Know
What is Business Email Compromise?
Business email compromise uses trusted business relationships as the attack surface. The attacker may spoof an executive, compromise a real mailbox, impersonate a vendor, or hijack an existing conversation so that a fraudulent instruction appears legitimate.
Why it matters
BEC can cause large, irreversible financial losses without malware. Normal business processes become the mechanism of the attack.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
Businesses reported hundreds of millions of dollars in BEC losses
The FBI's 2025 IC3 report lists reported Business Email Compromise losses above $568 million and separately documents AI-assisted BEC tactics including official-sounding executive impersonation and voice cloning.
BEC can produce major financial loss without exploiting a software vulnerability; the attacker exploits trust, business process, and identity verification.
Understand the mechanics
How it works
- 1
Research a company, relationship, transaction, or employee.
- 2
Impersonate or compromise a trusted identity.
- 3
Insert a believable request such as changed banking details, a confidential transfer, payroll update, or document request.
- 4
Create urgency or secrecy to reduce independent verification.
- 5
Receive the payment, credentials, or information and move quickly before the fraud is discovered.
Practice
What to watch for
- New bank or beneficiary details
- Pressure to bypass normal approval
- Secrecy
- Subtle domain differences
- Unusual timing or writing pattern
- Reply-chain or vendor-payment changes
Perform
What to do
- 1
Stop or recall the transaction if possible.
- 2
Verify the requester using a known phone number or established process.
- 3
Notify finance, security, and relevant leadership.
- 4
Preserve the message and transaction details.
- 5
Contact the financial institution promptly if money moved.
How to reduce the risk
- Dual approval for payment changes
- Out-of-band verification
- DMARC/SPF/DKIM
- Phishing-resistant MFA
- Mailbox monitoring
- Supplier-change controls
- Finance-specific simulations
Business impact
- Direct financial loss
- Payroll diversion
- Sensitive-data exposure
- Legal and insurance consequences
- Supplier/customer trust damage
What different roles should do
Finance
- Never change payment details solely from email
- Use dual approval and known-channel verification
Executive
- Do not encourage exceptions to payment controls
- Use agreed verification procedures
Security
- Investigate mailbox access, forwarding rules, sessions, and related messages
Framework & standards context
- MITRE ATT&CK T1566 — Phishing
Source transparency
Authoritative sources
Last reviewed: 2026-09-02