Direct Answer
Business email compromise, or BEC, caused S$57.3 million in reported losses across 262 Singapore cases in the first half of 2026, according to the Singapore Police Force. The safest response is to verify every new or changed payment instruction through a trusted contact method, require a second approver for material transfers, and stop payment immediately if an email account or invoice may have been compromised.
Introduction
The latest Singapore scam figures contain a warning for every accounts team. Overall scam cases and losses fell in the first half of 2026, yet business email compromise moved sharply in the opposite direction. Reported BEC cases rose 67.9 per cent from the same period in 2025, while losses jumped 193.1 per cent to S$57.3 million. That is more than S$218,000 per reported case on a simple average, although losses vary widely.
BEC is not merely a suspicious email with poor spelling. It is payment diversion built around real business processes. A criminal may take over a supplier's mailbox, imitate a director, alter a genuine invoice or insert a fraudulent bank account into an existing email thread. The request arrives where staff expect to see it, often at month-end, before a public holiday or while a senior employee is travelling.
Singapore SMEs are exposed because many rely on email for quotations, invoices and bank-detail changes, but keep payment approval informal. One employee may receive the invoice, confirm it and prepare the transfer. A familiar name or a reply inside a genuine thread can then replace independent verification. The practical defence is procedural: no bank-detail change should be approved on email alone.
How This Scam Works in Singapore
A BEC attack usually starts before the payment request. The scammer studies the business, its staff and its suppliers through company websites, LinkedIn profiles, social media, leaked credentials or previous phishing. Public information can reveal the finance manager, managing director, regular vendors and even when an executive is overseas.
In an account-takeover case, the criminal steals an email password through phishing, password reuse or malware. Access to a live mailbox provides more than a sender address. It reveals invoice formats, writing style, payment cycles, customer names and ongoing negotiations. The intruder may create forwarding rules, hide security alerts or monitor a thread until a large payment is due.
The attacker then changes one detail that matters: the destination account. A supplier appears to say that its bank has changed. A client receives a replacement invoice. A chief executive asks finance to make a confidential acquisition payment. The message may use the real display name and signature, or come from a lookalike domain containing one altered character.
Thread hijacking is especially dangerous. A criminal who controls one party's mailbox can reply within a legitimate conversation, quote earlier messages and attach a modified copy of a genuine invoice. Routine checks such as recognising the sender's tone or comparing the company logo are weak in this setting because much of the message is authentic.
Some attacks do not require a hacked mailbox. Scammers register a near-identical domain, copy the sender's signature and time the request using information gathered online. Caller ID and messaging accounts can also be spoofed or impersonated to support the story. A follow-up WhatsApp message saying “I have sent the revised invoice” is not independent confirmation if the WhatsApp account is also controlled by the criminal.
The final stage is urgency. Staff may be told that a shipment will be held, a discount will expire, a deal is confidential or the director cannot take a call. The goal is to make the employee treat the usual control as an obstacle. Once the payment reaches a mule account, funds can be split among other accounts, withdrawn, remitted overseas or converted into cryptocurrency.
Unauthorised mailbox access and the use of stolen credentials may constitute offences under Singapore's Computer Misuse Act. Fraud, money-mule activity and laundering can attract separate criminal liability. For the business, legal classification comes after the immediate task: halt the transfer and preserve the evidence.
Real-World Impact and Statistics
SPF's mid-year scam and cybercrime figures, released on 26 August 2026, recorded 262 BEC cases in the first six months of the year. Cases increased by 67.9 per cent, while losses climbed from S$19.5 million in the first half of 2025 to S$57.3 million in the same period of 2026. SPF described criminals impersonating suppliers, vendors, clients and senior executives to divert payments into fraudulent accounts.
The rise stands out against the national picture. Singapore recorded 16,821 scam cases between January and June 2026, down 14.4 per cent year on year. Total scam losses fell 17.9 per cent to about S$410.6 million. BEC therefore accounted for roughly 14 per cent of all reported scam losses despite representing fewer than two per cent of scam cases.
