What Is BEC (Business Email Compromise)?

Related problems: A vendor's bank details changed by email and we paid the wrong account; Fake emails from the CEO asking finance to send money urgently; Someone logged into an employee's mailbox and sent emails as them; Cyber insurer asking about payment verification controls

Business email compromise (BEC) is a type of fraud in which an attacker impersonates, or actually takes over, a trusted email account, such as an executive, an employee, a supplier or a lawyer, to persuade someone to send money or sensitive information. Typical examples are a fake request from the CEO to wire funds urgently, or a supplier email announcing new bank details just before a large invoice is due. It is one of the most financially damaging forms of cybercrime for businesses of all sizes.

At a glance

  • BEC targets business processes, especially payments, rather than computers.
  • Attackers either spoof or imitate a trusted address, or log in to a real account they have compromised.
  • Many BEC emails carry no link or attachment, which makes them harder for filters to catch.
  • Verification procedures for payment changes are the most important control, backed by email security and training.

What problem it solves

BEC is a threat, so for buyers it describes a set of risks to manage. The biggest is direct financial loss: once a wire transfer reaches an account controlled by criminals, the money is often moved quickly and may not be recoverable. Other forms aim at payroll (redirecting an employee’s direct deposit), gift card purchases, or sensitive data such as employee tax records.

What makes BEC hard is that it exploits normal business behavior. Finance teams are used to paying invoices by email, executives do send urgent requests, and suppliers do change banks. An attacker who has read a real mailbox for a few weeks can time a request perfectly and copy the tone of the real sender. Technical controls reduce the odds, but the decisive step is usually a person deciding whether to act.

How it works

Getting in or getting close. The attacker either compromises a real mailbox, often through phishing for the password, or sets up a lookalike domain or display name that resembles a trusted sender.

Watching. With access to a real mailbox, attackers often read email quietly, learn who approves payments, track open invoices and set up mailbox rules that hide replies from the real owner.

The request. At the right moment the attacker sends a request: change the bank details for this supplier, pay this invoice today, send the W-2 forms, buy gift cards for a client event. The message often stresses urgency and confidentiality.

The payout. Funds go to an account the attacker controls and are moved on quickly.

Defenses. Email authentication with DMARC makes it harder to spoof your own domain exactly. A secure email gateway (SEG) or advanced filtering can flag lookalike domains, first-time senders and unusual requests. Multi-factor authentication (MFA) makes mailbox takeover harder. Security awareness training (SAT) teaches finance and executive staff the warning signs. The control that matters most is procedural: verify any new or changed payment instructions through a separate channel, such as a phone call to a number already on file.

When it matters for buyers

  • When finance pays suppliers by wire or ACH. Any process where email can change where money goes is exposed.
  • When cyber insurance renews. Insurers often ask about payment verification and MFA, and BEC coverage terms vary.
  • When a supplier or customer is compromised. Fraudulent emails may come from their real accounts.
  • When executives are publicly visible. Names and titles on websites and social media make impersonation easier.

See our secure email gateway overview for the technical layer of protection.

Questions to ask vendors

  • How do you detect BEC messages that contain no links or attachments?
  • Do you flag lookalike domains and display-name impersonation of our executives and suppliers?
  • Can you detect a compromised internal mailbox, such as unusual logins or new forwarding rules?
  • How do you handle email from a real supplier account that has been taken over?
  • Does your training include finance-specific scenarios and payment verification practice?
  • What do you report to us when a BEC attempt is blocked or reported?

How it differs from phishing

Phishing is the broader technique of impersonating a trusted sender to trick someone into acting, usually by clicking a link, entering a password or opening a file. BEC is a specific fraud aimed at money or data, which may begin with phishing (to steal a mailbox password) but whose decisive message is usually a plain request with nothing malicious to scan. Controls built for phishing, such as link and attachment filtering, reduce BEC risk, but payment verification procedures and monitoring of mailbox behavior do more of the work.

Frequently Asked Questions

What should we do if we paid a fraudulent invoice?
Contact your bank immediately and ask it to recall or freeze the transfer; speed matters a great deal. In the US, report it to the FBI's Internet Crime Complaint Center (IC3) and to your cyber insurer, and have IT check whether any of your mailboxes were compromised. Recovery is not assured, but early action improves the odds.
Can email security tools stop BEC?
They help, but they are not enough alone. Many BEC emails contain no link or attachment and may come from a real, compromised account, so filters have less to inspect. Tools that analyze sender behavior and flag lookalike domains catch more, but payment verification procedures remain the most important control.
What is the difference between BEC and vendor email compromise?
Vendor email compromise is a form of BEC in which the attacker controls or impersonates one of your suppliers' email accounts and uses it to send fake invoices or changed bank details. Because the email may come from the real supplier's account, verification by phone using a number you already have on file is the key defense.
Does cyber insurance cover BEC losses?
Some policies cover funds transfer fraud or social engineering losses, often with lower sublimits than other cyber coverage, and some require proof that you followed verification procedures. Read the policy wording carefully, because coverage for BEC varies more than most.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.