Skip to content

Fraud

Business Email Compromise (BEC): What It Is, How BEC Scams Work, and Real-World Examples

Kajal Bhardwaj

Brand ManagerSep 22, 2026Updated Sep 23, 202616 min read

Business Email Compromise

Business email compromise is an online scam in which criminals impersonate executives, vendors, or trusted partners to convince employees to transfer funds, share sensitive information, or change payment details. The FBI's 2025 Internet Crime Complaint Centre (IC3) report recorded $3.046 billion in business email compromise (BEC) losses in a single year, making BEC one of the most expensive forms of cyber-enabled fraud.

Unlike traditional phishing attacks, BEC contains no malicious links or attachments. Fraudsters commit this fraud by misusing victims' trust, performing compromised activities, and using misleading social engineering to succeed. This guide explains what business email compromise is, how BEC attacks work, common scam types, real-world examples, and the steps organisations can take to reduce their risk.

What Is Business Email Compromise (BEC)?

BEC, or business email compromise, is an evolved and targeted fraud approach in which a criminal poses as an executive, a vendor, legal counsel, or another trusted party in order to convince an employee to authorise a payment, change banking details, or hand over sensitive data. Unlike other cybercrime patterns, BEC does not require the attacker to breach any banking network or deploy malicious software. It requires only a convincing impression, story, accurate timing, and a target who has no reason to doubt the message or suspect the incident as fraud.

Why Is Business Email Compromise Such a Serious Threat?

Business email compromise poses a serious threat because of the following reasons:

  • Stolen funds are quickly distributed across financial networks: BEC-related payments are typically executed through wire transfers or ACH transactions. Once received, fraudsters often transfer the funds across multiple accounts, making recovery much harder and reducing the likelihood of tracing the full transaction path.
  • Many BEC attacks evade conventional email security measures: Unlike malware-based threats, BEC emails often contain no malicious attachments. Instead, they rely on impersonation and social engineering, allowing fraudulent requests to pass through technical controls while appearing legitimate to recipients.
  • Attackers focus on employees with payment authority: Finance, procurement, HR, and executive-support personnel are common targets because they routinely process payments, update vendor information, and approve financial transactions. BEC campaigns closely mimic legitimate business requests, making recipients more likely to act on fraudulent instructions without additional verification.

BEC ranks among the costliest categories of cybercrime that law enforcement tracks worldwide. According to the FBI's Internet Crime Complaint Centre (IC3), Business Email Compromise (BEC) accounted for 24,768 complaints and approximately $3.05 billion in reported losses in 2025, making it the second costliest cyber-enabled fraud category after investment fraud.

How Do Business Email Compromise Attacks Work?

A BEC attack rarely happens in a single step. Most incidents follow a five-stage pattern that unfolds over days or weeks before attackers request a single fraudulent payment.

bec-image-2.webp

Step 1: Reconnaissance

Before sending a single email, fraudsters research the target organisation. They assess LinkedIn profiles, company websites, press releases, regulatory filings, job postings, social media activity, and recent news coverage. More sophisticated attacks involve fraudsters mapping out executive hierarchies, vendor relationships, payment processes, reporting structures, and approval workflows, so that their requests appear to be in line with normal business operations.

Step 2: Identity Spoofing or Account Compromise

The attacker then establishes a fabricated identity that naturally seems trustworthy. This could be achieved by registering a lookalike domain that differs by just one character from the real one, spoofing the display name while the underlying address differs, or outright compromising a real mailbox and inserting malicious inbox or forwarding rules to hide any reply from the genuine account holder.

bec-image-1.webp

Example: Microsoft documented phishing campaigns in which attackers spoofed an organization’s domain to send emails that appeared to come from legitimate internal accounts. In one case, a fake “SharePoint document” notification displayed the recipient’s own email address in both the “To” and “From” fields. This made the message appear to be a legitimate internal email, increasing the likelihood that the recipient would open or click it.

Step 3: Social Engineering

The fraudulent message is based on urgency, secrecy, and authority or fear of delay, and increasingly uses AI-generated text, cloned voices, or deepfake video to make the impersonation more convincing. The idea is to prevent the recipient from taking a moment to verify the request through some other channel.

Step 4: Payment Redirection

When the target responds to that fraudulent act, the attacker quickly moves the money to a number of accounts they control, usually mule accounts, international banks, or cryptocurrency exchanges. These are accounts that are frequently used and allow the fraudster to quickly transfer, withdraw, or distribute the stolen funds, making it much more difficult to recover.

