top of page

Stay Ahead of Emerging Threats

Thanks for submitting!

What is Business Email Compromise (BEC)?

  • Writer: ESET Expert
    ESET Expert
  • 21 minutes ago
  • 10 min read

In the era of instant communication and remote approvals, business email compromise shows how quickly routine processes can become attack paths.



With Business Email Compromise (BEC), attackers impersonate or take over a trusted identity to trick victims into sending money, credentials, or sensitive information to an unauthorized recipient.

It can be especially difficult to detect, as attackers can compromise legitimate inboxes or phone numbers, spoof addresses, identities, or even web domains to give the impression that they are communicating from a known, legitimate business. As a result, attacks don’t always involve malicious hyperlinks or files.


Key points of this article:


  • BEC targets trusted business processes, often deceiving victims into making a payment or account change that redirects funds to accounts controlled by criminals. 


  • The attacker may pretend to be someone in authority and use a non-company address or communicate from a genuine, but compromised account.


  • Phishing and BEC can overlap, but BEC is defined by the trusted-business impersonation and fraud objective.


  • Always verify payment or account changes through a separate, trusted channel.


  • If money has moved, contact the originating bank and file a detailed report with law enforcement immediately.

What is business email compromise?


A classic example of a business email compromise scam is an urgent email from someone impersonating the CEO of a company to an employee, asking them to resolve an urgent issue—be it by sending payment to a supplier, or sharing confidential information for an upcoming presentation. 

But that’s not the only type of attack by far, and it can be difficult to defend against because the attacker doesn’t need to follow a set path; they can hijack the business’ own communications channels and often can do so in multiple subtle ways. 


At its heart, BEC fraud involves impersonating a trusted business identity to redirect payments, credentials, or sensitive information, into the wrong hands. Attackers use a variety of methods to achieve this—they aren’t limited to the phishing or whaling attacks that have dominated news coverage.


Where BEC differs from other social engineering attacks


BEC can and does take place without any cyber expertise on the part of the attacker; they can set up a free email address using the name of an executive and convince their victim that they should communicate through that account, for example.


Of course, a BEC attack can start with a phishing link in an email, but it’s just as possible for an effective attack to involve nothing more than plain text email or SMS. On the other hand, the advent of real time video- and voice-altering platforms have made it possible for very sophisticated scams involving video and voice calls to impersonate executives in real time.


It’s important to remove ambiguity at this point, because some types of cyber attacks and scams are used in BEC.


Term

Useful working meaning

Relationship

BEC

Trusted-business impersonation used to cause fraud or data loss

The overall fraud pattern

Phishing

Deceptive communication used to prompt an unsafe action

Can be an entry method or part of BEC

Email account compromise

Unauthorized control of a real email account

Can make a BEC request appear authentic

Spoofing/lookalike domain

A forged or deceptively similar sender identity

One impersonation method

Video and Audio impersonation

Deceptive video or audio communication

Can be an entry method or further reinforcement method for BEC


How a BEC attack works


We’ve said it before, but it bears repeating: many successful cyberattacks begin with social engineering. Convincing a person to grant access, share information, or approve a transaction is often faster and easier than exploiting a technical vulnerability. As a result, attackers frequently rely on deception rather than advanced technical capabilities.


Successful BEC attacks make use of timing and context, exploiting trusted identities and relationships as well as hierarchies to gain access before suggesting a plausible transaction that changes a critical detail in an otherwise legitimate transaction redirecting funds or information to the attacker. That could involve a slide presentation going to what might seem like the CEO’s personal email address, or it might be the urgent payment of a purchase order for a supplier based on a PDF invoice that contains payment details for a compromised bank account, instead of the actual supplier’s existing payment details.


Let’s break this process down into a series of steps for the attacker:


  1. Reconnaissance. Attackers identify executives, finance staff, vendors, deals or payment cycles.

  2. Access or imitation: They then compromise a mailbox, spoof an address, or register a lookalike domain.

  3. Context building: They gain a context understanding that might be the style and tone of the person they are spoofing, the timing around regular financial transactions, or current events affecting the target business, such as a merger or acquisition.

  4. The change: Fraudsters introduce new banking details, wire transfer, gift cards purchases (if they’re unambitious), payroll redirection or sensitive records.

  5. Pressure: Combined with timing, the attacker will work to inject urgency, confidentiality or authority to unconsciously persuade the victim to bypass normal checks.

  6. Transfer and movement: If funds are being stolen, the attacker then needs to extract them, redirecting funds through other accounts to a point at which they can be cashed out.


