Business Email Compromise (BEC)

How BEC attacks work

BEC follows a consistent pattern. The attacker researches the target organisation, often using LinkedIn, company websites, and public filings to identify who authorises payments and who processes them. Then they impersonate a trusted authority figure through one of these methods:

  • Email spoofing – forging the sender address to match a known executive or supplier. The email appears to come from the CEO’s address but originates from the attacker’s server
  • Compromised account – gaining actual access to a legitimate email account through credential theft or password spraying. Messages sent from a real account are harder to detect
  • Lookalike domains – registering a domain visually similar to the target, for example (cyberf0rt.com instead of cyberfort.com) to send emails that pass a quick visual check
  • Thread hijacking – intercepting an existing email conversation between a company and its supplier, then inserting altered payment details mid-thread

The five types of BEC (FBI classification)

The FBI categorises BEC into five variants:

1. CEO fraud – impersonating the CEO or senior executive to request an urgent wire transfer, often to a finance team member. Pressure and urgency are the key tactics.

2. Invoice fraud – impersonating a supplier and sending a legitimate-looking invoice with altered bank details. Often timed to coincide with known payment cycles.

3. Account compromise – an employee’s actual email account is compromised and used to request payments from suppliers or customers in their contact list.

4. Attorney impersonation – pretending to be a lawyer or legal representative handling a confidential matter, using urgency and secrecy to prevent verification.

5. Data theft – targeting HR or payroll to obtain employee personal information, tax records, or W-2/P60 data for identity fraud.

Why BEC bypasses email security

Most email security solutions scan for malicious links, attachments, and known phishing patterns. BEC emails typically contain none of these. They are plain text messages from apparently legitimate senders making reasonable sounding requests. There is nothing for a URL filter or malware scanner to catch.

This is why BEC is fundamentally a people and process problem, not a technology problem. The defence must match the attack. It needs to target human decision-making, not just email headers.

Defending against BEC

Effective BEC defence combines email authentication, process controls, and awareness training:

  • DMARC, SPF, and DKIM – email authentication protocols that prevent domain spoofing. DMARC with a reject policy stops attackers sending email that appears to come from your domain. These are technical controls that should be in place on every business domain
  • Payment verification processes – any change to payment details or any new payment instruction above a threshold requires verbal confirmation via a known phone number (not one provided in the email). This single control prevents the majority of successful BEC attacks
  • Multi-person approval – large payments require approval from at least two authorised individuals, with one confirming through a separate channel
  • Email banners – flag emails originating from outside the organisation with a visible warning. Many BEC attacks impersonate internal executives, and an ‘external sender’ banner prompts scrutiny
  • Awareness training – finance, HR, and legal teams trained specifically on BEC scenarios. Generic phishing training is not sufficient. BEC training must cover urgency tactics, authority exploitation, and the specific scenarios above

BEC and deepfakes

BEC is evolving. Attackers now combine email-based BEC with deepfake voice or video to add a verbal confirmation layer. An employee receiving a suspicious email might call the ‘CEO’ to verify, and hear a cloned voice confirming the request. This convergence of BEC and deepfakes makes multi-channel verification (calling a known number, not one provided in the email) even more critical.

Cyberfort and BEC

We help organisations test and strengthen their BEC defences. Our crisis simulation exercises include BEC scenarios – replicating realistic CEO fraud and invoice redirection attacks against your finance team to identify process gaps before real attackers exploit them. Our cyber resilience audit assesses your email authentication (DMARC/SPF/DKIM), payment verification processes, and employee awareness against BEC-specific risks. Assess your BEC readiness →

Related glossary terms

  • Deepfakes in Cybersecurity – AI-generated voice and video now used to enhance BEC attacks with verbal impersonation
  • Cyber Crisis Simulation – exercises that include BEC attack scenarios to test organisational response
  • Zero Trust – the security principle that no request should be trusted based on a single factor, directly applicable to payment verification
  • NCSC CAF – the UK framework for assessing organisational security maturity, including social engineering resilience

External references

Frequently asked questions

What is the difference between phishing and BEC?

Phishing casts a wide net. Mass emails with malicious links or attachments sent to thousands of targets. BEC is targeted and personalised. The attacker researches the specific organisation, impersonates a known individual, and makes a credible request that contains no malicious payload. A phishing email asks you to click a link. A BEC email asks you to transfer £50,000 to a new supplier account.

How much do BEC attacks cost?

The FBI’s IC3 2024 Annual Report recorded $2.77 billion in BEC losses from 21,442 reported cases in the US alone, bringing the three-year total to nearly $8.5 billion (2022–2024). The average loss per BEC attack is now around $125,600, a 300% increase since 2015. BEC remains one of the most financially damaging cybercrime categories because each attack is targeted for maximum financial impact rather than volume.

Can email security tools stop BEC?

Email security tools catch spoofed domains (via DMARC/SPF/DKIM) and known malicious patterns, but they cannot reliably detect a well-crafted BEC email sent from a compromised legitimate account with no links or attachments. BEC defence requires a combination of email authentication, payment verification processes, and targeted employee training.

Awards and Accreditations

blue light commercial logo

Contact Us

Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX

+44 (0)1304 814800

[email protected]


Cyberfort
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.