Business email compromise (BEC) is a fraud scheme in which criminals impersonate executives, employees or suppliers by email to trick a company into sending money or sensitive data.
How BEC works
The attackers either break into a real mailbox – usually through phishing or reused passwords – or register a look-alike domain that differs by one letter. They study ongoing conversations and then strike at the right moment. Typical scenarios:
- CEO fraud – the “director” urgently asks accounting for a confidential transfer;
- fake invoices – a “supplier” announces new bank details;
- payroll diversion – an “employee” asks HR to change the salary account;
- data theft – requests for tax forms or customer records.
BEC often contains no links or attachments at all, so mail filters rarely catch it. Increasingly the email is backed by a phone call or video meeting with a voice or face deepfake.
Why BEC matters for security
According to the FBI’s Internet Crime Complaint Center, BEC causes losses of billions of dollars every year – far more than ransomware in direct reported losses. A single successful attack can cost a company millions, and money sent abroad is hard to recover once it passes through mule accounts.
How to defend
- Verify any payment or bank-detail change by calling a known phone number, never the one in the email.
- Require two-person approval for large or unusual transfers.
- Protect mailboxes with MFA, and alert on new forwarding and inbox rules.
- Configure DMARC and flag external senders and look-alike domains.