According to the FBI’s Internet Crime Complaint Center’s latest report, in 2025 there were 24,768 BEC complaints, which led to $3.04 billion in losses.
Table of Contents
While Microsoft 365 and Google Workspace come with robust security controls, the reality is that BEC attacks can happen through many different pathways and no single setting will protect against them all.
Moreover, email in both platforms is just one aspect of a larger cloud identity. As Microsoft points out, if Entra ID credentials are compromised, it can lead to the associated mailbox, calendars, contacts, documents, shared files, third-party apps, SharePoint folders, and OneDrive files being exposed as well. Google Workspace administrators can investigate activity across Gmail and Drive in supported editions.
Note: A compromised mailbox is therefore rarely just an email problem.
Finally, we should understand what Business Email Compromise doesn’t look like: a traditional cyber attack. Many users mistakenly believe that the typical way for BEC is a malicious attachment, suspicious link, or request for a password. The attacker may write a two-line message in a familiar tone and insert it into a genuine supplier conversation. Sometimes it even comes from a real account. That makes BEC particularly dangerous in Microsoft 365 and Google Workspace environments.
Further reading What is Business Email Compromise (BEC)?
Not All BEC Attacks Begin Alike
To the email recipient, most BEC messages may appear nearly identical. For example: the company CEO asks to wire money urgently, a vendor requests updated bank account information, or HR wants personal data about an employee.
But what happened behind the scenes to make these emails possible could be vastly different.
Attackers may have spoofed your domain, sent an email from a lookalike domain, compromised a trusted supplier’s email account, or simply logged into a legitimate Microsoft 365 or Google Workspace account. Each approach circumvents trust differently, and each can be stopped in its tracks with different security measures in place. This is why there’s no silver bullet technology to prevent all forms of BEC.
Let’s break down the following methods: setting DMARC can prevent domain spoofing, identity verification prevents account compromise, and independent verification is critical for high-value business transactions.
Close the Direct-Spoofing Route With DMARC Enforcement
The first line of defense against someone spoofing your organization's domain is email authentication.
SPF, DKIM and DMARC protect your domain by helping receiving mail servers identify legitimate emails from ones that simply look like they come from your domain.
Enabling DMARC isn’t the hard part. The real challenge is that most organizations using Microsoft 365 or Google Workspace also send email through multiple third-party services. Marketing automation platforms, CRM systems, customer support tools, billing platforms, and dozens of other business applications can relay mail from your domain. Until these services are identified and configured, jumping to a DMARC policy that enforces quarantine or rejection will cause any messages they send to fail authentication.
Monitoring lets most organizations safely learn which messages are legitimate before enforcing a DMARC policy. This is where a DMARC management platform such as EasyDMARC becomes useful. It turns aggregate reporting into a clearer view of sending sources, authentication failures, and the changes needed to progress safely toward enforcement.
DMARC is a great first layer of defense because it will stop attackers from sending email impersonating your domain straight to your customers. But it won’t protect you against all other approaches of BEC.
Prevent Account Takeover
Inside an authenticated user’s account, an attacker can search through existing email threads to learn how and who approves invoices. Then, they can forward payment emails to themselves, move replies to a hidden folder, share OAuth app access with a partner, or delete any incriminating email. Now we focus on different methods to prevent it.
Use Phishing-Resistant Authentication
Requiring MFA is a great baseline, but think about requiring stronger levels of authentication for higher-risk accounts. Administrator, finance, and HR accounts are good examples.
Passkeys and hardware-backed security keys help prevent credential phishing better than passwords and OTPs. Microsoft Entra ID allows you to enroll phishing-resistant authentication methods like passkeys, Windows Hello for Business, FIDO2 security keys, and certificate-based authentication. Google refers to security keys as the “strongest” 2-Step Verification option and also allows passkey-based login.
Additionally, if licensing allows, context-aware access policies can inform the decision. Microsoft Entra ID Conditional Access can enforce specific authentication strengths and assess access conditions. Google Workspace Context-Aware Access can limit app usage based on the user, location, IP address, and device security state.
Manage Third-Party Application Access
Just because a password hasn’t been cracked doesn’t mean your Microsoft 365 or Google Workspace accounts are safe from intrusion. By approving a malicious OAuth application or one with overly broad permissions, a user can grant it access to their email, files, and other data stored in the cloud without the need for a password.
Microsoft and Google both advise restricting users’ ability to approve applications and limiting OAuth access wherever possible. Include which users can approve application access in your internal security policy, keep an inventory of approved applications, require admin approval of apps with sensitive access requests, and conduct regular reviews to clean up orphaned apps. If there is no obvious business need, treat all unexpected requests for email or cloud storage access as suspicious.
