Cybersecurity glossary

What is Business Email Compromise (BEC)?

Learn what business email compromise is, how attackers hijack payment and payroll workflows, how BEC differs from mass phishing, and which verification controls stop fraudulent transfers.

Social engineering and user threatsUpdated August 13, 2026
Also known asBECCEO fraudVendor email compromisePayment diversion fraud

Definition

Business email compromise (BEC) is a targeted social-engineering attack in which adversaries impersonate executives, vendors, attorneys, or employees—often through spoofed, lookalike, or already-compromised mailboxes—to trick staff into sending money, changing payment details, or releasing sensitive business data.

Why BEC is a finance problem, not just an email problem

Business email compromise succeeds when an organization treats an email instruction as sufficient authority to move money. Attackers study who approves wires, which vendors get paid on which cadence, and which phrases executives actually use. The goal is rarely a credential harvest. It is a one-time or recurring diversion of funds that looks like ordinary treasury work.

Unlike commodity phishing, BEC often leaves no malware, no fake login, and no obvious “urgent password reset.” Finance teams already live with urgency: closings, payroll cutoffs, supplier penalties. Criminals borrow that urgency and add a plausible reason the usual process should be skipped “just this once.”

Losses are large because the victim organization initiates the transfer itself. Banks see a genuine customer payment. Recovery windows are short, especially across borders.

How a BEC campaign typically unfolds

1

Map the money path

Identify who pays vendors, who changes banking details, and which executives can override process under time pressure.

2

Choose an identity

Impersonate a CEO, CFO, counsel, realtor, or a real supplier—via spoofing, a lookalike domain, or a hijacked mailbox.

3

Build a believable pretext

Invent a confidential deal, an overdue invoice, a tax payment, or updated beneficiary details that fit the target’s calendar.

4

Engage the operator

Email the person who can actually move funds. Follow up, reply in-thread, and keep the request inside normal business language.

5

Force a process exception

Ask for secrecy, speed, a new account, or a changed IBAN while discouraging a call to the real party.

6

Cash out and layer

Receive the transfer, move funds quickly through mule accounts, and sometimes repeat with the next invoice cycle.

Common BEC patterns

Executive impersonation

A supposed CEO or CFO emails an assistant or controller to send a confidential wire, often citing an acquisition or legal deadline.

Vendor payment diversion

A real supplier conversation is hijacked, or a lookalike vendor domain requests updated banking details before the next invoice run.

Payroll and HR theft

Attackers pose as employees or HR to change direct-deposit accounts, or request W-2 and identity files during tax season.

Legal and real-estate closings

Settlement, retainer, or property-purchase funds are redirected using attorney or escrow impersonation at the moment money must move.

Why mailbox compromise beats spoofing

A spoofed message can be caught by authentication and banner warnings. Mail sent from a compromised vendor account authenticates, continues an existing thread, and references real invoice numbers. Defenders who only hunt for failed DMARC miss this path.

That is why BEC defense has to live in the payment process: known-good callbacks, dual approval for beneficiary changes, and holding periods for first-time payees. Email controls reduce impersonation; they do not prove that the human behind a legitimate mailbox is still the supplier’s accountant.

ThreatPrimary goalTypical tell
Business email compromiseDivert funds or release business dataPayment or process change requested by a trusted identity
Mass phishingSteal credentials or drop malwareGeneric lure plus login page or attachment
Spear phishingCompromise a specific person or mailboxPersonalized lure, often a precursor to BEC
Invoice malwareInfect finance endpointsUnexpected document or archive, not a clean wire request

Controls that actually interrupt BEC

Training helps people hesitate. Process design makes hesitation mandatory.

  • Require a callback to a phone number already on file—never the number in the requesting email—before any new or changed payee details are used.
  • Split duties: the person who receives a banking-detail change cannot be the only person who releases the payment.
  • Hold first-time and high-value payments, and compare beneficiary names against invoices and contracts, not just account numbers.
  • Deploy SPF, DKIM, and a rejecting DMARC policy on your domains, and watch for lookalike registrations that mimic finance vocabulary.
  • Banner external mail, including messages that display an internal name but arrive from outside, and treat display-name-only similarity as hostile.
  • Protect executive and finance mailboxes with phishing-resistant MFA, forwarding-rule audits, and alerts on inbox rules that hide or redirect mail.
  • Ask critical vendors to notify you of mailbox incidents and to use a registered portal or signed channel for banking updates.
  • Rehearse a recall playbook with your bank: who calls, which reference fields to provide, and how fast funds can be frozen.

Detection clues worth wiring into operations

Security and finance should share signals: sudden vendor bank-detail emails, slight domain differences (vendor-payments instead of the real vendor), unusual secrecy language, weekend wires, and mailbox rules created on finance accounts. A BEC attempt that fails the callback test is still intelligence—the same crew often retries another entity in the same supply chain.

The practical takeaway

Business email compromise turns ordinary payment authority into an attack surface. Criminals do not need to break your banking app if they can convince the person who already has access to send the money somewhere else.

Authenticate email to shrink spoofing, but put the real control next to the wire: out-of-band verification, dual control, and a culture where no executive email can skip those steps. If a payment destination can change because someone asked nicely in a thread, the organization is one convincing pretext away from a loss.

Related security terms

Frequently asked questions

What is business email compromise in simple terms?

BEC is when criminals pose as a CEO, vendor, lawyer, or coworker over email and convince someone to send money or change where payments go. The message often looks routine, not like a typical phishing lure with a fake login page.

How is BEC different from ordinary phishing?

Mass phishing usually tries to steal passwords or deliver malware at scale. BEC targets a specific payment, payroll, or data-release decision. Many BEC emails contain no link and no attachment; the payload is the human instruction.

Do attackers always spoof the CEO’s address?

No. They may use a lookalike domain, a display-name-only impersonation, a compromised vendor mailbox, or a thread hijack inside a real conversation. Compromised supplier accounts are especially dangerous because prior invoices look authentic.

Why do BEC scams succeed against trained staff?

They abuse real processes: last-minute wire changes, confidentiality around M&A, vendor onboarding, and authority from senior leaders. Time pressure and apparent legitimacy beat generic ‘spot the typo’ training.

Can SPF, DKIM, and DMARC stop BEC?

They reduce direct spoofing of your own domain. They do not stop lookalike domains, display-name tricks, or mail sent from a genuinely compromised vendor account that authenticates correctly.

What is the single most effective BEC control?

Out-of-band verification of payment-detail changes using a known-good phone number or in-person process, plus dual control so one person cannot both request and release a new beneficiary.

Is BEC only about wire transfers?

Wires remain the classic payoff, but attackers also redirect ACH and payroll, steal W-2 and customer data, request gift cards, and abuse real-estate or legal settlement payments.

References

Explore authoritative guidance and frameworks related to business email compromise (bec).

Explore every security definition

Return to the glossary to search by term, alias, starting letter, or security category.

Browse glossary