Step 5: Money Laundering

Once a fraudulent transfer has occurred, criminals will often move the funds through multiple accounts, mules, and, in some cases, international jurisdictions within a short period of time. According to the FBI, in 2025, the FBI’s IC3 Recovery Asset Team was able tofreeze an estimated $679 million in suspected fraudulent transfers, with a 58% success rate on all Financial Fraud Kill Chain cases.

Real-World Examples of Business Email Compromise

Real-world BEC attacks show that attackers do not need malware or network access to cause significant financial damage. Instead, they exploit trust, timing, and routine business processes.

  • Facebook and Google ($121 million): Between 2013 and 2015, Lithuanian national Evaldas Rimasauskas ran a fake hardware-supplier company under the same name as Quanta Computer, a real vendor to both Facebook and Google, and used forged invoices and contracts to convince both companies to wire a combined $121 million to accounts he controlled. The scheme ended with a guilty plea to wire fraud in 2019.
  • Toyota Boshoku ($37 million): In August 2019, a European subsidiary of Toyota Boshoku Corporation, a Toyota Group company that supplies seats and interior components, was duped into wiring roughly 4 billion yen (about $37.3 million) to a third party following fraudulent payment instructions. Toyota Boshoku brought in legal professionals and reported the loss to local authorities, but the incident illustrates how even a large, well-resourced manufacturer with global supply-chain experience can still be caught by a single convincing payment redirection.
  • FACC Aerospace (€50 million): Austrian aerospace parts manufacturer FACC, whose customers include Airbus and Boeing, lost roughly €42 million (about $47 million) in what it later called the “Fake President Incident.” A fraudulent email impersonating CEO Walter Stephan instructed a finance employee to wire funds for what was framed as a confidential acquisition. FACC managed to block about €10.9 million before it left the company's control, but the rest was gone. The fallout extended well beyond the financial loss: the company took a €41.9 million charge over the incident, and its supervisory board fired Stephan months later for failing in his duties regarding the fraud.

These incidents followed a common pattern: the attacker impersonated a trusted party, the request was legitimate, and the fraud was detected only after the transfer of funds. These examples reveal why BEC remains one of the most financially damaging types of cyber fraud in the world.

How Is BEC Different From Phishing and EAC?

Business Email Compromise (BEC)

BEC (Business email compromise), phishing, and EAC (email account compromise) all rely on social engineering, but they differ in how they're actually executed and what attackers aim to achieve. The table below shows the clear differences among these three.

Key FactorsBECPhishingEAC
Primary GoalFraudulent payments or sensitive data disclosureCredential theft or malware deliveryUse a compromised mailbox to conduct fraud
Delivery MechanismImpersonated executive, vendor, or partner requesting a business actionMalicious links, attachments, or fake login pagesMessages sent directly from a compromised legitimate mailbox
Uses a Legitimate MailboxNot alwaysNoYes
Malware RequiredRarelyOftenRarely
Typical TargetFinance teams, executives, procurement, HRAny employeeExisting customers, vendors, and internal teams connected to the compromised account
Detection DifficultyHighModerateVery high

Swipe the table

Phishing uses malicious links, attachments, or fake login pages to steal credentials at scale. BEC targets a legitimate business action such as authorising a payment or changing bank details, sometimes without any malicious payload. EAC takes this one step further. It uses a fully compromised mailbox to commit fraud, making it one of the hardest variants to detect.

What Are the Common Types of Business Email Compromise Scams?

BEC scams involve multiple fraud types, including CEO fraud, Account Compromise, Data Theft, and others. Each targets a different role, workflow, or payment trigger inside an organisation. Fraudsters carry out multiple convincing actions to persuade employees to transfer funds and make the fraud successful. Knowing which type affects your organisation helps finance and security teams match the right verification step to the risk level.

