BEC (Business Email Compromise)
Business email compromise (BEC) is a targeted attack in which a fraudster impersonates a trusted party, such as an executive, supplier or colleague, over email to trick an organisation into transferring money or sensitive data. BEC relies on social engineering rather than malware, and it is one of the most financially damaging categories of cyber crime.
Business email compromise is a form of targeted email fraud in which an attacker impersonates someone the victim trusts in order to induce a fraudulent payment or the disclosure of sensitive information. Unlike mass phishing, BEC is precise and researched: the attacker studies the target organisation, understands its payment processes and relationships, and crafts a convincing request that fits normal business activity. It relies almost entirely on deception rather than technical exploitation.
Several common scenarios recur. In CEO fraud, the attacker impersonates a senior executive and instructs a finance-team member to make an urgent payment. In invoice fraud, the attacker poses as a legitimate supplier and requests that future payments go to a new, attacker-controlled bank account. In payroll diversion, an employee’s salary is redirected. Each exploits legitimate business processes, and each turns on a human being trusting a request that looks routine.
What makes BEC so effective, and so dangerous, is that it often involves no malware at all. There is no malicious attachment or link for a security tool to catch; there is simply an email, sometimes sent from a genuinely compromised account, making a plausible request. This means technical defences that scan for malicious content may see nothing wrong, and the attack succeeds or fails on whether a person notices something amiss. Attackers reinforce the deception with urgency, authority and secrecy to discourage the victim from checking.
The financial impact is severe. Law-enforcement agencies consistently rank BEC among the costliest categories of cyber crime by total losses, ahead of many higher-profile threats, because a single successful attack can divert a large payment and because it targets exactly the processes that move money. The losses are direct and often difficult to recover once funds have been transferred to an attacker’s account and moved on.
Defending against BEC combines technical and procedural controls. Email authentication standards make impersonation of an organisation’s own domain harder, and multi-factor authentication reduces account takeover. But because the attack targets process and judgement, procedural controls are decisive: verifying payment and bank-detail changes through a second, out-of-band channel, requiring dual authorisation for significant transfers, and training staff, especially in finance, to recognise the pressure tactics of BEC and to treat urgency as a reason to verify rather than to hurry.
Because BEC targets process and judgement rather than technology, the most effective defences are procedural. Verifying any change to payment or bank details through a separate, out-of-band channel, requiring dual authorisation for significant transfers, and training finance staff to treat urgency as a reason to check rather than to hurry all defeat the core tactic. Technical controls such as email authentication and multi-factor authentication reduce impersonation and account takeover, but the procedural controls are decisive.
Social engineering assessments from Precursor test susceptibility to business email compromise and related fraud, and helps organisations harden both the technical controls and the payment-verification processes that stop these attacks.