Skip to content

Knowledge centre

Email security: stopping payment fraud in UAE businesses

Business Email Compromise is one of the most financially damaging cyber threats in the UAE. The attack does not need sophisticated malware — a convincing email and a distracted finance team is enough. Here is how to close the gap.

Why email is still the primary attack vector

Despite two decades of security investment, email remains the entry point for the majority of financial fraud and data breaches. In the UAE context, the risk is amplified by several factors: a high volume of cross-border trade, routine use of wire transfers, a business culture that values fast decision-making, and a supplier landscape that mixes well-governed enterprises with smaller vendors whose own email security is weak.

Business Email Compromise (BEC) is the specific fraud type that exploits this environment. An attacker either compromises a legitimate email account or creates a convincing lookalike domain, then inserts themselves into a payment conversation. The instruction to change a bank account or approve an urgent transfer looks genuine because it arrives from — or appears to arrive from — a trusted address. By the time the fraud is discovered, the funds have moved.

Unlike ransomware, BEC leaves no obvious trace. There is no encrypted file, no ransom note, no system outage. The first visible sign is often a phone call from a supplier asking why their invoice has not been paid.

The three layers attackers exploit

1. Domain impersonation

Attackers register domains that closely resemble yours — swapping a letter, adding a hyphen, or using a different top-level domain (.net instead of .com, for example). Emails sent from these domains pass basic spam filters because the sending domain itself has no prior bad reputation. Without DMARC, DKIM and SPF records correctly configured on your own domain, it is also trivially easy to spoof your address entirely — sending email that appears to come from you@yourcompany.ae without touching your systems at all.

2. Compromised legitimate accounts

If an attacker gains access to a real mailbox — through a phished password, a reused credential from a breached site, or a Microsoft 365 tenant with multi-factor authentication (MFA) not enforced — they can read conversations, wait for the right moment and intervene from a trusted address. There is no lookalike domain to detect. The email genuinely originates from your supplier's or partner's account.

3. Social engineering at the finance layer

Many BEC attacks succeed not because the technical controls failed but because staff were not trained to question urgent financial instructions arriving by email. A message purporting to be from the CEO requesting a same-day transfer, or a supplier update marked as time-sensitive, exploits the same human tendency that makes any request from authority feel difficult to challenge. Technical controls reduce the volume of attacks that reach staff, but they cannot replace process discipline at the point of payment approval.

What a layered email security stack looks like

Effective email security is not a single product — it is a set of controls that work together across the delivery pipeline, the inbox and the human layer.

DNS authentication records (SPF, DKIM, DMARC). These three DNS records tell receiving mail servers whether an email claiming to be from your domain was actually sent by an authorised source. SPF lists the servers permitted to send on your behalf. DKIM adds a cryptographic signature to outgoing mail. DMARC ties both together and specifies what receiving servers should do with mail that fails — quarantine it, reject it, or let it through. A DMARC policy set to p=reject eliminates the most basic form of spoofing. Many UAE organisations have SPF records in place but no DMARC policy, or a DMARC policy set to p=none (monitoring only) that has never been tightened.

Advanced anti-phishing and safe links. Microsoft Defender for Office 365 adds protection that Exchange Online Protection alone does not provide: safe attachments scan files in a detonation environment before delivery, safe links rewrite URLs and check them at click time, and anti-phishing policies apply machine-learning models to detect impersonation of internal users and known external contacts. These features need to be configured with appropriate policies — the default settings are not sufficient for organisations handling significant financial transactions.

Multi-factor authentication on every mailbox. MFA is the single most effective control against account compromise. If an attacker obtains a password through phishing or credential stuffing, MFA prevents them from accessing the mailbox. In a Microsoft 365 environment, MFA should be enforced via Conditional Access policy rather than left as an optional per-user setting. For a full review of your Microsoft 365 security configuration, including MFA enforcement, licence governance and Defender policies, Missan can run a structured tenant assessment.

External sender labelling. A simple but effective control: configure Microsoft 365 to prepend a clear label to emails arriving from outside your organisation. This makes it immediately obvious when a message appearing to come from a colleague or executive is actually external — a common tell in CEO fraud attacks.

Payment process controls. Technology cannot fully substitute for process. High-value payment instructions should require a second verification channel — a phone call to a known number, not a reply to the email. Bank account changes from suppliers should be verified out of band before any transfer is made. Finance teams should be explicitly briefed on what to do when they receive an urgent payment request by email alone.

Assessing your current exposure

The quickest way to assess email security gaps is to ask a few specific questions of your current IT provider or internal team:

  • What is our current DMARC policy, and when was it last reviewed?
  • Is MFA enforced by policy for all users, including shared and administrative accounts?
  • Are Microsoft Defender for Office 365 safe links and safe attachments active and correctly configured?
  • Have any external sender warning banners been configured?
  • When did staff last receive training on BEC and payment fraud?

If the answers are uncertain or incomplete, that is the gap. A free IT health check from Missan will review your email security posture alongside endpoint, identity, backup and broader cybersecurity risk — and give leadership a clear priority view of what needs attention first.

For organisations that want ongoing protection rather than a one-time assessment, managed cybersecurity and MDR from Missan includes continuous monitoring of the Microsoft 365 environment, alert triage and a team that investigates anomalies before they become incidents. Missan has been operating in the UAE since 2004 and holds Microsoft Cloud Solution Provider status — meaning the team configures and manages Microsoft 365 tenants as a core competency, not an occasional add-on.

A note on incident response

If you suspect a BEC incident has already occurred — a payment has gone to an unexpected account, or a mailbox shows signs of unauthorised access — act quickly. Contact your bank immediately to attempt a recall. Preserve mail logs and do not delete anything. Engage your IT provider or a cybersecurity team to determine the entry point and scope. The faster a compromised account is identified and secured, the lower the overall exposure.

Prevention is cheaper than recovery. The controls described above are not expensive to implement relative to the financial exposure they prevent — and for most UAE organisations, a properly configured Microsoft 365 tenant already licences most of them. The gap is almost always configuration and governance, not budget.

Frequently asked questions

What is Business Email Compromise and how common is it in the UAE?

Business Email Compromise (BEC) is a type of fraud where attackers impersonate a trusted party — a supplier, executive or finance contact — to redirect payments or extract sensitive data. The UAE is among the most targeted markets in the Middle East because of the volume of international trade, the prevalence of wire transfers and the speed at which commercial decisions are expected to move. Incidents often go unreported to avoid reputational damage, which means the real scale is higher than published figures suggest.

Does Microsoft 365 include email security out of the box?

Microsoft 365 includes Exchange Online Protection (EOP) in every licence, which handles basic spam and malware filtering. However, EOP alone does not block sophisticated impersonation attacks, zero-day threats or targeted phishing. Microsoft Defender for Office 365 (Plan 1 or Plan 2) adds safe links, safe attachments, anti-phishing policies and attack simulation. These require correct configuration to be effective — a Microsoft 365 tenant left on default settings frequently has significant gaps even if the licence is technically present.

How do I find out whether our email security is adequate?

A good starting point is to ask your provider or internal IT team for a written summary of your anti-phishing configuration, DMARC/DKIM/SPF records, and the last time email security policies were reviewed. If they cannot provide this quickly, there is likely a gap. A structured IT health check from an independent engineer will surface email security weaknesses alongside other risks — without requiring full system access for the initial conversation.

Not sure how your email security stacks up?

A free IT health check from Missan covers email security, Microsoft 365 configuration, endpoint protection, backup and more — a senior engineer, a structured review, a clear report.