  • CEO Fraud: An attacker impersonates a chief executive officer and emails a finance employee demanding an immediate, confidential wire transfer for an acquisition or an urgent project. A common variant instead asks an executive assistant to buy hundreds of dollars in gift cards.
  • False Invoice or Vendor Scheme: Scammers represent themselves as a legitimate supplier and confirm to the accounts payable team that banking information or a mailing address has changed. They ask to redirect payment to a new account without telling anyone about the change.
  • Account Compromise or Account Takeover: Attackers gain control of a legitimate employee or vendor email account and leverage existing email conversations to send fraudulent payment instructions or request invoice settlements. Trusted communication history makes these requests much harder to identify as malicious.
  • Attorney Impersonation: Criminals pose as outside legal counsel handling a high-pressure, highly sensitive matter, such as a merger, an audit, or a lawsuit, and direct the request at junior staff who may not have the legal authority to question the law.
  • Data Theft: Attackers target HR personnel to gain access to employee W-2 forms, tax records, or direct-deposit details. They can then use the details for financial fraud or identity theft.
  • Email Account Compromise (EAC): The attacker doesn't spoof or impersonate a mailbox from the outside; they control the real, legitimate account and send fraudulent instructions from it. This makes the EAC the hardest BEC variant to detect through sender or domain checks alone.

What Are the Warning Signs of a Business Email Compromise Attempt?

BEC emails are built to look ordinary. But most warning signs are procedural rather than technical. If a payment request, vendor account update, invoice approval, or other sensitive business instruction breaks the normal workflow within an organisation, it deserves closer scrutiny. Any single sign below could have its own explanation; when two or three show up together on the same request, manual verification is necessary.

  • A sudden or unscheduled payment request: Legitimate payments almost always follow a predictable cycle. For example, a known invoice date, a recurring vendor, an approved purchase order. A request that falls outside that rhythm, particularly one framed as one-off or time-sensitive, deserves closer scrutiny before it moves forward.
  • A last-minute change to bank account details: Vendors and employees usually maintain the same account for business-related transactions. If any changes happen, they clearly communicate that to vendors through an established channel. A last-minute change mentioned in the email thread before the payment is about to be made is one of the crucial warning signs of BEC fraud.
  • Pressure language such as “needed urgently” or “handle this quietly”: Business emails that reflect a sense of urgency and secrecy about the payments need to be verified before making any payment. A true executive or vendor never asks an organisation to skip the payment details from an official. They never ask you to skip a credible process or to leave the manager off the payment-confirmation email loop. That instruction is itself a red flag for BEC (business email compromise).
  • Timing around travel, holidays, or reduced staffing: Attackers purposely send requests when the real executive or vendor contact is least available to provide quick confirmation, such as when they’re on a trip, a public holiday or at other known times when the chances are higher that they will ignore it or fail to verify due to personal reasons.
  • A request marked confidential that skips the standard approval workflow: The financial approval process involves many people, and multiple officials can review the payment of a vendor or employee. Any instruction to an employee to hide a transaction from other employees or approvers, or to disable access to view it, is a strong indicator of a high risk of fraud.
  • A sender domain that differs from the legitimate domain by a single character, inserted symbol, or altered top-level domain (TLD): Lookalike domains are designed to mimic trusted organisations and bypass routine scrutiny. Examples include swapped letters, added hyphens, or changes from company.com to company.co or company.net. Such variations are a common indicator of business email compromise (BEC) attempts.
  • An unexpected change in payment instructions from an established vendor: A long-standing supplier who has never asked for a change suddenly requesting one, especially through email alone, should trigger a cross-check and the same verification an organisation would apply to a brand-new vendor.

Effective Strategies Every Business Should Implement to Protect Against BEC Attacks

bec-image-4.webp

Preventing Business Email Compromise (BEC) requires a combination of process controls, employee awareness, and technology safeguards. Because most BEC attacks rely on impersonation and social engineering rather than malware, organisations must focus on verifying identities and detecting suspicious behaviour before releasing funds or sensitive data.

Enforce Independent Verification Procedures

  • Out-of-band verification: Employees should always verify payment requests, vendor account changes, and updates to sensitive data through a separate communications channel, such as a phone call or approved internal platform.
  • Use trusted contact information: Verify requests using contact details already stored in company records, not phone numbers or email addresses provided in the request.
  • Dual approval workflows: Require at least two authorised individuals to approve high-value payments, payroll updates, or banking changes.
  • Escalate unusual requests: Any request involving urgency, secrecy, or deviations from standard procedures should trigger additional review.

Strengthen Technical Controls

  • Deploy phishing-resistant MFA: Protect corporate email and cloud accounts with strong multi-factor authentication.
  • Implement SPF, DKIM, and DMARC: Use Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC) to verify that emails originate from authorised domains and to reduce the risk of domain spoofing.
  • Monitor account activity: Detect suspicious logins, unusual locations, mailbox rule changes, and other signs of account compromise.
  • Use fraud intelligence: Device intelligence, behavioural analytics, digital footprint analysis, and risk scoring can help identify impersonation attempts that traditional security tools may miss.

