What is business email compromise (BEC)?
Business email compromise (BEC) is a form of targeted, email-based social-engineering fraud in which an attacker impersonates a trusted person, such as an executive, a colleague, or a vendor, to trick an employee into transferring money or handing over sensitive data. Unlike mass phishing, BEC is highly personalized and usually contains no malware, no malicious links, and no attachments. That's precisely what makes it so hard for traditional email security to catch. It's also known as email account compromise (EAC), and the FBI has described it as one of the most financially damaging online crimes tracked. Because BEC abuses normal business processes, an urgent request from the "CEO," a vendor's "updated" bank details, rather than exploiting a technical vulnerability, it succeeds against organizations of every size and maturity. This page explains what BEC is, how an attack unfolds, the main types the FBI recognizes, why it's so difficult to detect, its real-world scale, and how organizations can prevent and respond to it.
Key takeaways
- BEC is targeted email fraud, not mass phishing. Attackers impersonate a trusted party and tailor the message to a specific victim, usually to trigger a payment or data disclosure.
- It often carries no malware or links. BEC emails are frequently plain text, so they slip past filters that look for malicious payloads.
- It exploits people and process, not software. BEC relies on authority, urgency, and trust in normal approval workflows rather than a technical exploit.
- The financial impact is enormous. BEC is consistently among the costliest cybercrimes reported to the FBI, with billions in losses each year.
- Defense is layered. Effective protection combines email authentication (DMARC, SPF, DKIM), MFA, payment-verification controls, user training, and behavioral detection.
How a BEC attack works
BEC attacks are patient and methodical. A typical campaign follows a recognizable sequence:
- Reconnaissance. The attacker researches the target organization using public sources such as the company website, LinkedIn, and social media to identify key people, reporting lines, vendors, and payment processes.
- Access or impersonation. The attacker either spoofs a trusted email address or a lookalike domain, or compromises a real mailbox through phishing or stolen credentials. A compromised account is especially dangerous because the fraudulent email genuinely comes from a legitimate address.
- Social engineering. Using authority, urgency, and confidentiality, the attacker crafts a convincing request, sometimes inserting themselves into an existing email thread and mimicking the sender's tone and style.
- Execution. The victim acts on the request: wiring funds, changing vendor bank details, buying gift cards, or sharing sensitive data such as payroll or W-2 information.
- Exfiltration. Money moves quickly through intermediary and international accounts, often via money mules, making recovery difficult once the transfer clears.
When an attacker lurks inside a compromised mailbox, they may monitor communications for weeks, learning payment cycles and relationships before striking at the moment a large or routine payment is due.
The main types of BEC
The FBI defines five major categories, each exploiting a different point in an organization's workflow.
A closely related term is vendor email compromise (VEC), where attackers impersonate or take over a supplier's account to redirect legitimate B2B payments. Supplier-invoicing fraud is often cited as the variant producing the largest individual losses, because organizations routinely process vendor payments and may not scrutinize familiar invoices closely.
Why BEC is so hard to detect
BEC defeats many traditional controls precisely because it looks like ordinary business email:
- No malicious payload. With no malware, links, or attachments to scan, signature-based email filters have little to flag.
- Low volume. A campaign may consist of just one or two emails, so it doesn't create the traffic spike that triggers detection, and source addresses can be rotated easily.
- Legitimate or spoofed sources. Attackers use neutral-reputation IPs, spoofed domains, or genuinely compromised accounts, and may even pass DMARC checks when authentication is misconfigured or the mailbox is real.
- Human-centric. The attack targets a person's judgment under pressure, not a software weakness, so technical defenses alone can't fully close the gap.
The growing use of generative AI has made matters worse, helping attackers write more fluent, personalized messages in languages beyond English, and extending BEC into multi-channel scams that combine email with phone or video.
The scale and impact of BEC
BEC is one of the most financially damaging categories of cybercrime. In its 2024 Internet Crime Report, the FBI's Internet Crime Complaint Center (IC3) logged over 21,000 BEC complaints and close to 2.8 billion US dollars in reported losses, making BEC the second-costliest crime type it tracks. Cumulative reported losses run into the tens of billions of dollars over the past decade. Beyond direct theft, victims face knock-on costs: data-breach response, regulatory and legal exposure, damaged vendor and customer relationships, and operational disruption.
A notable characteristic is that BEC represents a small share of attack volume but an outsized share of financial impact, which is why it should be treated as a distinct risk rather than a subset of generic phishing.
How to prevent BEC
Because BEC blends technical and human elements, effective prevention is layered across both:
- Enforce email authentication. Correctly configured DMARC, SPF, and DKIM reduce domain spoofing. DMARC should be set to actively reject or quarantine unauthenticated mail, not just monitor.
- Require MFA. Phishing-resistant multi-factor authentication (MFA) limits account takeover, cutting off the most dangerous BEC variant at the source.
- Verify payments out of band. Confirm any new or changed payment instructions through a separate, known channel, a phone call to a verified number, never by replying to the email in question. Build this into finance and accounts-payable procedures.
- Train people continuously. Teach staff to recognize urgency, authority, and unusual requests, and to question them. Share real BEC examples, and make clear that managers and executives are not exempt from falling for these lures.
- Use behavioral email security. Modern tools apply machine learning and natural-language processing to analyze communication patterns, sender behavior, and email threads, catching anomalies that signature-based filters miss.
How to respond to a BEC incident
If a fraudulent transfer is suspected, speed is decisive. Contact the financial institution immediately to request a recall of funds, since some transfers can be frozen if reported fast enough. In the US, report the incident to the FBI's IC3, whose Financial Fraud Kill Chain has recovered misdirected funds in some cases.
In parallel, investigate scope through security and, where needed, legal counsel to determine whether a mailbox or system was compromised. Preserve evidence, meet any breach-notification obligations, and review applicable insurance coverage. Documenting the incident and sharing lessons internally helps harden the organization against the next attempt.
Expert insight: Catching what the email gateway misses
The most dangerous BEC cases produce no obvious technical signal at the email layer. A message from a genuinely compromised mailbox, with no link and no attachment, asking to update a vendor's bank details, is indistinguishable from legitimate business correspondence to a traditional filter. Preventive email controls, authentication, gateways, training, are essential, but they won't catch everything, so detection has to extend beyond the inbox.
BEC rarely happens in isolation. It's usually preceded or accompanied by signals elsewhere: a suspicious sign-in to a mailbox, a new inbox forwarding rule, anomalous OAuth grants, impossible-travel authentication, or unusual access to finance systems. Sekoia is a European cybersecurity vendor whose unified AI SOC platform correlates telemetry across email, identity, and cloud, backed by its in-house Threat Detection & Research (TDR) team's intelligence, so that the account-compromise activity behind many BEC attacks can be detected as it unfolds rather than discovered after the money has moved. Detections mapped to MITRE ATT&CK help analysts connect a mailbox anomaly to a wider intrusion.
Sekoia is not a secure email gateway and doesn't replace dedicated email-security and anti-fraud controls; those remain the front line against BEC. What a CTI-led SOC platform adds is the cross-surface visibility to catch the identity and account-takeover activity that pure email tools miss, and to respond before a fraudulent request becomes a completed transfer. As a European vendor with a data-sovereignty posture, Sekoia also suits organizations with European governance requirements.