Common types of BEC


We’ve given a flavor of the types of BEC attack, but it’s worth grouping them together as a means to understanding and preventing them:


  • Vendor or invoice fraud: The attacker either impersonates or compromises an established supplier or customer, changing payment details on a genuine invoice, or creating a fraudulent invoice with altered payment details.


  • Executive impersonation (CEO fraud): Victims are approached by an attacker who impersonates a senior leader or fellow employee who requests help with an urgent purchase, account credentials, or other information. Even seemingly harmless details, such as office locations or meeting-room data, can help attackers build credibility in later stages of a scam.


  • Payroll diversion: This attack targets HR and payroll teams, impersonating an employee and asking them to alter the banking details to a different bank account controlled by the attacker.


  • Attorney or real-estate fraud: This type of fraud occurs during large purchases by a company, like the acquisition of another business, the purchase of a costly piece of equipment or real estate. The attacker impersonates a key person in the transaction, such as a lawyer or executive, and inserts replacement payment instructions to divert funds.


  • Gift-card fraud: An employee is persuaded to buy gift cards on their company payment account and send the codes to the attacker.


  • Data-request fraud: The fraudulent request seeks tax, payroll, or employee information that can used to enable further fraud.


What’s the scale of the problem?


BEC should not be underestimated. The US Federal Bureau of Investigation (FBI) runs a center for handling reports of internet-connected crime, going by the name of Internet Crime Complaint Center (IC3). 


In 2025, its second highest recorded cyber-enabled crime loss behind Investment Fraud was BEC, at more than $3 billion in reported losses, based solely on voluntary complaints. That’s just in the USA, and only applies to complaints received by IC3, excluding the business cost of recovering from the fraud, so it’s inevitable that the real cost is even more than that. 


Same report shows that over the three-year period from 2023 to 2025, annual losses from BEC consistently ranged between $2.77 billion and $3 billion.


How AI changes the impersonation risk


Something that’s recently changed the phishing landscape is AI, However, this is a bit tricky to measure for BEC attacks, as it isn’t always apparent that AI has been involved, or the level of sophistication of its use. For example, IC3 reported over 22,000 complaints and roughly $893 million in adjusted losses with an AI-related descriptor across all crime types—so not just BEC. Sophistication ranged from official-sounding emails to voice cloning.


There’s also a certain amount of confirmation bias at work when it comes to AI use in cyber crime and scams generally: things like voice or video cloning sound scary and dominate coverage, when in reality, their use is less frequent. That said, AI is often used in organizations to automate dull, repetitive work, and it isn’t a surprise that criminals want to do the same.



Why one control is not enough


Because BEC can take place without cyber compromise, there’s is no single technology capable of preventing every form of BEC. In fact, existing cyber security capabilities can prevent or alert on email account compromise, known-bad domains or malware. 


Banks now routinely check the names of payees against details payers put in to prevent what’s called APP (Advanced Push Payment) scams where the account number and sort code for payments are substituted in intercepted invoices. It’s entirely practical to build up a picture of an emerging attack using mailbox rules, communication pattern analysis and payload and keyword filtering. 


Protecting accounts and banking processes with multifactor authentication or signoff procedures for large bank transfers involving multiple people is also both possible and desirable in many cases.

The other thing to note is that BEC can target members of the public; for example, an attacker can spoof or compromise the email account of a bank or law firm and persuade a home buyer to route payment for their new property to a different account.


Nonetheless, the most effective defenses are cultural: training (and re-training) employees in the common signals that a scam might be under way.


Controls and what they do:

Control

Helps with

Does not solve alone

SPF (Sender Policy Framework), DKIM (Domain Keys Identified Mail) and DMARC (Domain-based Message Authentication, Reporting and Conformance

Some sender spoofing and domain-abuse cases

A real compromised mailbox

Email filtering

Known malicious content, infrastructure and suspicious patterns

Every plain-text social engineering request

MFA (Multifactor Authentication) and identity controls

Many account-takeover paths

Spoofing or a fraudulent business process

Detection and response

Identity, mailbox and behavioral signals; investigation

The payment approval decision by itself

Finance verification

Fraudulent account or payment changes

Mailbox compromise and wider intrusion

Awareness training

Recognition, reporting and process use

A guaranteed human outcome that is flexible across technological attack and social engineering

How to reduce BEC risk: one simple rule


There’s one rule that might help deal with these attacks though. BEC and similar frauds often involve time pressure on the victim, and there’s a major reason for that: given time, the story the fraudster has spun unravels fast. As a result, the golden rule for anyone tasked with a sudden, significant change or charge, is to inspect it. 


