Business email compromise, or BEC, is a targeted fraud in which an attacker poses as a trusted person and convinces an employee to move money or change payment details. The trusted person is usually an executive, a finance lead, or a supplier. Unlike mass phishing, BEC is patient and well prepared. It often carries no link, no attachment, and no malware at all. The attacker just sends a plausible message at the right moment to the right person, leaning on authority and a deadline. That is exactly why technical defenses struggle to catch it, and why BEC sits among the most financially damaging attacks a company can face.
For a regulated company in finance, healthcare, critical infrastructure, or SaaS, BEC is both a security problem and a compliance problem. A single fraudulent transfer can run into six or seven figures and is often unrecoverable. If the attacker also reads the mailbox before striking, customer and employee personal data is exposed, which turns the incident into a reportable breach under the GDPR. Frameworks such as the NIS2 Directive and ISO/IEC 27001:2022 expect you to control payment processes, manage access, and prove that you did. BEC tests all of those controls at once, and it does so by attacking the one layer no firewall protects: human trust.
BEC is a money-focused form of phishing and social engineering. The criminal does not need to break anything. They only need one person to follow an instruction without checking it. We measure how well your staff and your process resist that pressure through security awareness training and simulated attacks.
Why BEC is so financially damaging
Most cyber attacks try to break in. BEC tries to be invited in. It abuses a process that is supposed to work: someone with authority asks for a payment, and the company pays. Because the request looks legitimate and arrives through a normal channel, the money usually moves before anyone is suspicious. By the time the fraud is noticed, the funds have often been pulled out of the receiving account and split across other accounts, frequently in another country.
The losses are large because BEC targets the payments themselves, not the infrastructure around them. A ransomware crew has to encrypt systems and then negotiate. A BEC actor just redirects a wire transfer that the company was already going to make. There is no ransom to haggle over and no decryption to wait for. The attacker simply receives the money that should have gone to a supplier or a salary account.1
BEC also scales cheaply for the attacker. The reconnaissance is mostly free, drawn from public sources, and a single successful invoice fraud can return more than a whole campaign of mass phishing. That economics keeps BEC at the top of the threat landscape year after year, and it is why finance, payroll, and procurement teams are the people most worth protecting.
How a BEC attack unfolds
A BEC attack is a sequence, not a single email. Understanding the sequence is what lets you break it. The attacker either compromises a real mailbox or spoofs a trusted identity, studies how the company pays, waits for the right moment, and then sends one carefully timed instruction.
- 01Gain a foothold or build a lookalikeThe attacker either takes over a real account through phishing or a stolen password, or registers a domain and address that closely resembles a genuine one. A compromised mailbox is the more dangerous case, because messages come from the real address and pass every authenticity check.
- 02ReconnaissanceFrom inside a mailbox or from public sources, the attacker learns who approves payments, who the suppliers are, what invoices are due, and how the company phrases its emails. They watch for an executive who is travelling or a payment that is already expected.
- 03Craft the requestThe attacker sends a fake payment order or a request to change bank details. The message leans on authority, urgency, and confidentiality, often asking the victim not to discuss it with anyone, which removes the natural check of a second opinion.
- 04Move and launder the moneyThe victim sends the transfer to an account the attacker controls. The funds are withdrawn or forwarded within hours, which is why fast action with the bank is the only reliable way to recover anything.
Notice that only the first step involves anything technical, and even that is often just a stolen password. The rest of the attack is conversation, timing, and trust. That is the heart of why BEC defeats tools that look for malicious code.
The main types of BEC fraud
BEC takes several recognizable forms. They share the same playbook, impersonate a trusted party and request a payment or a change, but they target different people and different transactions. Recognizing the type helps a finance team know which verification step matters most.2
| Type | How it works | Usual target |
|---|---|---|
| CEO or executive fraud | A message that appears to come from a senior executive demands an urgent, confidential transfer, often while the executive is hard to reach. | Finance staff who will not question authority |
| Fake supplier or invoice fraud | The attacker poses as a known supplier and asks to update the bank details on file, so the next legitimate invoice is paid to the wrong account. | Accounts payable and procurement |
| Account compromise | The attacker uses a genuine, hijacked internal mailbox to send requests, so nothing about the sender looks wrong. | Anyone who trusts the compromised colleague |
| Payroll diversion | A request, supposedly from an employee, asks HR to change the bank account where their salary is paid. | HR and payroll teams |
| Attorney or legal impersonation | The attacker poses as a lawyer or adviser handling a confidential, time-sensitive matter such as an acquisition, pressuring quick payment in secret. | Executives and finance leads |
Account compromise is the most dangerous of these, because the email is genuinely from the right person's address. It is also the bridge to identity theft, where a stolen corporate login becomes the foothold for fraud, lateral movement, and further attacks.
