By Eagle Tech Corp

September 2026 • 8-minute read

Quick Answer

Nonprofits can reduce the risk of business email compromise by combining Multi-Factor Authentication, stronger email security, user training, payment-verification procedures, identity protection, and proactive monitoring.

For organizations with 15-80 employees, the biggest risk is rarely just malicious software. It is often an attacker convincing a real employee to send money, reveal credentials, change banking information, or share sensitive data.

That makes business email compromise both a cybersecurity problem and a business-process problem. Technology can block many threats, but leadership also needs clear procedures for handling financial requests, account changes, and sensitive communications.

Key Takeaways

  • Business email compromise often relies on impersonation and social engineering rather than traditional malware.
  • MFA is essential, but it should be combined with email filtering, identity monitoring, and secure procedures.
  • Financial changes should always be verified through a second communication method.
  • Employees need practical training that reflects the types of scams they actually encounter.
  • AI can make fraudulent emails more convincing, increasing the importance of verification and cybersecurity awareness.

Boardroom Brief

Business email compromise succeeds because attackers exploit trust.

A fraudulent request may appear to come from an Executive Director, Board Member, vendor, finance employee, or trusted partner. If an attacker gains access to a real mailbox, the message may even come from the correct email address.

The safest nonprofit organizations therefore combine technical cybersecurity controls with clear operational procedures. Employees should know not only how to recognize suspicious emails, but also what actions require independent verification before money or information changes hands.

Business Email Compromise Is Different From Ordinary Spam

Most people recognize obvious spam.

Business email compromise is designed not to look like spam.

Instead, attackers attempt to imitate normal business communication. A message may ask the finance team to update vendor banking information, purchase gift cards, approve an urgent wire transfer, or send confidential employee records.

Sometimes the attacker impersonates an executive.

In other cases, the attacker compromises a legitimate email account and observes conversations before inserting themselves into an existing payment or vendor process.

That makes the attack far more difficult to recognize.

A polished email with the correct signature and familiar language can still be fraudulent.

Protect the Identity Before Protecting the Inbox

Email security increasingly begins with identity.

If an attacker obtains an employee's username and password, that account may provide access to email, Microsoft 365, files, Teams, SharePoint, and other cloud applications.

Multi-Factor Authentication significantly strengthens that first line of defense.

But MFA works best as part of a broader identity-management strategy.

Organizations should also review administrative privileges, disable unused accounts, promptly remove former employees, monitor suspicious sign-ins, and limit access based on job responsibilities.

The goal is straightforward:

If one account is compromised, how much of the organization can the attacker reach?

Good identity management limits that exposure.

Email Security Needs Multiple Layers

There is no single product that stops every malicious message.

Effective email protection uses multiple layers to identify suspicious senders, malicious links, unusual attachments, impersonation attempts, and other indicators of fraud.

For nonprofits using Microsoft 365, email security should be reviewed alongside the rest of the tenant configuration.

Policies that were acceptable several years ago may no longer reflect the organization's current risk.

This is another reason Managed IT and cybersecurity should not operate separately.

Email is one of the most important systems your staff uses every day, so protecting it should be part of ongoing IT management rather than an occasional security project.

Create a Verification Rule for Financial Changes

Some of the strongest protection against business email compromise has nothing to do with software.

Consider a message that appears to come from a longtime vendor:

"We've changed banks. Please use the new account information attached for all future payments."

The email may look completely legitimate.

Instead of asking employees to determine whether the email is "real," establish a business process that removes the guesswork.

For example:

Any request to change banking information, payment instructions, payroll information, or other financial details must be independently verified using a known phone number or previously established communication method.

Do not use the phone number contained in the suspicious email itself.

This simple procedure can prevent a convincing fraudulent message from becoming a financial loss.

Slow Down "Urgent" Requests

Attackers often create artificial urgency.

They want employees to act before they have time to ask questions.

Common themes include:

"Please handle this before my meeting."

"I need this wire sent today."

"Don't call me - I'm traveling."

"Purchase these cards immediately."

"Send me the employee tax information before noon."

The details vary, but the pressure is intentional.

Leadership should give employees explicit permission to slow down unusual requests.

A healthy cybersecurity culture does not punish someone for verifying a payment request from the Executive Director.

It rewards them for protecting the organization.

