Four scenarios we see in real businesses
Phishing was involved in 85% of the breaches UK businesses identified last year (Cyber Security Breaches Survey 2025/26), and business email compromise cost victims .77 billion in 2024 according to the FBI. The mechanics are less dramatic than the numbers.
1. The supplier bank-detail change. An email arrives from a supplier you really use, on their real thread, saying they have changed banks. Either the supplier's mailbox has been compromised, or the domain is a lookalike. Finance updates the details. The next payment goes to the criminal.
2. The urgent request from the boss. "I am in a meeting, can you pay this invoice today, I will explain later." From a lookalike address, or from the director's real mailbox after a password was phished.
3. The credential harvest. A message "from Microsoft" or "from IT" with a link to a login page that looks right. The password goes to the attacker, who logs in, sets up a forwarding rule, and waits for an invoice to intercept.
4. The compromised customer. A customer's mailbox is taken over and used to send you a malicious attachment, from a real address you trust, on a real thread.
Scenarios 1 and 4 are why "we know our suppliers" is not a defence, and scenario 3 is why the fraud often starts weeks before anyone notices.
The controls that stop most of it
| Control | What it stops | Where it comes from |
|---|---|---|
| MFA enforced for everyone, legacy authentication blocked | Scenario 3: a stolen password is useless on its own. | Every Microsoft 365 plan (security defaults); Conditional Access on Business Premium. |
| SPF, DKIM and DMARC at reject on your domains | Criminals sending as you to your customers and staff. | DNS records; see the email security guide. |
| Impersonation protection listing your directors and key suppliers | Scenarios 1 and 2 from lookalike addresses and display names. | Defender for Office 365 Plan 1, in Business Premium. |
| Safe Links and Safe Attachments | Malicious links checked at click time; attachments detonated before delivery (scenario 4). | Defender for Office 365 Plan 1. |
| Preset security policies (Standard or Strict) | Microsoft's recommended anti-phishing, spam and malware thresholds instead of the defaults. | Every plan for the basics; Defender for the advanced settings. |
| External email tagging | A visible banner on mail from outside the business, so "from the MD" from outside stands out. | Exchange Online setting. |
| Auto-forwarding blocked and inbox rules alerted | The attacker's first move after a compromise. | Exchange Online and Defender alerts. |
| One-click reporting and someone who reviews the reports | Finds the campaign that got through, and removes it from everyone else's inbox. | Report Message add-in; Defender for Office 365 for the clean-up. |
| Monitoring | Risky sign-ins and new forwarding rules seen when they happen. | Entra ID alerts, and a SOC if you want them read at night. |
Not sure which of these applies to your business? Ask an engineer.
Book a Discovery CallThe checks for staff, especially finance
Technology stops most attempts. People stop the rest, and the rule set has to be short enough to survive a busy Friday.
- Bank-detail changes are verified by phone, on a number you already hold, not one in the email. No exceptions, including for the MD.
- Urgency is a signal, not a reason. Any payment request that says "today" or "do not tell anyone" is checked by a second person.
- Look at the address, not the name. Display names are free; the address behind them is what matters. Hover before you click; on a phone, press and hold.
- Never log in from a link in an email. Go to the app or type the address.
- Report, do not delete. The report button tells IT and protects colleagues who got the same message.
- If you did click, say so immediately. The cost of a compromise is set by how fast it is found, not by whether it happened.
Put these on one page, get the directors to sign it, and rehearse it once a year. Phishing simulations (included with Defender for Office 365 Plan 2 in the Defender Suite) make the rehearsal realistic.
If money has gone
Speed matters more than anything. Contact your bank immediately and ask them to recall the payment; banks can sometimes freeze funds if told within hours. Report to Action Fraud (England, Wales and Northern Ireland) or Police Scotland. Preserve the emails and headers. Then find out how it happened, because if a mailbox was compromised the attacker may still be in it; our compromised account guide covers that sequence.
How Black Sheep Support manages email protection
Email protection is part of our security baseline: the domain records at reject and monitored, Defender for Office 365 presets applied and tuned, impersonation lists maintained as your suppliers change, external tagging, forwarding blocked, reporting in place and reviewed, and alerts routed to monitoring. We also run the finance-team briefing and, for clients on the Defender Suite, phishing simulations. [TO CONFIRM: whether awareness training and simulations are a standard inclusion or an add-on.]
Start with the free domain security audit to see whether your own domain can be spoofed, then book a review of the inbound side.
Want a second opinion before you buy licences?
We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.
Frequently asked questions
Does Microsoft 365 protect against phishing?
Every plan includes basic anti-spam, anti-malware and spoof protection. The controls that stop targeted phishing and invoice fraud (impersonation protection, Safe Links, Safe Attachments) come with Defender for Office 365, included in Business Premium, and all of it needs configuring.
What is business email compromise?
Fraud carried out through email that appears to come from a trusted person or company: a supplier changing bank details, a director requesting a payment, or a compromised real mailbox used to redirect money. The FBI recorded .77 billion in losses from it in 2024.
How do we stop invoice fraud?
Verify every bank-detail change by phone on a known number; protect your own domain with DMARC; use impersonation protection for suppliers and directors; enforce MFA so a phished password cannot be used; and monitor for forwarding rules. All five together.
Should we train staff or rely on technology?
Both. Technology stops the volume; a short, rehearsed set of rules for finance stops the targeted attempt that gets through. Neither works alone.
What should we do if we paid a fraudulent invoice?
Call your bank immediately to attempt a recall, report to Action Fraud or Police Scotland, keep the emails, and check whether a mailbox was compromised. The faster the bank is told, the better the chance of recovery.
Are phishing simulations worth it?
For most businesses, yes, once the basics are in place. They make the rules real and show who needs a quiet word. They are included with Defender for Office 365 Plan 2 in the Defender Suite for Business Premium.
Book an email security review
We will check whether your domain can be spoofed, what your inbound protection is actually configured to do, and what your finance team's process would stop, and give you the fixes in order.
- Your domain's SPF, DKIM and DMARC state.
- What Defender and Exchange are and are not doing for you today.
- The finance-team rules on one page.
- What monitoring would add.
Sources
Prices and product facts on this page were checked against the following Microsoft pages on the dates shown.
- 1.FBI Internet Crime Complaint Center: 2024 Internet Crime Report · accessed 10 September 2026
- 2.GOV.UK: Cyber Security Breaches Survey 2025/2026 · accessed 10 September 2026
- 3.Microsoft Learn: Why do I need Microsoft Defender for Office 365? (Plan 1 vs Plan 2) · accessed 10 September 2026
What has changed on this page
- 10 September 2026Page published. Statistics from FBI IC3 2024 and the UK Cyber Security Breaches Survey 2025/26.

