Skip to main content
Business email compromise scam targeting a new employee with a fake gift card request

Business Email Compromise: Why Your Newest Employee Is the Easiest Target

Updated August 1, 2026

Earlier this year, a new employee at one of our clients posted on LinkedIn that she’d just started her new job. Within her first few days, she got an email that looked like it came from the company’s general manager, asking her to buy several gift cards for a client appreciation gesture and send back the codes. She didn’t know the GM’s actual writing style yet, didn’t know the company’s usual approval process for that kind of request, and didn’t want to seem difficult in her first week. So she did it – before anyone caught it.

Nothing about that attack required hacking anything. The attacker read a public LinkedIn post, picked their moment, and impersonated someone the new hire had no track record with yet to compare against. That’s business email compromise (BEC) in its most common form: not a technical break-in, but a well-timed impersonation aimed at exactly the person least equipped to spot it.

Why This Keeps Working

BEC isn’t a shrinking problem. The FBI’s 2025 Internet Crime Report recorded $3.04 billion in BEC losses for the year – up from $2.77 billion in 2024 – with an average loss of over $122,000 per complaint. Eighty-six percent of that money moved through wire transfer or ACH, which is exactly why gift cards have become such a popular alternative for attackers: most employees associate BEC with wire fraud, not gift cards, so a gift card request raises less suspicion even though it’s the same scam.

New employees are disproportionately vulnerable for reasons that have nothing to do with carelessness: they don’t yet know what a real request from leadership sounds like, they don’t know the normal approval chain for payments or purchases, and they’re motivated to be helpful and responsive in their first week rather than to push back on a request from someone senior. Attackers know this, and public job announcements on LinkedIn make new hires easy to find.

What Is Business Email Compromise?

Business email compromise is a scam where an attacker impersonates someone the target trusts – usually an executive, a vendor, or a business partner – and requests a payment, transfer, or purchase. It doesn’t require compromising an actual email account, though some versions do; often it’s simply a look-alike domain or a spoofed display name convincing enough to pass a quick glance.

The attacker typically researches the target company first, using publicly available information from LinkedIn, company websites, and social media to learn who reports to whom, who’s new, and who handles payments. That research is what makes the resulting email feel plausible enough to act on quickly, especially when it’s phrased as urgent and confidential.

How to Fight Business Email Compromise

Train Employees – Especially New Ones

General phishing awareness training helps, but new hires need something more specific: a heads-up, in their first week, that a request for gift cards, wire transfers, or sensitive information from “leadership” should always be verified through a second channel, no matter how senior the sender appears or how urgent it sounds. We run this training for clients through Huntress Managed SAT, and we specifically flag new-hire onboarding as a window worth extra attention, not less.

Require Out-of-Band Verification for Payment Requests

Any request to send money, buy gift cards, or change payment details should be confirmed through a separate channel – a phone call to a known number, not a reply to the email itself – before anyone acts on it. This isn’t just good practice anymore: cyber insurance carriers increasingly condition crime-coverage claims on having a documented call-back procedure in place, and a challenged claim is very often built around the business’s failure to follow its own verification step. We help clients build this into a written policy, not just an informal habit.

Use Email Authentication

SPF, DKIM, and DMARC make it harder for an attacker to spoof your own domain convincingly, and they reduce the odds of a look-alike domain slipping through unnoticed. This won’t stop every BEC attempt, since many rely on a similar-looking domain rather than your real one, but it closes off one of the easier versions of the attack.

Filter Aggressively at the Inbox

We run Proofpoint for client email security, which blocks roughly 15,000 BEC and impersonation messages per business day across its customer base. Good filtering catches a large share of these attempts before they reach an inbox at all – but it isn’t perfect, which is why the training and verification steps above still matter even with strong filtering in place.

Have a Response Plan Ready

If a payment does go out, speed matters. Know in advance who to call – your bank, and law enforcement via the FBI’s IC3 – and don’t wait to see if it resolves itself. Gift card codes are close to unrecoverable the moment they’re sent, but wire transfers can sometimes be recalled within a narrow window if the bank is notified fast enough.

The Bottom Line

Business email compromise doesn’t need a technical vulnerability to succeed – it needs one employee, on one ordinary day, to trust a request that looks like it came from someone they don’t yet know well enough to question. New hires are the easiest target precisely because they’re doing everything right by being responsive and eager to help. The fix isn’t making them more suspicious of everyone; it’s giving them, from day one, a simple rule: any request for money or gift cards gets verified through a second channel before it gets acted on, no exceptions.

Book a Free Consultation

Not sure whether your team – especially your newest hires – would catch a request like this? Let’s talk. Book a time on my calendar and we’ll look at your onboarding process and payment verification policy, as part of a broader cybersecurity program built for your business.

Frequently Asked Questions

BEC is a scam where an attacker impersonates someone a target trusts – typically an executive, vendor, or business partner – to request a payment, wire transfer, or purchase like gift cards. It relies on social engineering and impersonation rather than a technical break-in.

New hires don’t yet know what a genuine request from leadership sounds like, aren’t familiar with the normal approval process for payments, and are motivated to be responsive in their first days on the job. Public job announcements on sites like LinkedIn make them easy for attackers to identify.

Gift cards are easier to cash out and, since most people associate BEC with wire fraud, a gift card request often raises less suspicion even though it’s the same underlying scam.

The FBI’s 2025 Internet Crime Report recorded $3.04 billion in BEC losses for the year, with an average loss of over $122,000 per complaint.

Often, but coverage is frequently conditioned on having a documented payment-verification (call-back) procedure in place. Claims are commonly challenged specifically because that procedure wasn’t followed, so it’s worth confirming your policy’s exact requirements before you need to file a claim.

Act immediately – contact your bank to attempt a recall if it was a wire transfer, and report the incident to the FBI’s IC3. Gift card codes are very difficult to recover once sent, so speed matters most for wire transfers.