Cybersecurity glossary
What is Business Email Compromise (BEC)?
Learn what business email compromise is, how attackers hijack payment and payroll workflows, how BEC differs from mass phishing, and which verification controls stop fraudulent transfers.
Definition
Business email compromise (BEC) is a targeted social-engineering attack in which adversaries impersonate executives, vendors, attorneys, or employees—often through spoofed, lookalike, or already-compromised mailboxes—to trick staff into sending money, changing payment details, or releasing sensitive business data.
Why BEC is a finance problem, not just an email problem
Business email compromise succeeds when an organization treats an email instruction as sufficient authority to move money. Attackers study who approves wires, which vendors get paid on which cadence, and which phrases executives actually use. The goal is rarely a credential harvest. It is a one-time or recurring diversion of funds that looks like ordinary treasury work.
Unlike commodity phishing, BEC often leaves no malware, no fake login, and no obvious “urgent password reset.” Finance teams already live with urgency: closings, payroll cutoffs, supplier penalties. Criminals borrow that urgency and add a plausible reason the usual process should be skipped “just this once.”
Losses are large because the victim organization initiates the transfer itself. Banks see a genuine customer payment. Recovery windows are short, especially across borders.
How a BEC campaign typically unfolds
Map the money path
Identify who pays vendors, who changes banking details, and which executives can override process under time pressure.
Choose an identity
Impersonate a CEO, CFO, counsel, realtor, or a real supplier—via spoofing, a lookalike domain, or a hijacked mailbox.
Build a believable pretext
Invent a confidential deal, an overdue invoice, a tax payment, or updated beneficiary details that fit the target’s calendar.
Engage the operator
Email the person who can actually move funds. Follow up, reply in-thread, and keep the request inside normal business language.
Force a process exception
Ask for secrecy, speed, a new account, or a changed IBAN while discouraging a call to the real party.
Cash out and layer
Receive the transfer, move funds quickly through mule accounts, and sometimes repeat with the next invoice cycle.
Common BEC patterns
Executive impersonation
A supposed CEO or CFO emails an assistant or controller to send a confidential wire, often citing an acquisition or legal deadline.
Vendor payment diversion
A real supplier conversation is hijacked, or a lookalike vendor domain requests updated banking details before the next invoice run.
Payroll and HR theft
Attackers pose as employees or HR to change direct-deposit accounts, or request W-2 and identity files during tax season.
Legal and real-estate closings
Settlement, retainer, or property-purchase funds are redirected using attorney or escrow impersonation at the moment money must move.
Why mailbox compromise beats spoofing
A spoofed message can be caught by authentication and banner warnings. Mail sent from a compromised vendor account authenticates, continues an existing thread, and references real invoice numbers. Defenders who only hunt for failed DMARC miss this path.
That is why BEC defense has to live in the payment process: known-good callbacks, dual approval for beneficiary changes, and holding periods for first-time payees. Email controls reduce impersonation; they do not prove that the human behind a legitimate mailbox is still the supplier’s accountant.
BEC versus related email threats
| Threat | Primary goal | Typical tell |
|---|---|---|
| Business email compromise | Divert funds or release business data | Payment or process change requested by a trusted identity |
| Mass phishing | Steal credentials or drop malware | Generic lure plus login page or attachment |
| Spear phishing | Compromise a specific person or mailbox | Personalized lure, often a precursor to BEC |
| Invoice malware | Infect finance endpoints | Unexpected document or archive, not a clean wire request |
Controls that actually interrupt BEC
Training helps people hesitate. Process design makes hesitation mandatory.
- Require a callback to a phone number already on file—never the number in the requesting email—before any new or changed payee details are used.
- Split duties: the person who receives a banking-detail change cannot be the only person who releases the payment.
- Hold first-time and high-value payments, and compare beneficiary names against invoices and contracts, not just account numbers.
- Deploy SPF, DKIM, and a rejecting DMARC policy on your domains, and watch for lookalike registrations that mimic finance vocabulary.
- Banner external mail, including messages that display an internal name but arrive from outside, and treat display-name-only similarity as hostile.
- Protect executive and finance mailboxes with phishing-resistant MFA, forwarding-rule audits, and alerts on inbox rules that hide or redirect mail.
- Ask critical vendors to notify you of mailbox incidents and to use a registered portal or signed channel for banking updates.
- Rehearse a recall playbook with your bank: who calls, which reference fields to provide, and how fast funds can be frozen.
Detection clues worth wiring into operations
Security and finance should share signals: sudden vendor bank-detail emails, slight domain differences (vendor-payments instead of the real vendor), unusual secrecy language, weekend wires, and mailbox rules created on finance accounts. A BEC attempt that fails the callback test is still intelligence—the same crew often retries another entity in the same supply chain.
The practical takeaway
Business email compromise turns ordinary payment authority into an attack surface. Criminals do not need to break your banking app if they can convince the person who already has access to send the money somewhere else.
Authenticate email to shrink spoofing, but put the real control next to the wire: out-of-band verification, dual control, and a culture where no executive email can skip those steps. If a payment destination can change because someone asked nicely in a thread, the organization is one convincing pretext away from a loss.
Related security terms
Phishing
Broader credential and lure campaigns; BEC is a payment-focused, often malware-free subset.
Spear Phishing
Highly tailored email used to research, impersonate, or compromise the mailboxes that enable BEC.
Email Spoofing
Forged sender identity is one common way BEC messages appear to come from a trusted executive or supplier.
Pretexting
The invented business story—urgent closing, confidential acquisition, updated banking details—that makes the request feel legitimate.
Social Engineering
The human-influence discipline that BEC applies to finance, legal, and HR workflows.
Frequently asked questions
What is business email compromise in simple terms?
BEC is when criminals pose as a CEO, vendor, lawyer, or coworker over email and convince someone to send money or change where payments go. The message often looks routine, not like a typical phishing lure with a fake login page.
How is BEC different from ordinary phishing?
Mass phishing usually tries to steal passwords or deliver malware at scale. BEC targets a specific payment, payroll, or data-release decision. Many BEC emails contain no link and no attachment; the payload is the human instruction.
Do attackers always spoof the CEO’s address?
No. They may use a lookalike domain, a display-name-only impersonation, a compromised vendor mailbox, or a thread hijack inside a real conversation. Compromised supplier accounts are especially dangerous because prior invoices look authentic.
Why do BEC scams succeed against trained staff?
They abuse real processes: last-minute wire changes, confidentiality around M&A, vendor onboarding, and authority from senior leaders. Time pressure and apparent legitimacy beat generic ‘spot the typo’ training.
Can SPF, DKIM, and DMARC stop BEC?
They reduce direct spoofing of your own domain. They do not stop lookalike domains, display-name tricks, or mail sent from a genuinely compromised vendor account that authenticates correctly.
What is the single most effective BEC control?
Out-of-band verification of payment-detail changes using a known-good phone number or in-person process, plus dual control so one person cannot both request and release a new beneficiary.
Is BEC only about wire transfers?
Wires remain the classic payoff, but attackers also redirect ACH and payroll, steal W-2 and customer data, request gift cards, and abuse real-estate or legal settlement payments.
References
Explore authoritative guidance and frameworks related to business email compromise (bec).
Explore every security definition
Return to the glossary to search by term, alias, starting letter, or security category.