Threats & Social EngineeringBeginnerThreat1 validated evidence record

Business Email Compromise (BEC)

30 sec

A fraud scheme in which an attacker impersonates or compromises a trusted business identity to manipulate payments, payroll, credentials, or sensitive information.

Know

What is Business Email Compromise?

Business email compromise uses trusted business relationships as the attack surface. The attacker may spoof an executive, compromise a real mailbox, impersonate a vendor, or hijack an existing conversation so that a fraudulent instruction appears legitimate.

Why it matters

BEC can cause large, irreversible financial losses without malware. Normal business processes become the mechanism of the attack.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Government / AuthoritativeMeasured outcome

Businesses reported hundreds of millions of dollars in BEC losses

2025FBI Internet Crime Complaint CenterCross-sector

The FBI's 2025 IC3 report lists reported Business Email Compromise losses above $568 million and separately documents AI-assisted BEC tactics including official-sounding executive impersonation and voice cloning.

Why this is evidence

BEC can produce major financial loss without exploiting a software vulnerability; the attacker exploits trust, business process, and identity verification.

See the source — FBI: 2025 Internet Crime Report

Understand the mechanics

How it works

  1. 1

    Research a company, relationship, transaction, or employee.

  2. 2

    Impersonate or compromise a trusted identity.

  3. 3

    Insert a believable request such as changed banking details, a confidential transfer, payroll update, or document request.

  4. 4

    Create urgency or secrecy to reduce independent verification.

  5. 5

    Receive the payment, credentials, or information and move quickly before the fraud is discovered.

Practice

What to watch for

  • New bank or beneficiary details
  • Pressure to bypass normal approval
  • Secrecy
  • Subtle domain differences
  • Unusual timing or writing pattern
  • Reply-chain or vendor-payment changes

Perform

What to do

  1. 1

    Stop or recall the transaction if possible.

  2. 2

    Verify the requester using a known phone number or established process.

  3. 3

    Notify finance, security, and relevant leadership.

  4. 4

    Preserve the message and transaction details.

  5. 5

    Contact the financial institution promptly if money moved.

How to reduce the risk

  • Dual approval for payment changes
  • Out-of-band verification
  • DMARC/SPF/DKIM
  • Phishing-resistant MFA
  • Mailbox monitoring
  • Supplier-change controls
  • Finance-specific simulations

Business impact

  • Direct financial loss
  • Payroll diversion
  • Sensitive-data exposure
  • Legal and insurance consequences
  • Supplier/customer trust damage

What different roles should do

Finance

  • Never change payment details solely from email
  • Use dual approval and known-channel verification

Executive

  • Do not encourage exceptions to payment controls
  • Use agreed verification procedures

Security

  • Investigate mailbox access, forwarding rules, sessions, and related messages

Framework & standards context

  • MITRE ATT&CK T1566 — Phishing

Keep learning

CEO FraudVendor Email CompromiseEmail SpoofingAccount TakeoverDMARC

Source transparency

Authoritative sources

Last reviewed: 2026-09-02