Active Incident? 24/7 Response →
SleuthX

Family Office Notes

Business Email Compromise Against Wealthy Families: How It Works

BEC is not a virus — it is a patient con run through your own inbox. Here is the kill chain, told from the family's side of it.

All articles·8 min read·June 27, 2026

A con run through your own inbox

Business email compromise is not a virus.

It is a patient, human con that travels through legitimate channels — usually your own email — and ends in a wire that cannot be recalled.

For a wealthy family, the appeal to an attacker is simple: large, routine transfers to lawyers, escrow agents, contractors, and advisers, authorized by a small circle that moves on trust.

This piece explains how the attack works from the family's side.

The controls that stop it live in the wire-transfer controls checklist, and if money has already left, the small-business BEC recovery playbookcovers the first moves — this article is about understanding the mechanics, not recovering from them.

It is general information, not legal advice, and not a substitute for retained counsel.

The kill chain, step by step

The family-victim variations

The same machinery is pointed at the situations unique to private wealth: a property purchase where a fake escrow instruction diverts the deposit; a renovation where a contractor's invoice is intercepted and re-banked; a philanthropic grant rushed before a deadline.

The constant is that the request looks ordinary and arrives through a channel the family already trusts.

Why the losses are so large

Business email compromise is among the costliest categories of online crime.

The FBI logged 21,442 complaints in 2024 with adjusted losses of roughly US$2.77 billion, and puts cumulative exposed losses in the tens of billions of dollars over the past decade.

The reason is structural: the payments are big, the instructions look real, and a completed wire is extraordinarily hard to claw back.

What understanding it changes

Seeing the kill chain makes the defense obvious.

If the danger is a believable instruction in a trusted channel, the answer is to verify outside that channel before money moves — an out-of-band callback, a hold on any bank-detail change, and a rule that no wire goes out on email alone.

Most family offices that have looked closely at how a single deception could travel through their process make a handful of quiet adjustments and close the gap.

The fix is not dramatic; it is deliberate.

Sources

  1. Federal Bureau of Investigation, Internet Crime Complaint Center (IC3), 2024 Internet Crime Report. https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
  2. Federal Bureau of Investigation, Internet Crime Complaint Center (IC3), Business Email Compromise: The $55 Billion Scam (Public Service Announcement I-091124-PSA). https://www.ic3.gov/PSA/2024/PSA240911
  3. Deloitte Private, The Family Office Cybersecurity Report 2024. https://www.deloitte.com/global/en/services/deloitte-private/research/family-office-cybersecurity-report.html

Related services

Self-serve forensic tool

Want professional help with defending against business email compromise?

$995 once — lifetime license

Run the AI forensic agent yourself — every tool unlocked, no subscription.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

BEC against families: quick answers

What is business email compromise, in plain terms?
It is a con run through email. An attacker either breaks into a mailbox or imitates one, studies how the family and its advisers communicate, and then sends a believable payment instruction at the right moment. There is usually no malware and no obvious alarm — just a message that looks exactly like the ones that come every week.
Why would a private family be targeted rather than a company?
Because the money is real, the approvals are few, and the communications are informal. A family office routinely moves large sums to lawyers, contractors, escrow agents, and advisers, often on trust and speed. That is precisely the environment business email compromise is designed to exploit.
How would we even know it happened?
Often you don't, until a payment lands in the wrong account or a real vendor asks where their money is. Hidden mailbox forwarding rules and lookalike domains are built to stay quiet. The earliest reliable signal is usually a control catching a mismatch — which is why prevention matters more than detection.

Certified Expertise

GIAC

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management