The broader data explains why prevention cannot depend on banks spotting an account takeover. SPF said 80.8 per cent of reported scams involved victims making the transfer themselves. In BEC, a staff member may use the company's genuine banking portal and valid authorisation token. The transaction looks authorised even though the instruction was fraudulent.
SPF also reported that the Anti-Scam Centre recovered more than S$97.7 million in scam losses during H1 2026 and helped avert at least S$127.1 million through proactive interventions. Recovery figures refer to money frozen in accounts or cryptocurrency wallets, not necessarily funds already returned to victims. Speed remains critical because each onward transfer makes tracing and recovery harder.
The harm is wider than the immediate loss. A supplier may still be owed for goods already delivered. Insurance coverage may depend on policy wording and compliance with internal controls. A compromised mailbox can contain employees' or customers' personal data, creating a separate incident-management question under the Personal Data Protection Act (PDPA). Organisations must assess what data was exposed, contain the access and consider whether notification duties are triggered.
How to Protect Yourself
Verify payment changes out of band. If an invoice contains a new bank account, call a known contact using a number already held in your records. Do not use a number supplied in the change request. Read the account name and number back to the supplier and record who confirmed them.
Use two-person approval. Separate invoice receipt, vendor-master changes and payment release. For larger or unusual transfers, require a second approver who checks the commercial purpose and the independently verified bank details. A director's urgent email should not override this rule.
Lock down vendor records. Restrict who can edit supplier bank details in the accounting system. Send an automatic notification to the supplier's established contact when a change is made, then impose a short cooling-off period before the first payment where operations allow.
Protect email accounts. Require multi-factor authentication, block legacy authentication, use unique passwords and review mailbox forwarding rules. Configure SPF, DKIM and DMARC for company domains to reduce straightforward spoofing. These controls do not prevent every attack, but they remove common entry points and make impersonation easier to detect.
Train for the exact scenario. Staff need practice with realistic warning signs: a changed beneficiary, a lookalike domain, an unexpected confidential request, a payment split across accounts or pressure to skip a call-back. Generic reminders to “be vigilant” are less useful than a one-page payment-change procedure beside the approval screen.
Set bank controls before an incident. Use transaction limits, maker-checker workflows, beneficiary controls and alerts for large or first-time payments. Ask the bank what emergency suspension or kill-switch options apply to the company's accounts. MAS supervises financial institutions, but no regulatory framework turns a fraudulent authorised transfer into a guaranteed refund.
Verify financial counterparties. For businesses claiming to provide investments or regulated financial services, check the MAS Financial Institutions Directory and Investor Alert List. A professional website, ACRA registration or familiar brand name does not prove that the person sending the instructions is authorised by that entity.
Minimise public operational detail. Do not publish direct finance-team addresses, approval hierarchies or executive travel plans unless necessary. Review what staff reveal on social media. Criminals use small pieces of accurate information to make a false request believable.
What to Do If You Are Targeted
If a suspicious request has not been paid, stop the process and contact the supposed sender through a trusted channel. Preserve the message, attachment and full email headers. Do not forward it casually, as forwarding can remove technical details that investigators or security staff need.
If money has been transferred, call the bank immediately through its official fraud channel. Ask for the transfer to be stopped or recalled and for the receiving account to be flagged. Do not wait for the supplier to finish its own investigation. Then call the 24/7 ScamShield Helpline at 1799 for guidance and make a police report.
Give the bank and SPF exact information: payment time, amount, beneficiary account, transaction reference, invoice, email thread, sender address, domain and the moment the fraud was discovered. Preserve system and mailbox logs. If cryptocurrency was involved, record wallet addresses and transaction hashes.
Secure the email environment. Reset the affected account's password, revoke active sessions, remove unknown forwarding rules and check whether recovery details or MFA methods were changed. Review other mailboxes and audit recent vendor-detail amendments. A criminal may have prepared more than one fraudulent payment.
