Business Email Compromise (BEC)
Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.
Business email compromise (BEC) is a financially motivated attack in which the attacker impersonates — or takes over — a trusted email account to authorize fraudulent payments, redirect invoices, or exfiltrate sensitive data. The FBI's IC3 consistently ranks BEC as one of the costliest cybercrime categories, with losses exceeding $2.9 billion per year in reported cases alone.
How it works
BEC attacks typically follow one of several patterns:
- CEO fraud. The attacker impersonates the CEO or CFO and emails a finance employee requesting an urgent wire transfer to a new account. The message often emphasizes confidentiality ("Don't discuss this with anyone yet — we'll announce after close").
- Vendor invoice fraud. The attacker compromises or spoofs a supplier's email and sends a modified invoice with updated banking details. The payment goes to the attacker's account.
- Account compromise. The attacker gains access to an employee's actual mailbox (via phishing or credential stuffing) and uses it to send legitimate-looking requests to contacts, partners, or internal teams.
- Attorney impersonation. Fake legal communications create urgency around time-sensitive deals, acquisitions, or regulatory matters.
- Payroll diversion. The attacker poses as an employee and asks HR or payroll to update their direct-deposit details, quietly rerouting salary payments to an attacker-controlled account.
BEC is effective because it rarely contains malware or malicious links — the payload is a convincing email asking someone to take a routine business action. Traditional email security tools that scan for threats often miss BEC entirely.
How to defend against it
- Implement payment verification procedures — out-of-band confirmation (phone call to a known number) for any new or changed payment instructions, regardless of who appears to have sent them.
- Simulate BEC scenarios so employees in finance, HR, and executive support practice recognizing and reporting impersonation attempts. NOUSEC simulations support BEC-style pretexts.
- Deploy email authentication (SPF, DKIM, DMARC) to make domain spoofing detectable, and configure display-name impersonation warnings.
- Monitor for human risk indicators — employees who handle financial transactions or have access to sensitive data need heightened awareness and tighter controls.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo