Business Email Compromise (BEC)
BEC attacks cost businesses billions annually through fraudulent wire transfers. Learn how to recognize and prevent invoice and payment fraud.
What You Need to Know
Business Email Compromise (BEC) targets businesses by impersonating executives, vendors, or partners to trick employees into transferring money or sensitive data. The FBI reports BEC as one of the most financially damaging cybercrimes.
Unlike ransomware or malware, BEC relies on social engineering. Criminals exploit trust, authority, and routine business processes. Attacks are often well-researched and timed for maximum effectiveness.
How BEC Attacks Work
1Account Compromise or Impersonation
Criminals either hack into legitimate business email accounts through phishing/credential theft, or create lookalike email addresses that impersonate executives or vendors.
2Reconnaissance
Attackers monitor compromised accounts to learn about business operations, relationships, communication styles, and upcoming transactions. This allows highly tailored attacks.
3Timing the Attack
Attacks are timed for maximum effectiveness—when executives are traveling, when large invoices are due, or when time zones create communication delays.
4Sending the Request
Fraudulent emails request wire transfers, payment detail changes, or sensitive information. They match normal business operations and appear to come from trusted sources.
5Receiving the Funds
Money is wired to attacker-controlled accounts, often overseas. Funds are quickly moved through multiple accounts to prevent recovery.
Warning Signs to Watch For
Urgent requests for wire transfers from executives
Emails claiming to be from the CEO requesting immediate, confidential wire transfers.
Vendor payment detail changes
Requests to update bank account information for invoice payments.
Unusual timing or communication style
Emails sent outside normal hours or with different tone/language than usual.
Requests for secrecy
Instructions to keep the request confidential or not discuss with others.
Pressure to bypass normal procedures
Claims of special circumstances requiring immediate action without normal approvals.
Slightly altered email addresses
Addresses that look legitimate but have subtle differences (ceo@cornpany.com vs ceo@company.com).
Requests for employee W-2 or personal data
Emails asking HR to send all employee tax records or sensitive information.
Psychological Tactics Used
Authority
Impersonating CEOs, CFOs, or other executives whose instructions employees are conditioned to follow without question.
Urgency
Creating time pressure that discourages verification: 'I need this done before the close of business today.'
Secrecy
Requesting confidentiality ('Don't mention this to anyone') isolates targets from the colleagues who might spot the fraud.
Trust in Relationships
Leveraging established vendor relationships and ongoing invoice streams to make fraudulent requests seem routine.
Who Is Most at Risk
- Businesses that conduct wire transfers
- Companies working with international vendors
- Organizations with public information about executives
- Finance and accounts payable employees
- HR departments with access to employee data
- Companies without dual approval requirements for payments
- Businesses lacking security awareness training
Real-World Scenario
The Vendor Invoice Scam
$340,000 lost to invoice fraudA construction company received an email appearing to be from a regular supplier, informing them that the vendor had changed banks and providing new wire transfer details. The email came from an address nearly identical to the real vendor's. The company paid $340,000 to the new account. When the real vendor inquired about the overdue payment, the company discovered the fraud. The money had already been transferred overseas.
Red Flags Present:
- Request to change payment details via email
- Slightly altered sender email address
- No phone verification of banking change
- Large payment without dual approval
- No independent confirmation with vendor
How to Protect Your Business
Verify Payment Changes by Phone
Always confirm banking detail changes by calling a known number for the vendor—not a number provided in the email.
Implement Dual Authorization
Require two people to approve wire transfers or payments above a certain threshold.
Enable Multi-Factor Authentication
Protect all email accounts with MFA to prevent unauthorized access.
Train Employees Regularly
Conduct ongoing security awareness training focused on BEC tactics and verification procedures.
Verify New Vendor Setup
Confirm new vendor details through independent research, not information provided by the vendor.
Scrutinize Urgent Executive Requests
Establish protocols for verifying unusual requests from executives, especially for wire transfers.
What to Do If You've Been Affected
Contact Your Bank Immediately
Request a wire recall. Time is critical—notify your bank within 24-48 hours for the best chance of recovery.
File an FBI IC3 Complaint
Report to the FBI's Internet Crime Complaint Center at ic3.gov. The FBI's Recovery Asset Team works with banks to freeze funds.
Notify Your IT/Security Team
Determine if email accounts were compromised. Change passwords, enable MFA, and investigate the intrusion.
Preserve Evidence
Save all emails, headers, and communications related to the fraud for law enforcement investigation.
Notify Affected Parties
If employee data was compromised, notify affected employees and consider credit monitoring.
Review and Strengthen Procedures
Analyze how the attack succeeded and implement additional controls to prevent recurrence.
Frequently Asked Questions
Protect Your Investments
Download our free Investor Protection Guide with actionable steps to verify companies and avoid scams.