Business Email Compromise (BEC)
What Is Business Email Compromise?
Business Email Compromise (BEC) is a sophisticated cyberattack in which criminals impersonate trusted individuals (executives, vendors, or business partners) through email to manipulate employees into transferring funds, disclosing credentials, or sharing sensitive information. Unlike phishing campaigns that cast wide nets, BEC attacks are targeted, researched, and personalised.
BEC represents one of the highest-value cybercrime categories globally because it exploits human trust rather than technical vulnerabilities. There is often no malware involved, just convincing social engineering through carefully crafted email communication.
How BEC Attacks Are Executed
Attackers typically begin with open-source intelligence gathering, researching the target organisation’s leadership, vendor relationships, payment processes, and communication patterns through social media, the company website, and prior data breaches. They then craft emails that appear to originate from a trusted source.
Common BEC scenarios include:
- CEO fraud: An email appearing to be from the CEO instructs the finance team to process an urgent wire transfer
- Vendor impersonation: A supplier's email account is compromised and used to redirect invoice payments to a fraudulent account
- Attorney impersonation: Fake legal counsel pressure-tests employees during sensitive transactions
- Employee credential harvesting: Fake IT support requests trick staff into surrendering login credentials
Why BEC Is Particularly Dangerous for Businesses
BEC attacks bypass most traditional cybersecurity defences because they do not contain malicious links or attachments that trigger automated filtering systems. They rely on social engineering, manipulating human decision-making. The time pressure, authority framing, and apparent legitimacy of these requests are specifically designed to override an employee’s instinct to verify.
Protecting Your Organisation Against BEC
Technical controls provide a first layer of defence: email authentication protocols (SPF, DKIM, DMARC), multi-factor authentication on email accounts, and AI-based anomaly detection that flags unusual sender behaviour. But technical measures alone are insufficient.
Employee awareness training is essential. Staff need to understand BEC attack patterns, know how to verify payment or credential requests through out-of-band confirmation (a direct phone call, not a reply to the same email chain), and feel empowered to question unusual instructions regardless of apparent authority.
Key Takeaways
- BEC is a targeted social engineering attack that impersonates trusted figures to manipulate financial transfers or credential disclosure.
- It exploits human trust rather than technical vulnerabilities, bypassing most automated security filters.
- Common forms include CEO fraud, vendor impersonation, and attorney impersonation during sensitive transactions.
- Effective BEC defence combines email authentication protocols, MFA, anomaly detection, and regular staff awareness training.
- Out-of-band verification for any unusual financial or credential request is the most direct human control against BEC.
