← All terms

Business Email Compromise (BEC)

Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.

Business email compromise (BEC) is a financially motivated attack in which the attacker impersonates — or takes over — a trusted email account to authorize fraudulent payments, redirect invoices, or exfiltrate sensitive data. The FBI's IC3 consistently ranks BEC as one of the costliest cybercrime categories, with losses exceeding $2.9 billion per year in reported cases alone.

How it works

BEC attacks typically follow one of several patterns:

  • CEO fraud. The attacker impersonates the CEO or CFO and emails a finance employee requesting an urgent wire transfer to a new account. The message often emphasizes confidentiality ("Don't discuss this with anyone yet — we'll announce after close").
  • Vendor invoice fraud. The attacker compromises or spoofs a supplier's email and sends a modified invoice with updated banking details. The payment goes to the attacker's account.
  • Account compromise. The attacker gains access to an employee's actual mailbox (via phishing or credential stuffing) and uses it to send legitimate-looking requests to contacts, partners, or internal teams.
  • Attorney impersonation. Fake legal communications create urgency around time-sensitive deals, acquisitions, or regulatory matters.
  • Payroll diversion. The attacker poses as an employee and asks HR or payroll to update their direct-deposit details, quietly rerouting salary payments to an attacker-controlled account.

BEC is effective because it rarely contains malware or malicious links — the payload is a convincing email asking someone to take a routine business action. Traditional email security tools that scan for threats often miss BEC entirely.

How to defend against it

  • Implement payment verification procedures — out-of-band confirmation (phone call to a known number) for any new or changed payment instructions, regardless of who appears to have sent them.
  • Simulate BEC scenarios so employees in finance, HR, and executive support practice recognizing and reporting impersonation attempts. NOUSEC simulations support BEC-style pretexts.
  • Deploy email authentication (SPF, DKIM, DMARC) to make domain spoofing detectable, and configure display-name impersonation warnings.
  • Monitor for human risk indicators — employees who handle financial transactions or have access to sensitive data need heightened awareness and tighter controls.
Full guide
Read the deep dive on this attack →

Related terms

WhalingWhaling is a spear phishing attack specifically targeting senior executives or high-value individuals within an organization.Spear PhishingSpear phishing is a targeted phishing attack that uses personalized information about the victim to increase its effectiveness.PretextingPretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.Vendor Email Compromise (VEC)Vendor email compromise hijacks a supplier's real email account or thread to redirect customer payments — BEC's hardest-to-spot variant.CEO FraudCEO fraud is a social engineering attack where criminals impersonate a senior executive to pressure an employee into urgent wire transfers or data disclosure.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo