Business email compromise (BEC)

Business email compromise is a targeted fraud in which an attacker impersonates an executive, a colleague or a supplier to redirect a payment or extract sensitive data. It typically contains no link, no attachment and no malicious code at all - which is exactly why it gets delivered.

Why BEC defeats technical controls

Most email security works by finding something bad in the message: a known-malicious URL, a suspicious attachment, a script. A BEC message contains none of those. It is a short, plausible, well-written note asking a colleague to update some bank details or push a payment through before end of day.

There is nothing for a scanner to detect, because nothing in the message is technically wrong. The fraud lives entirely in the meaning of the words and the identity of the sender, and both of those are judgement calls a filter cannot make. That is the whole reason BEC produces disproportionate financial losses relative to how few messages are sent.

The common variants

VariantWho is impersonatedWhat is asked for
CEO fraudA senior executiveAn urgent, confidential transfer, often while they are travelling
Invoice or mandate fraudA real supplierA change of bank details on a genuine outstanding invoice
Vendor email compromiseNobody - the real supplier account is usedA reply in an existing thread with new payment details
Payroll diversionAn employee, to HRA change of salary destination account
Attorney impersonationA lawyer handling a confidential matterSecrecy plus urgency around a transfer
Gift card scamA managerVouchers bought and codes photographed - the low-value entry version

The pattern across all six is identical: an authority figure, a payment, a deadline, and a reason not to check. Where the message is hand-written for one target using real research, it is also spear phishing - the two labels describe the same message from different angles.

What actually stops it

Because the message is not technically detectable, the control has to sit in the payment process rather than in the mail flow.

  1. Make verification mandatory and boring. Any change of bank details is confirmed by calling a number already on file - never a number from the message, and never by replying to the thread. Two minutes closes most of this category.
  2. Require two people for payments above a threshold, so no single compromised or pressured individual can complete one.
  3. Remove urgency as an override. Staff must know that no genuine executive request is damaged by a five-minute verification, and that acting fast is never the priority.
  4. Tag external mail, so a message claiming to be internal is visibly not.
  5. Enforce DMARC at reject to end exact-domain spoofing, while accepting it does nothing against lookalike domains or a compromised supplier.
  6. Monitor mailboxes for new forwarding rules, which is how an attacker quietly reads an invoice thread before joining it.
  7. Deploy phishing-resistant sign-in for finance and executives, since account takeover is the entry point for the most damaging variant.

If a payment has already gone out, contact the bank immediately and ask for a recall - the first few hours are the only realistic window. The surrounding control set is in how to prevent phishing.

Next step

Ready to measure your phishing and training program?

Book a demo and see how PhishGun can support your simulation and training program, reporting needs, and compliance evidence.