Notify relevant business leaders, finance, IT, legal counsel, the data protection officer and the insurer without unnecessary delay. If personal data may have been accessed, assess the incident under the PDPA and consult the Personal Data Protection Commission's breach-management guidance. CSA Singapore's SingCERT can assist organisations with cybersecurity incident reporting and technical guidance.
Tell affected suppliers or customers through verified contacts. A clear notice can stop a second payment and prevents the criminal from using the compromised thread against another party. Avoid blaming the employee who acted on the message; a fact-focused review produces better reporting and stronger controls.
Common Mistakes to Avoid
Trusting a familiar display name. Email applications often show a person's name more prominently than the real address. Expand the sender details and check the full domain, but remember that a genuinely compromised account will pass this test.
Calling the number in the suspicious email. The scammer controls that number. Use the supplier master record, signed contract or a contact number independently obtained before the request arrived.
Treating a reply in an old thread as proof. Thread history can be stolen from a mailbox. The payment change itself still requires a separate call-back.
Allowing urgency or seniority to bypass controls. A genuine chief executive can tolerate a five-minute verification that protects six figures. Confidentiality is not a reason to remove dual authorisation.
Assuming MFA makes BEC impossible. MFA reduces risk, but attackers can steal active sessions, trick users into approving prompts or rely on lookalike domains. Payment verification remains necessary.
Deleting the email after spotting the fraud. Preserve it with headers and attachments. Evidence helps identify the route of compromise and supports bank, police and insurer reviews.
Paying a second “recovery fee”. Scammers may pose as investigators, lawyers or asset-recovery firms after the first loss. Neither SPF nor a legitimate bank will ask you to transfer money to a “safe account” to recover funds.
FAQ
What is business email compromise?
Business email compromise is a scam in which criminals impersonate or take over a business email account to redirect a payment, obtain sensitive information or induce another fraudulent action. Common variants include fake supplier bank changes, altered invoices and executive impersonation.
How much did Singapore businesses lose to BEC in the first half of 2026?
SPF recorded S$57.3 million in losses across 262 BEC cases in H1 2026. Losses were 193.1 per cent higher than in H1 2025, while reported cases rose 67.9 per cent.
How can an SME verify a supplier's new bank account?
Call an established supplier contact using a number already held in company records. Confirm the account name and number verbally, document the check, and require a second employee to approve the vendor-master change and first payment.
Can a bank reverse a BEC transfer?
A bank may be able to stop, recall or freeze funds if notified quickly and if the money remains within reach, but recovery is not guaranteed. Contact the bank immediately, then report the incident to SPF and provide complete transaction evidence.
Does cyber insurance cover business email compromise?
Coverage depends on the policy. Some policies distinguish social-engineering fraud, computer fraud and funds-transfer fraud, and may require call-back controls or timely notification. Review the wording with the insurer or broker before an incident and notify the insurer promptly after one.
Is BEC a PDPA data breach?
It can be. If a compromised mailbox exposed personal data, the organisation should assess the scale and likely harm under the PDPA, contain the breach and determine whether notification to the PDPC and affected people is required. A fraudulent payment alone does not automatically establish a notifiable data breach.
Where should a Singapore SME report a suspected BEC scam?
Contact the bank first if a payment was made. Call ScamShield at 1799 for 24/7 scam guidance, file a police report with SPF, and report cybersecurity aspects to CSA Singapore's SingCERT where appropriate.
Conclusion
The H1 2026 figures show why BEC deserves board-level attention in Singapore SMEs. A relatively small number of cases caused S$57.3 million in losses, and the sharp increase occurred while the overall scam situation improved. Email security matters, but the decisive control sits in the payment process.
Make one rule non-negotiable: a changed beneficiary or unusual payment instruction is never approved from email alone. Verify through a trusted channel, use dual authorisation and document the check. If a transfer has already gone out, call the bank immediately, preserve the evidence, contact ScamShield at 1799 and report the case to SPF. Minutes can decide whether funds are frozen or moved beyond reach.