Offensive SecurityJun 16, 2026 · 10 min read

Business email compromise (BEC): how to spot it and stop it

Business email compromise is among the costliest attacks there is. An attacker poses as an executive or supplier and asks for a payment. See how to stop it.
A finance specialist verifying a payment request by phone while reading email on a computer.

Business email compromise, or BEC, is a targeted fraud in which an attacker poses as a trusted person and convinces an employee to move money or change payment details. The trusted person is usually an executive, a finance lead, or a supplier. Unlike mass phishing, BEC is patient and well prepared. It often carries no link, no attachment, and no malware at all. The attacker just sends a plausible message at the right moment to the right person, leaning on authority and a deadline. That is exactly why technical defenses struggle to catch it, and why BEC sits among the most financially damaging attacks a company can face.

For a regulated company in finance, healthcare, critical infrastructure, or SaaS, BEC is both a security problem and a compliance problem. A single fraudulent transfer can run into six or seven figures and is often unrecoverable. If the attacker also reads the mailbox before striking, customer and employee personal data is exposed, which turns the incident into a reportable breach under the GDPR. Frameworks such as the NIS2 Directive and ISO/IEC 27001:2022 expect you to control payment processes, manage access, and prove that you did. BEC tests all of those controls at once, and it does so by attacking the one layer no firewall protects: human trust.

BEC is a money-focused form of phishing and social engineering. The criminal does not need to break anything. They only need one person to follow an instruction without checking it. We measure how well your staff and your process resist that pressure through security awareness training and simulated attacks.

Why BEC is so financially damaging

Most cyber attacks try to break in. BEC tries to be invited in. It abuses a process that is supposed to work: someone with authority asks for a payment, and the company pays. Because the request looks legitimate and arrives through a normal channel, the money usually moves before anyone is suspicious. By the time the fraud is noticed, the funds have often been pulled out of the receiving account and split across other accounts, frequently in another country.

The losses are large because BEC targets the payments themselves, not the infrastructure around them. A ransomware crew has to encrypt systems and then negotiate. A BEC actor just redirects a wire transfer that the company was already going to make. There is no ransom to haggle over and no decryption to wait for. The attacker simply receives the money that should have gone to a supplier or a salary account.1

BEC also scales cheaply for the attacker. The reconnaissance is mostly free, drawn from public sources, and a single successful invoice fraud can return more than a whole campaign of mass phishing. That economics keeps BEC at the top of the threat landscape year after year, and it is why finance, payroll, and procurement teams are the people most worth protecting.

How a BEC attack unfolds

A BEC attack is a sequence, not a single email. Understanding the sequence is what lets you break it. The attacker either compromises a real mailbox or spoofs a trusted identity, studies how the company pays, waits for the right moment, and then sends one carefully timed instruction.

  1. 01
    Gain a foothold or build a lookalike
    The attacker either takes over a real account through phishing or a stolen password, or registers a domain and address that closely resembles a genuine one. A compromised mailbox is the more dangerous case, because messages come from the real address and pass every authenticity check.
  2. 02
    Reconnaissance
    From inside a mailbox or from public sources, the attacker learns who approves payments, who the suppliers are, what invoices are due, and how the company phrases its emails. They watch for an executive who is travelling or a payment that is already expected.
  3. 03
    Craft the request
    The attacker sends a fake payment order or a request to change bank details. The message leans on authority, urgency, and confidentiality, often asking the victim not to discuss it with anyone, which removes the natural check of a second opinion.
  4. 04
    Move and launder the money
    The victim sends the transfer to an account the attacker controls. The funds are withdrawn or forwarded within hours, which is why fast action with the bank is the only reliable way to recover anything.

Notice that only the first step involves anything technical, and even that is often just a stolen password. The rest of the attack is conversation, timing, and trust. That is the heart of why BEC defeats tools that look for malicious code.

The main types of BEC fraud

BEC takes several recognizable forms. They share the same playbook, impersonate a trusted party and request a payment or a change, but they target different people and different transactions. Recognizing the type helps a finance team know which verification step matters most.2

TypeHow it worksUsual target
CEO or executive fraudA message that appears to come from a senior executive demands an urgent, confidential transfer, often while the executive is hard to reach.Finance staff who will not question authority
Fake supplier or invoice fraudThe attacker poses as a known supplier and asks to update the bank details on file, so the next legitimate invoice is paid to the wrong account.Accounts payable and procurement
Account compromiseThe attacker uses a genuine, hijacked internal mailbox to send requests, so nothing about the sender looks wrong.Anyone who trusts the compromised colleague
Payroll diversionA request, supposedly from an employee, asks HR to change the bank account where their salary is paid.HR and payroll teams
Attorney or legal impersonationThe attacker poses as a lawyer or adviser handling a confidential, time-sensitive matter such as an acquisition, pressuring quick payment in secret.Executives and finance leads
The most common forms of business email compromise and who they target.

Account compromise is the most dangerous of these, because the email is genuinely from the right person's address. It is also the bridge to identity theft, where a stolen corporate login becomes the foothold for fraud, lateral movement, and further attacks.

Why technical filters miss BEC

Email security tools are built to find threats in content. They scan attachments for malware, follow links to known bad sites, and score messages on reputation. BEC carries none of those signals. A request to change a bank account number is just text. It contains no exploit, no payload, and often no link, so a filter that is hunting for malicious files sees nothing to block.

When the attacker uses a compromised internal mailbox, the problem is worse. The message passes SPF, DKIM, and DMARC because it really is from your domain. It comes from a real colleague, in a real thread, often quoting real context the attacker read in the inbox. No anomaly detection fires, because technically nothing is anomalous. Someone simply sent an email and someone else acted on it.

Building a layered defense

Because BEC attacks people and process, the defense has to live in process, supported by technology. No single control stops it. A layered approach assumes any one layer can be bypassed and makes sure another catches the fraud before the money leaves.

  • Require dual approval for any payment or change of bank details above a defined threshold, so no single person can release funds alone.
  • Verify every change of payment details out of band, by calling a known phone number you already hold on file, never the number written in the email.
  • Deploy DMARC with SPF and DKIM so attackers cannot easily spoof your own domain, and set the policy to reject rather than just monitor.
  • Turn on multi-factor authentication for email and finance systems to block the account takeover that powers the most dangerous BEC.
  • Run regular awareness training and phishing simulations so finance, HR, and procurement staff learn to read urgency and secrecy as warning signs.
  • Apply least privilege so a single compromised mailbox cannot read or approve more than its owner genuinely needs.

The non-negotiable control is out-of-band verification. If your team confirms every payment change by voice on a trusted number, the attacker's entire script collapses, because the one channel they control is the email. DMARC and MFA shrink the attack surface, but the verified phone call is what stops the loss.

BEC is defeated by a phone call, not a firewall.

What to do if it happens

A payment that has already been sent is not always lost. Recovery depends almost entirely on speed, because the attacker moves the money within hours. Treat any suspected BEC as a live incident from the first minute, not as an internal embarrassment to handle quietly.

  1. 01
    Call the bank immediately
    Ask the bank to attempt a recall or freeze on the transfer. If you act within hours, the funds can sometimes be stopped before they are withdrawn or forwarded.
  2. 02
    Report to the authorities
    Notify law enforcement and any national fraud reporting body. Fast reporting improves the chance that the receiving account can be frozen across borders.
  3. 03
    Preserve the evidence
    Keep the original emails with full headers, the payment records, and any account access logs. Do not delete anything, even the fraudulent message.
  4. 04
    Start your incident response plan
    Trigger your incident response plan, check whether a mailbox was compromised, reset credentials, and assess whether personal data was exposed and a GDPR breach notification is required.

If the investigation shows an attacker had access to a mailbox, treat it as an account compromise and a possible data breach, not just a failed payment. The same access that enabled the fraud may have exposed personal data, and the related rise of deepfake fraud means a follow-up voice or video request should also be verified, never trusted on its face.

BEC and phishing are two ends of the same craft. Phishing is the broad, automated front that often delivers the stolen password an attacker uses to take over a mailbox. BEC is the precise, hand-built follow-through that turns that access into money. The defense for both rests on the same foundation: a workforce that pauses, questions, and verifies, especially when a message creates pressure to act fast and in secret.

Awareness is not a poster on the wall. It is measurable. By simulating realistic supplier and executive impersonation against your own teams, you find out who acts on a fake instruction and who picks up the phone first. That evidence tells you where to tighten the process and turns abstract training into a control you can show an auditor under NIS2 or ISO/IEC 27001.

How Raptoric helps

Raptoric runs security awareness training and simulated social engineering that mirror real BEC attacks against your finance, HR, and procurement teams. We measure who verifies and who pays, then give you concrete fixes for both the human and the process side, from dual-approval thresholds to out-of-band verification rules. As an independent, vendor-neutral firm, we have no product to sell you behind the advice. Book a scoping call.

Frequently asked questions

How is BEC different from ordinary phishing?
Ordinary phishing is mass-scale and usually relies on a malicious link or attachment. BEC is targeted, carefully researched, and often carries no link or malware at all. It impersonates a specific executive or supplier and asks for a payment, relying on authority and urgency rather than technique, which is why email filters frequently miss it.
Why do email security filters fail to stop BEC?
Filters scan for malware, bad links, and sender reputation. A BEC message is plain text with no payload, so there is nothing for the filter to block. When the attacker uses a hijacked internal mailbox, the email passes SPF, DKIM, and DMARC because it genuinely comes from your domain, so no technical alarm fires at all.
What is the single most effective control against BEC?
Out-of-band verification. Confirm every payment and every change of bank details by calling a phone number you already hold on file, never the number in the email. Because the attacker only controls the email channel, a verified call on a trusted number breaks their script and stops the loss before the money leaves.
Does multi-factor authentication help against BEC?
Yes, especially against account takeover. MFA on email and finance systems stops an attacker from using a stolen password to log in and send fraudulent requests from a genuine internal mailbox. That account compromise is the most dangerous form of BEC, so MFA removes one of the attacker's strongest routes in.
What should we do if the payment has already been sent?
Act within hours. Call the bank immediately to request a recall or freeze, report the fraud to law enforcement, and preserve the original emails and payment records as evidence. Then trigger your incident response plan, check whether a mailbox was compromised, and assess whether a GDPR breach notification is required.
How do DMARC, SPF, and DKIM reduce BEC risk?
These email authentication standards make it much harder for an attacker to spoof your own domain. SPF and DKIM verify that a message really came from an authorised server, and a DMARC policy set to reject blocks lookalike messages claiming to be from you. They do not stop a compromised genuine mailbox, so they work alongside verification and MFA, not instead of them.

Sources

  1. 1ENISA. ENISA Threat Landscape. European Union Agency for Cybersecurity, 2024. Link
  2. 2CISA. Avoiding Social Engineering and Phishing Attacks. Cybersecurity and Infrastructure Security Agency, 2021. Link
Related service
Offensive Security
Want this tested on your own systems?
Our team will scope it with you on a 30-minute call.
Book a scoping call