Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

    • Environmental Topics
    • Air
    • Bed Bugs
    • Chemicals, Toxics, and Pesticide
    • Emergency Response
    • Environmental Information by Location
    • Health
    • Land, Waste, and Cleanup
    • Lead
    • Mold
    • Radon
    • Research
    • Science Topics
    • Water Topics
    • A-Z Topic Index
    • Laws & Regulations
    • By Business Sector
    • By Topic
    • Compliance
    • Enforcement
    • Guidance
    • Laws and Executive Orders
    • Regulations
    • Report a Violation
    • Environmental Violations
    • Fraud, Waste or Abuse
    • About EPA
    • Our Mission and What We Do
    • Headquarters Offices
    • Regional Offices
    • Labs and Research Centers
    • Planning, Budget, and Results
    • Organization Chart
    • EPA History

Breadcrumb

  1. Home
  2. Office of Inspector General

FRAUD ALERT: Business Email Compromise

FRAUD ALERT: Business Email Compromise

Download Audio

Transcript fraudcast_business_email_compromise.txt
Running Time 14:56:00

Fraud Alert

The U.S. Environmental Protection Agency Office of Inspector General is issuing a fraud alert to highlight an increasingly common and costly form of cybercrime known as business email compromise, or BEC. In this sophisticated scam, criminals are using fraudulent emails that appear to come from known and trusted sources to access to company email accounts and target organizations that make or receive financial transactions. These emails may originate from lookalike, or spoofed, email accounts or legitimate email accounts compromised through phishing campaigns. Using information obtained from successful phishing campaigns to impersonate a representative of the trusted entity, the criminals deceive personnel into transferring funds or sensitive information under the guise of a legitimate business request.

Using an email address that looks nearly identical to one that their victims are familiar with, scammers request changes to bank account information for invoices or other financial transactions. Scammers may take time to groom their victim, building trust and rapport, or they may try to pressure their victims into providing information quickly by claiming that the transaction is critical and time sensitive. In some cases, they may send a message with links or attachments containing malware that, when opened, give criminals access to sensitive information.

How can you protect your organization from BEC?

  • Create organizational policies for receiving new payment instructions, including a multistep process to verify new payment instructions. 
  • Employ email security systems that can detect phishing attempts, domain spoofing, and other cyber threats, and use two-factor authentication to combat account compromise.
  • Train staff regularly on cybersecurity best practices and how to recognize phishing emails and require them to report phishing attempts—even seemingly minor ones.

If you suspect that your organization has fallen victim to a BEC scheme, you should immediately notify your IT department and financial institution. 

If the BEC relates to a program or operation of the EPA or U.S. Chemical Safety and Hazard Investigation Board, report the incident to the EPA Office of Inspector General Hotline at OIG.Hotline@epa.gov.  

FRAUD ALERT: Business Email Compromise (pdf) (308.19 KB)

Office of Inspector General

  • EPA OIG Hotline
Contact the Office of Inspector General
Contact the Office of Inspector General to ask a question, provide feedback, or report a problem.
Last updated on December 3, 2025
  • Assistance
  • Spanish
  • Arabic
  • Chinese (simplified)
  • Chinese (traditional)
  • French
  • Haitian Creole
  • Korean
  • Portuguese
  • Russian
  • Tagalog
  • Vietnamese
United States Environmental Protection Agency

Discover.

  • Accessibility Statement
  • Budget & Performance
  • Contracting
  • EPA www Web Snapshot
  • Grants
  • No FEAR Act Data
  • Plain Writing
  • Privacy and Security Notice

Connect.

  • Data
  • Inspector General
  • Jobs
  • Newsroom
  • Regulations.gov
  • Subscribe
  • USA.gov
  • White House

Ask.

  • Contact EPA
  • EPA Disclaimers
  • Hotlines
  • FOIA Requests
  • Frequent Questions
  • Site Feedback

Follow.