Watch for Signs of Account Compromise
One goal of BEC attackers can be to stay stealthy long enough to learn who is talking to whom and where money is being sent.
Microsoft urges you to look for typical mailbox anomalies such as email suddenly going missing or deleted email not existing, suspicious emails appearing in Sent Items or Deleted Items folders, unexpected external forwarding addresses, and inbox rules that automatically move messages to RSS Subscriptions, Notes or Junk Email folders.
Google also advises you to look at any Gmail filters you have set up, as well as forwarding settings, account recovery options, missing messages, contacts, and other Gmail-related settings if you suspect an account was compromised.
Wait for someone to tell you that an email was there and now it's gone. Unexpected mailbox forwarding rules, filters, and other settings should be considered suspicious, the victims' security events, especially in the case of financial, executive, and administrative accounts.
Take High-Risk Decisions Outside the Email Trust Chain
Organizations need technical controls, but they also need additional layers of defense. While a message can initiate a business process, it shouldn’t be sufficient to execute a risky transaction.
Requests to change supplier bank accounts, payment instructions, payroll details, or other sensitive operations should be confirmed by another channel your company trusts. The FBI recommends calling the person or company to confirm payment changes and using a phone number you already have on file, not one included in the email. Additional approval steps can also make sense for larger or unusual payments, based on the organization’s volume and workflows.
The guiding principle here is simple:
Note: Email can initiate the request. It shouldn’t serve as the only evidence that the request is legitimate.
Trainings and Internal Company Policy Regulations
Employee awareness is still a vital safety net. But your people are only as prepared as your processes. Organizations should practice responding to realistic BEC attacks so teams can spot fraud and handle suspicious requests properly. Organizations should document and consistently enforce those plans.
There are also several Microsoft 365 and Google Workspace features you can use to spot BEC. Both platforms display external sender warnings, first contact alerts, spoofing notifications, and more. These warnings can be helpful cues to pause. But employees should never assume an email request is safe because those warnings are absent.
What to do after BEC
Once BEC is verified, the initial response is to take action to remove the attacker’s access.
Microsoft recommends disabling compromised accounts during investigations and checking for ways attackers could maintain access. Entra ID also provides a process for revoking user access and refresh tokens.
Microsoft 365 provides its own investigation and remediation capabilities, with the available depth depending on the organization’s licenses.
In Google Workspace, suspending a suspected compromised user resets the user’s sign-in cookies and OAuth tokens. Administrators should then investigate the account, review forwarding and filters, and restore access only after the account has been secured.
Organizations with supported Google Workspace editions can use the Security Investigation Tool to find and remove malicious messages from inboxes.
Note: For incidents involving transferred funds, time matters.
The FBI recommends contacting the originating financial institution as soon as the fraud is discovered and filing a detailed IC3 complaint. Businesses outside the United States should follow the equivalent process with their bank and relevant local authorities.
A focused response should follow this order:
- Suspend or disable the affected account.
- Revoke active sessions and tokens.
- Reset credentials and review registered authentication methods.
- Remove unauthorized inbox rules, forwarding, delegates, and application grants.
- Find messages sent by the attacker and identify internal and external recipients.
- Check whether attackers viewed, changed, or deleted email, files, contacts, or other cloud data.
- Preserve audit data and other evidence.
- Contact the financial institution immediately
Recover What the Attacker Changed or Deleted
An attacker may delete messages to hide evidence, remove files, alter cloud data, or interfere with normal business operations. Native recovery may help, but an independent backup provides a separate recovery path outside the affected environment.
Here you can look at MSP360 Backup for Microsoft 365 and Google Workspace, which offers automated Outlook backup and Gmail backup for data protection. It is a dedicated SaaS backup solution with quick and simple recovery options for data alongside other workloads of both platforms. It supports immutable backup (locked copy of your data), item-level restore, which lets administrators select the users and components that need protection, supports the BYOC (Bring Your Own Cloud) option, and offers centralized multi-tenant management for MSPs.
Further reading 13 Best Outlook Backup Solutions
Conclusion
Business Email Compromise attacks don’t target one vulnerability. They target your users’ trust. That trust can be placed in your domain, a legitimate M365 or GW account, or a normal business workflow. The best defense is to secure each individually instead of putting all of your trust in one technology or policy. Companies that implement email authentication, robust identity security, clear operating procedures, and a proven recovery plan are much better equipped to prevent BEC attacks and limit damage if an attack does happen.
Here’s the recap for your convenience:
- Email authentication prevents domain spoofing
- Identity security prevents account takeover
- Operating procedures prevent fraudulent approval
- Backup reduces business impact when attackers compromise cloud data