Why technical filters miss BEC
Email security tools are built to find threats in content. They scan attachments for malware, follow links to known bad sites, and score messages on reputation. BEC carries none of those signals. A request to change a bank account number is just text. It contains no exploit, no payload, and often no link, so a filter that is hunting for malicious files sees nothing to block.
When the attacker uses a compromised internal mailbox, the problem is worse. The message passes SPF, DKIM, and DMARC because it really is from your domain. It comes from a real colleague, in a real thread, often quoting real context the attacker read in the inbox. No anomaly detection fires, because technically nothing is anomalous. Someone simply sent an email and someone else acted on it.
Building a layered defense
Because BEC attacks people and process, the defense has to live in process, supported by technology. No single control stops it. A layered approach assumes any one layer can be bypassed and makes sure another catches the fraud before the money leaves.
- Require dual approval for any payment or change of bank details above a defined threshold, so no single person can release funds alone.
- Verify every change of payment details out of band, by calling a known phone number you already hold on file, never the number written in the email.
- Deploy DMARC with SPF and DKIM so attackers cannot easily spoof your own domain, and set the policy to reject rather than just monitor.
- Turn on multi-factor authentication for email and finance systems to block the account takeover that powers the most dangerous BEC.
- Run regular awareness training and phishing simulations so finance, HR, and procurement staff learn to read urgency and secrecy as warning signs.
- Apply least privilege so a single compromised mailbox cannot read or approve more than its owner genuinely needs.
The non-negotiable control is out-of-band verification. If your team confirms every payment change by voice on a trusted number, the attacker's entire script collapses, because the one channel they control is the email. DMARC and MFA shrink the attack surface, but the verified phone call is what stops the loss.
BEC is defeated by a phone call, not a firewall.
What to do if it happens
A payment that has already been sent is not always lost. Recovery depends almost entirely on speed, because the attacker moves the money within hours. Treat any suspected BEC as a live incident from the first minute, not as an internal embarrassment to handle quietly.
- 01Call the bank immediatelyAsk the bank to attempt a recall or freeze on the transfer. If you act within hours, the funds can sometimes be stopped before they are withdrawn or forwarded.
- 02Report to the authoritiesNotify law enforcement and any national fraud reporting body. Fast reporting improves the chance that the receiving account can be frozen across borders.
- 03Preserve the evidenceKeep the original emails with full headers, the payment records, and any account access logs. Do not delete anything, even the fraudulent message.
- 04Start your incident response planTrigger your incident response plan, check whether a mailbox was compromised, reset credentials, and assess whether personal data was exposed and a GDPR breach notification is required.
If the investigation shows an attacker had access to a mailbox, treat it as an account compromise and a possible data breach, not just a failed payment. The same access that enabled the fraud may have exposed personal data, and the related rise of deepfake fraud means a follow-up voice or video request should also be verified, never trusted on its face.
The link to phishing and awareness
BEC and phishing are two ends of the same craft. Phishing is the broad, automated front that often delivers the stolen password an attacker uses to take over a mailbox. BEC is the precise, hand-built follow-through that turns that access into money. The defense for both rests on the same foundation: a workforce that pauses, questions, and verifies, especially when a message creates pressure to act fast and in secret.
Awareness is not a poster on the wall. It is measurable. By simulating realistic supplier and executive impersonation against your own teams, you find out who acts on a fake instruction and who picks up the phone first. That evidence tells you where to tighten the process and turns abstract training into a control you can show an auditor under NIS2 or ISO/IEC 27001.
How Raptoric helps
Raptoric runs security awareness training and simulated social engineering that mirror real BEC attacks against your finance, HR, and procurement teams. We measure who verifies and who pays, then give you concrete fixes for both the human and the process side, from dual-approval thresholds to out-of-band verification rules. As an independent, vendor-neutral firm, we have no product to sell you behind the advice. Book a scoping call.