Verify the change, not the message


What does this mean? It means that it’s vital to confirm new payment details or instructions through a different contact method or communications channel using details stored in a trusted system. 

That might be as simple as calling the desk extension of the executive to check the instruction before proceeding, or looking up the supplier’s phone number directly from its website or the letterhead on a physical invoice. Ignore contact details that are supplied as part of the communication and go direct to a verifiable source. 


Here’s a list, in order, of what you should look to do:

  1. Independently verify any payment or account details; If you receive an invoice with new details, or an invoice from a brand new supplier, call them to check the details are correct.

  2. Set thresholds for risk-based transactions: For example, a daily limit on company credit card spend, or spend on specific items such as gift cards. For significant amounts, consider dual authorization policies.

  3. Enable Multifactor Authentication (Preferably using authentication apps or hardware tokens instead of SMS) and strong account recovery procedures.

  4. Monitor for anomalous sign-ins, mailbox rules and delegated access. Managed Detection and response and email security platforms are both useful for this.

  5. Enable domain protection and email authentication.

  6. Define role-specific practices for finance, HR, executives and high-risk suppliers. For example, payroll detail changes should be verified in person, or via trusted communications such as in-house messaging apps or the employee’s home or personal mobile number.

  7. Create simple reporting routes for unusual requests or communications with rapid security and finance escalation. Everyone should know who to speak to if they receive an unusual request from someone who looks or sounds like a senior executive.



First things first: don’t sit on the information. 


If the suspected BEC involved a financial transaction, alert the bank you used immediately with your suspicions and as much information as possible, and also alert your organization’s finance team if it’s a payment made on behalf of a company. 


Ask the bank for a payment recall or reversal, and also ask about the Hold Harmless Letter or Letter of Indemnity processes the bank uses in situations such as this. Next, speak to law enforcement; in the US this is likely to be IC3, but in the UK it’ll likely be Report Fraud platform, for example. The more information and detail you can provide the better.


The bad news: It’s far from given that the payment or information that’s been given away can be recovered. That said, banks and law enforcement can do more if they’re alerted quickly and given all of the information, and it can prevent further frauds or play a part in bringing the attackers to justice.

What sort of data and information on the fraud are useful for banks and law enforcement, and what do you need to do?


  1. Preserve any messages, including full headers, transaction records and relevant mailbox and identity logs.

  2. Secure any affected accounts, revoke active sessions and review forwarding or inbox rules applied to suspected compromised accounts.

  3. Determine whether other payments, mailboxes, identities or data are affected.

  4. Notify internal Finance, Security, Legal, Privacy and Insurer contacts according to the approved plan. Your organization does have a plan, right? Check that exists.

  5. Document all decisions and apply lessons to verification and detection controls.

  6. Make a case for social engineering and fraud training for employees to help them spot attempts.

Conclusion: Don’t let that invoice wear a fake moustache


BEC succeeds when trust, urgency, and routine business processes are exploited. While email security, identity protection, and monitoring tools all play important roles, effective defenses depend just as much on verification procedures and employee awareness. 

Organizations that consistently verify payment changes, protect accounts with strong authentication, and train employees to question unusual requests can significantly reduce their risk of BEC-related fraud.


FAQs: Business email compromise


Is BEC the same as phishing?

You can have BEC without phishing and vice versa—there is an overlap. BEC is a targeted fraud tactic built around a trusted business identity and request. Phishing can play a part in it, but a lack of phishing email doesn’t mean a lack of attempted BEC fraud.


What is the difference between BEC and email account compromise?

BEC describes the pattern of a specific type of fraud. Just like our answer on Phishing above, email account compromise can take place outside of BEC fraud. It usually describes control of a real mailbox, which can be used to carry out BEC.


What are common examples of BEC?

Common patterns include vendor invoice changes, executive payment requests, payroll redirection, real-estate wire fraud, gift card scams, and requests for employee data or credentials.


How much did BEC cost in 2025?

IC3 recorded $3,046,598,558 in reported BEC losses from 24,768 complaints in 2025. BEC was second by reported loss behind investment fraud.


Can email security stop BEC?

Email security can block or flag some attacks, but no single control covers spoofing, real-account compromise and fraudulent business requests. Organizations need to combine email, identity, detection, finance and awareness controls.


What should a business do after sending money to a scammer?

Contact the originating bank immediately to request a recall or reversal, then file a detailed complaint with law enforcement. Follow the approved incident plan and preserve evidence.


Does AI cause most BEC attacks?

No—not so far. AI can support convincing email and voice impersonation, but there is little evidence that it is being used at scale beyond a few high-profile new reports.

Comments


bottom of page