Business email compromise (BEC) is a type of fraud in which an attacker impersonates, or actually takes over, a trusted email account, such as an executive, an employee, a supplier or a lawyer, to persuade someone to send money or sensitive information. Typical examples are a fake request from the CEO to wire funds urgently, or a supplier email announcing new bank details just before a large invoice is due. It is one of the most financially damaging forms of cybercrime for businesses of all sizes.
At a glance
- BEC targets business processes, especially payments, rather than computers.
- Attackers either spoof or imitate a trusted address, or log in to a real account they have compromised.
- Many BEC emails carry no link or attachment, which makes them harder for filters to catch.
- Verification procedures for payment changes are the most important control, backed by email security and training.
What problem it solves
BEC is a threat, so for buyers it describes a set of risks to manage. The biggest is direct financial loss: once a wire transfer reaches an account controlled by criminals, the money is often moved quickly and may not be recoverable. Other forms aim at payroll (redirecting an employee’s direct deposit), gift card purchases, or sensitive data such as employee tax records.
What makes BEC hard is that it exploits normal business behavior. Finance teams are used to paying invoices by email, executives do send urgent requests, and suppliers do change banks. An attacker who has read a real mailbox for a few weeks can time a request perfectly and copy the tone of the real sender. Technical controls reduce the odds, but the decisive step is usually a person deciding whether to act.
How it works
Getting in or getting close. The attacker either compromises a real mailbox, often through phishing for the password, or sets up a lookalike domain or display name that resembles a trusted sender.
Watching. With access to a real mailbox, attackers often read email quietly, learn who approves payments, track open invoices and set up mailbox rules that hide replies from the real owner.
The request. At the right moment the attacker sends a request: change the bank details for this supplier, pay this invoice today, send the W-2 forms, buy gift cards for a client event. The message often stresses urgency and confidentiality.
The payout. Funds go to an account the attacker controls and are moved on quickly.
Defenses. Email authentication with DMARC makes it harder to spoof your own domain exactly. A secure email gateway (SEG) or advanced filtering can flag lookalike domains, first-time senders and unusual requests. Multi-factor authentication (MFA) makes mailbox takeover harder. Security awareness training (SAT) teaches finance and executive staff the warning signs. The control that matters most is procedural: verify any new or changed payment instructions through a separate channel, such as a phone call to a number already on file.
When it matters for buyers
- When finance pays suppliers by wire or ACH. Any process where email can change where money goes is exposed.
- When cyber insurance renews. Insurers often ask about payment verification and MFA, and BEC coverage terms vary.
- When a supplier or customer is compromised. Fraudulent emails may come from their real accounts.
- When executives are publicly visible. Names and titles on websites and social media make impersonation easier.
See our secure email gateway overview for the technical layer of protection.
Questions to ask vendors
- How do you detect BEC messages that contain no links or attachments?
- Do you flag lookalike domains and display-name impersonation of our executives and suppliers?
- Can you detect a compromised internal mailbox, such as unusual logins or new forwarding rules?
- How do you handle email from a real supplier account that has been taken over?
- Does your training include finance-specific scenarios and payment verification practice?
- What do you report to us when a BEC attempt is blocked or reported?
How it differs from phishing
Phishing is the broader technique of impersonating a trusted sender to trick someone into acting, usually by clicking a link, entering a password or opening a file. BEC is a specific fraud aimed at money or data, which may begin with phishing (to steal a mailbox password) but whose decisive message is usually a plain request with nothing malicious to scan. Controls built for phishing, such as link and attachment filtering, reduce BEC risk, but payment verification procedures and monitoring of mailbox behavior do more of the work.
