Back to Learning Hub

Business Email Compromise (BEC) Explained

Last updated: 2026-08-133 min read

Learn what Business Email Compromise (BEC) is, how these sophisticated financial scams work, and the strategies organizations can use to defend against them.

Business Email Compromise (BEC) is a cybercrime in which an attacker uses a legitimate or convincingly faked business email account to redirect money. Unlike ordinary phishing, it rarely relies on malicious links or attachments. BEC is almost pure social engineering and impersonation.

It is consistently among the most financially damaging categories of cybercrime — the FBI puts global losses in the billions. For per-incident losses by sector, see the BEC industry benchmarks.


How BEC works

  1. Reconnaissance. The attacker studies the organisation through LinkedIn, the company website, and social media, mapping executives, finance staff, and vendor relationships.
  2. Compromise or impersonation. They either take over a real mailbox — usually via an earlier credential phishing attack — or register a lookalike domain, [email protected] in place of [email protected].
  3. Monitoring. With a real account, they read quietly for days or weeks, learning payment cycles, vendor names, and how the account's owner writes.
  4. The ask. An email requests an urgent wire transfer, a change of payment routing, or gift card purchases — timed and worded to sound entirely routine.

The main variants

  • CEO fraud. An executive is impersonated and finance receives an urgent, confidential transfer request.
  • Vendor email compromise. A supplier's account is compromised and fake invoices go to their clients, routing payment to the attacker.
  • Account compromise. An employee's mailbox is used to request invoice payments to fraudulent accounts.
  • Attorney impersonation. The attacker poses as legal counsel handling a secret, time-critical matter needing immediate funding.

Why it evades technical controls

There is usually no malware to detect — no attachment, no link for a scanner to flag. When a real account is compromised, the message comes from a genuine sender on a genuine domain, passing every authentication check — which is why an email header analyzer tells you a sender is forged, but never that a request is safe. And the request arrives wrapped in real context, such as an invoice that was genuinely due, so it reads as normal business.

Defending against BEC

Out-of-band verification is the single most effective control. Any change to payment details or high-value transfer must be confirmed by calling the vendor on a number you already hold — never the number in the email.

Around that: require multi-factor authentication on all mailboxes, which raises the cost of the account takeover BEC depends on. Demand multiple approvals for transfers above a threshold, so no one person can both authorise and execute a large payment. Publish SPF, DKIM, and DMARC records — an email spoofing test shows which of the three your domain publishes today — and flag domains that look confusingly similar to your own or your partners'.

Move fast if it happens. A wire transfer can sometimes be recalled within hours but rarely after days, so the order is: contact your bank immediately and ask for a recall, then report to law enforcement, then preserve the mailbox evidence before anyone "tidies up". Treat a successful BEC as an account compromise as well as a financial loss — assume the mailbox is still being read until you have proven otherwise.

Finally, train the people actually targeted. Generic phishing training is not enough for finance, HR, and executive staff, who need to recognise CEO fraud and vendor compromise specifically — see BEC prevention training.


Related Learning

Ready to stop phishing attacks?

Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.