Train Staff Around Real Scenarios

Annual cybersecurity training has value, but employees need more than a generic presentation telling them not to click suspicious links.

Training should reflect the situations nonprofit employees actually encounter.

Finance teams need to understand payment diversion and banking-change fraud.

Human resources staff should recognize requests for payroll or employee data.

Fundraising teams should understand risks involving donor information.

Executives should know that their identities are especially valuable to attackers because employees are more likely to respond quickly to requests that appear to come from leadership.

The most useful training connects cybersecurity with real job responsibilities.

Eagle Insight

One of the most important cultural changes leadership can make is removing the fear of asking:

"Can I verify this before I proceed?"

Technology teams sometimes focus heavily on stopping every malicious email before it reaches the employee.

That's an important goal, but it is unrealistic to assume every fraudulent message will always be blocked.

A resilient organization assumes someone will eventually encounter a convincing attack and makes sure the employee knows exactly what to do next.

Good security gives people both tools and permission to question unusual requests.

AI Consideration

Generative AI is increasing the quality of social-engineering attacks.

Historically, phishing messages were often easy to recognize because of poor grammar, awkward phrasing, or obvious formatting mistakes. AI can help attackers produce professional-looking messages that sound more natural and can be tailored to a specific organization or role.

That means traditional advice such as "look for spelling mistakes" is no longer enough.

Nonprofits should train employees to focus on context and behavior instead:

Is this request unusual?

Does it involve money, credentials, or sensitive information?

Is someone trying to bypass the normal process?

Is there artificial urgency?

Can the request be verified independently?

AI does not fundamentally change the solution. It makes strong cybersecurity fundamentals and verification procedures even more important.

If an Account Is Compromised, Speed Matters

When an organization suspects that an email account has been compromised, the response should be immediate.

The IT team may need to reset credentials, revoke active sessions, review MFA settings, examine mailbox forwarding rules, inspect recent login activity, and determine what other systems the compromised account could access.

Leadership may also need to evaluate whether sensitive information was exposed or whether fraudulent messages were sent to donors, employees, vendors, or partners.

This is where having a documented incident-response process matters.

During an incident, you do not want the first question to be:

"Who are we supposed to call?"

That answer should already be documented.

A Simple Business Email Compromise Framework

Nonprofit leadership can think about protection in five stages:

Stage Objective
Protect Secure accounts with MFA, strong identity controls, and email security
Detect Monitor suspicious logins, inbox behavior, and unusual activity
Verify Independently confirm financial and sensitive requests
Train Teach employees how attacks relate to their actual jobs
Respond Have a documented process for suspected account compromise

No single control is perfect.

Together, however, these layers make it considerably harder for an attacker to turn one convincing email into a major business incident.

Frequently Asked Questions

What is business email compromise?

Business email compromise is a form of fraud in which attackers impersonate or compromise trusted email accounts to convince someone to send money, change payment information, provide credentials, or disclose sensitive information.

Does MFA prevent business email compromise?

MFA significantly reduces the risk of unauthorized account access, but it cannot prevent every form of social engineering. Attackers may still impersonate executives or vendors without compromising an account, which is why verification procedures and employee training remain important.

What should employees do when a payment request seems unusual?

Do not reply to the message to verify it. Use a known phone number or another established communication method to independently confirm the request.

Who is most likely to be targeted?

Anyone can be targeted, but finance personnel, executives, HR employees, administrative staff, and employees with access to sensitive information are particularly attractive targets.

What should we do if we think an email account has been compromised?

Contact your IT or cybersecurity provider immediately. Credentials and active sessions may need to be reset, suspicious forwarding rules investigated, and recent account activity reviewed.

About Eagle Tech Corp

Eagle Tech Corp provides proactive Managed IT services, cybersecurity solutions, Microsoft 365 management, and strategic technology consulting for nonprofit organizations throughout Northern Virginia, Maryland, and Washington, DC.

We help nonprofit leaders protect their organizations from cyber threats, strengthen their technology environments, and build practical security strategies that support their mission.

Is Your Nonprofit Prepared for a Convincing Email Attack?

Cybersecurity is strongest when technology, employees, and business processes work together.

Eagle Tech Corp can help nonprofit organizations evaluate Microsoft 365 security, identity management, email protection, employee awareness, and incident-response readiness so a convincing email does not become a major business problem.