Mastodon Mastodon Mastodon Mastodon

Business Email Compromise

Updated: · CyberSecureFox Editorial Team

Business email compromise (BEC) is a fraud scheme in which criminals impersonate executives, employees or suppliers by email to trick a company into sending money or sensitive data.

How BEC works

The attackers either break into a real mailbox – usually through phishing or reused passwords – or register a look-alike domain that differs by one letter. They study ongoing conversations and then strike at the right moment. Typical scenarios:

  • CEO fraud – the “director” urgently asks accounting for a confidential transfer;
  • fake invoices – a “supplier” announces new bank details;
  • payroll diversion – an “employee” asks HR to change the salary account;
  • data theft – requests for tax forms or customer records.

BEC often contains no links or attachments at all, so mail filters rarely catch it. Increasingly the email is backed by a phone call or video meeting with a voice or face deepfake.

Why BEC matters for security

According to the FBI’s Internet Crime Complaint Center, BEC causes losses of billions of dollars every year – far more than ransomware in direct reported losses. A single successful attack can cost a company millions, and money sent abroad is hard to recover once it passes through mule accounts.

How to defend

  • Verify any payment or bank-detail change by calling a known phone number, never the one in the email.
  • Require two-person approval for large or unusual transfers.
  • Protect mailboxes with MFA, and alert on new forwarding and inbox rules.
  • Configure DMARC and flag external senders and look-alike domains.
Synonyms:
business e-mail compromise