Last updated · first published · reviewed by the Smart Money Verified Team

Business Email Compromise (BEC)

BEC attacks cost businesses billions annually through fraudulent wire transfers. Learn how to recognize and prevent invoice and payment fraud.

What You Need to Know

Business Email Compromise (BEC) targets businesses by impersonating executives, vendors, or partners to trick employees into transferring money or sensitive data. The FBI reports BEC as one of the most financially damaging cybercrimes.

Unlike ransomware or malware, BEC relies on social engineering. Criminals exploit trust, authority, and routine business processes. Attacks are often well-researched and timed for maximum effectiveness.

How do BEC attacks work?

1Account Compromise or Impersonation

Criminals either hack into legitimate business email accounts through phishing/credential theft, or create lookalike email addresses that impersonate executives or vendors.

2Reconnaissance

Attackers monitor compromised accounts to learn about business operations, relationships, communication styles, and upcoming transactions. This allows highly tailored attacks.

3Timing the Attack

Attacks are timed for maximum effectiveness—when executives are traveling, when large invoices are due, or when time zones create communication delays.

4Sending the Request

Fraudulent emails request wire transfers, payment detail changes, or sensitive information. They match normal business operations and appear to come from trusted sources.

5Receiving the Funds

Money is wired to attacker-controlled accounts, often overseas. Funds are quickly moved through multiple accounts to prevent recovery.

What warning signs should I watch for?

Urgent requests for wire transfers from executives

Emails claiming to be from the CEO requesting immediate, confidential wire transfers.

Vendor payment detail changes

Requests to update bank account information for invoice payments.

Unusual timing or communication style

Emails sent outside normal hours or with different tone/language than usual.

Requests for secrecy

Instructions to keep the request confidential or not discuss with others.

Pressure to bypass normal procedures

Claims of special circumstances requiring immediate action without normal approvals.

Slightly altered email addresses

Addresses that look legitimate but have subtle differences (ceo@cornpany.com vs ceo@company.com).

Requests for employee W-2 or personal data

Emails asking HR to send all employee tax records or sensitive information.

What psychological tactics do scammers use?

Authority

Impersonating CEOs, CFOs, or other executives whose instructions employees are conditioned to follow without question.

Urgency

Creating time pressure that discourages verification: 'I need this done before the close of business today.'

Secrecy

Requesting confidentiality ('Don't mention this to anyone') isolates targets from the colleagues who might spot the fraud.

Trust in Relationships

Leveraging established vendor relationships and ongoing invoice streams to make fraudulent requests seem routine.

Who is most at risk?

  • Businesses that conduct wire transfers
  • Companies working with international vendors
  • Organizations with public information about executives
  • Finance and accounts payable employees
  • HR departments with access to employee data
  • Companies without dual approval requirements for payments
  • Businesses lacking security awareness training

What does a real-world scenario look like?

The Vendor Invoice Scam

$340,000 lost to invoice fraud

A construction company received an email appearing to be from a regular supplier, informing them that the vendor had changed banks and providing new wire transfer details. The email came from an address nearly identical to the real vendor's. The company paid $340,000 to the new account. When the real vendor inquired about the overdue payment, the company discovered the fraud. The money had already been transferred overseas.

Red Flags Present:

  • Request to change payment details via email
  • Slightly altered sender email address
  • No phone verification of banking change
  • Large payment without dual approval
  • No independent confirmation with vendor

How can I protect my business?

Verify Payment Changes by Phone

Always confirm banking detail changes by calling a known number for the vendor—not a number provided in the email.

Implement Dual Authorization

Require two people to approve wire transfers or payments above a certain threshold.

Enable Multi-Factor Authentication

Protect all email accounts with MFA to prevent unauthorized access.

Train Employees Regularly

Conduct ongoing security awareness training focused on BEC tactics and verification procedures.

Verify New Vendor Setup

Confirm new vendor details through independent research, not information provided by the vendor.

Scrutinize Urgent Executive Requests

Establish protocols for verifying unusual requests from executives, especially for wire transfers.

What should I do if I've been affected?

1

Contact Your Bank Immediately

Request a wire recall. Time is critical—notify your bank within 24-48 hours for the best chance of recovery.

2

File an FBI IC3 Complaint

Report to the FBI's Internet Crime Complaint Center at ic3.gov. The FBI's Recovery Asset Team works with banks to freeze funds.

3

Notify Your IT/Security Team

Determine if email accounts were compromised. Change passwords, enable MFA, and investigate the intrusion.

4

Preserve Evidence

Save all emails, headers, and communications related to the fraud for law enforcement investigation.

5

Notify Affected Parties

If employee data was compromised, notify affected employees and consider credit monitoring.

6

Review and Strengthen Procedures

Analyze how the attack succeeded and implement additional controls to prevent recurrence.

What to do next

Payment instructions that arrive by email deserve a call back on a known number, plus a records check on any unfamiliar company named in the thread.

Frequently Asked Questions

BEC is a sophisticated scam targeting businesses that conduct wire transfers or work with vendors. Criminals compromise or impersonate business email accounts to trick employees into transferring money or sensitive data. The FBI reports billions lost annually to BEC attacks.

Criminals gain access through phishing attacks that steal credentials, malware that captures passwords, or by purchasing compromised credentials on the dark web. Sometimes they don't compromise accounts but create similar-looking email addresses to impersonate executives or vendors.

Common scenarios include: CEO fraud (impersonating executives requesting urgent wire transfers), vendor impersonation (changing payment details on legitimate invoices), W-2 scams (requesting employee tax records), and lawyer impersonation (fake attorney requesting confidential transfers).

BEC attacks use social engineering rather than technical exploits. They leverage trust, authority, and urgency. Emails appear to come from known contacts, requests align with normal business operations, and urgency discourages verification.

Contact your bank immediately to attempt to recall the wire transfer. File a complaint with the FBI IC3. The FBI's Recovery Asset Team may be able to freeze and recover funds if notified quickly—typically within 24-48 hours of the transfer.

Protect Your Investments

Download our free Investor Protection Guide with actionable steps to verify companies and avoid scams.

I agree to receive recurring automated text messages at the phone number provided. Consent is not a condition to purchase. Msg & data rates may apply. Reply HELP/STOP. Terms & Privacy.

Your information is secure and never sold

How do you check a company or person right now?

Use the free check on this site. Enter the name and it searches the official registers for you in one step, then shows you what those records say — registration status and anything reported against them. Every answer names the official source behind it, so you can confirm it yourself if you want to.

Who writes these guides

Written and reviewed by the Smart Money Verified Team. We build every guide from primary regulator material, we take no payment from any company we write about, and we say plainly when public records cannot answer a question. Our guides are education, not financial advice.

How we check things: our methodology · disclosures