling and unfamiliar addresses. The message has neither. It is a well-written reply from a supplier your team has corresponded with for years.

This is why business email compromise persistently costs organisations more than ransomware does, while attracting a fraction of the attention.

The Microsoft 365 controls that matter

Enforce MFA, including on legacy protocols

Most mailbox compromises begin with a password used somewhere it should not have been. MFA stops the majority of them, but only where it is actually enforced. Legacy authentication protocols cannot present a challenge, so blocking them tenant-wide closes the path attackers try first.

Turn on mailbox auditing

Without it, you cannot answer the question that matters after the fact: what did they read, and for how long? That answer determines whether you have a notifiable personal data breach, and it is not reconstructable later if the logging was off at the time.

Alert on inbox rule creation

A rule that moves invoice-related mail to a rarely used folder is one of the strongest indicators available, and it is easy to alert on. Very few legitimate users create rules that hide payment correspondence from themselves.

Alert on impossible travel and unfamiliar sign-in properties

A sign-in from Manila and another from an unrelated country twenty minutes later is worth investigating. These alerts exist in Entra ID and are frequently left unconfigured.

Review mail forwarding

Automatic forwarding to external addresses gives an attacker a copy of everything without needing to return to the mailbox. Block it by policy and review the exceptions.

The control that works even when the others have failed

Every one of the technical measures above can be defeated by a determined attacker or an unlucky day. The process control cannot.

Any change to supplier bank details requires a phone call to a number you already held, before payment.

Not a number in the email requesting the change. Not a number on the attached letterhead. The number in your supplier records from before the request arrived.

Write it into your payment procedure, tell your suppliers you do this, and apply it without exception. A supplier who is offended by a verification call is a supplier who has not yet been targeted.

If it has already happened

  1. Call the bank immediately. Recovery is measured in hours. Ask for a recall on the transfer.
  2. Reset the credentials and revoke active sessions. A password reset alone does not end a session that already holds a token.
  3. Look for the rules. Inbox rules and forwarding are usually still in place, and finding them tells you how long the attacker had access.
  4. Establish what was accessible. If personal information was in that mailbox, you may have a notifiable breach under the Data Privacy Act, with a seventy-two hour window.
  5. Tell the other party. If the compromise was on your side, the supplier or client on the other end of the thread needs to know their correspondence was read.
  6. Report it. The PNP Anti-Cybercrime Group and the NBI Cybercrime Division both accept reports, and a report supports any insurance claim.

Frequently asked questions

Would our antivirus or spam filter have caught this?

No. There is no malicious payload to detect and the sender is legitimate. Detection has to come from identity and behaviour signals rather than content inspection.

Is this the same as phishing?

Phishing is often how the access is obtained, but the compromise itself is different. Phishing asks you to click something. Business email compromise asks you to do exactly what you already intended to do, into a different account.

Can the money be recovered?

Sometimes, if reported within hours. Recovery rates fall sharply after the first day, which is why the bank call comes before the internal investigation.

Does this count as a personal data breach?

If personal information was accessible in the compromised mailbox, quite possibly. The assessment turns on what was in there and the risk of harm to the individuals concerned. Establish the scope quickly, because the seventy-two hour clock starts when you become aware.

We are small. Are we really a target?

Smaller organisations are targeted more, not less. Payment approval is informal, verification procedures are rarely written down, and one person often holds several roles. The attack scales cheaply, so a modest invoice is still worth an attacker's time.

Where to start

Onprem2Cloud IT Solutions Co. is a Microsoft Cloud Solution Provider based in Muntinlupa City, serving businesses and government agencies across Metro Manila and beyond. Our cloud security posture assessments cover exactly the gaps this attack exploits: MFA enforcement and coverage, legacy authentication, mailbox auditing, forwarding and inbox rule policies, and sign-in risk configuration.

See our cybersecurity services, or get in touch to discuss an assessment of your tenant.