Reduce Exposure and Build Employee Awareness

  • Limit publicly available information: Restrict unnecessary exposure of executive details, organisational structures, and business activities that attackers can use for reconnaissance.
  • Provide regular training: Educate employees about executive impersonation, vendor fraud, invoice scams, and other common BEC tactics.
  • Recognise behavioural red flags: Encourage teams to question requests that create urgency, demand secrecy, or involve unusual payment instructions.
  • Run simulated exercises: Regular BEC simulations help employees practise verification procedures and improve response readiness.

Prepare for Rapid Incident Response

  • Act immediately: Contact banking partners, security teams, and relevant authorities as soon as a fraudulent transfer or suspicious request is identified.
  • Preserve evidence: Retain emails, transaction records, and communication logs to support investigations and recovery efforts.

How Does Sign3 Detect Fraud Beyond Email Signals?

Business email compromise ultimately succeeds or fails at the payment stage, when someone updates bank details, approves a transfer, or onboards a new vendor. We help organisations assess the risk factors behind those actions by analysing signals that traditional email security and fraud detection tools often miss. The signals are as follows:

  • Device Intelligence identifies suspicious devices used to make transactions, change vendors, or update accounts. This helps to identify signs of fraud such as device reuse or tampering.
  • Behavioural Biometrics looks at how users actually use their systems. This signal also helps detect anomalous behaviour that could indicate an account takeover, even when valid credentials are used.
  • Network and Graph Intelligence: Links related accounts, devices, and identities to identify mule-account networks and repeat fraud actors.
  • Digital Footprint and Location Intelligence: Highlights inconsistencies in identity, vendor, and location data that may warrant additional verification.
  • Risk Scoring: Combines these signals into a real-time assessment, helping finance and risk teams prioritise high-risk transactions and account changes.

Together, these layers let an organisation verify a vendor, a beneficiary account, or a payment change against the same intelligence Sign3 uses to detect fraud everywhere else in the customer lifecycle, rather than relying on a finance employee to detect, unaided, an email built specifically to convince them.

Conclusion

BEC, or business email compromise, succeeds because it exploits trust rather than the technology used in financial institutions and banks. Even organisations with mature cybersecurity programmes can suffer significant losses when attackers manipulate employees, vendors, or executives into authorising fraudulent transactions. Traditional security tools such as firewalls, antivirus software, and malware scanners are not designed to detect these trust-based attacks.

This is where an effective, layered fraud intelligence approach comes in, combining device intelligence, behavioural biometrics,digital footprint analysis, graph intelligence, and risk scoring. Together, these can identify suspicious activity before money moves from an account. Our platform uses the same approach. By uncovering hidden fraud networks, identifying high-risk identities, and detecting suspicious behavioural patterns in real time, we help financial institutions and enterprises stop fraudulent transactions before losses occur.Connect with us for a demo and experience how this fraud intelligence layer works in reality.

Frequently Asked Questions

What is an example of business email compromise?

One widely cited example of BEC is the $121 million fraud against Facebook and Google, in which a criminal impersonated a real hardware vendor and submitted forged invoices that both companies paid over more than two years.

Is BEC the same as phishing?

No. BEC is not the same as Phishing. This is a broad category of email fraud that generally relies on malicious links, attachments, or credential theft. BEC is a more targeted form of email fraud that often contains no malware and instead relies on impersonation and social engineering to redirect a legitimate payment or data request.

What is the difference between BEC and EAC?

The main difference between BEC and EAC is that in a Business Email Compromise (BEC) attack, the criminal pretends to be someone else using a fake or spoofed address. In the case of an Email Account Compromise (EAC) attack, the criminal actually takes over the actual, legitimate email account and sends fraudulent instructions from it.

Is business email compromise illegal?

Yes, business email compromise is strictly illegal. Most jurisdictions prosecute BEC as part of wire fraud, identity theft, and money laundering, and the FBI also actively investigates BEC cases through its Internet Crime Complaint Centre.

Can a BEC attack happen without malware?

Yes. Most BEC attacks can be carried out without any malware. BEC do not include a malicious link, attachment or executable file. The attack relies only on convincing impersonation and a convincing business reason to move money or data, which is why traditional email security often fails to detect it.

Which departments are most targeted in BEC attacks?

BEC attacks frequently target finance, accounts payable, procurement, payroll, human resources, legal teams and more. Departments that handle wire transfers, vendor payments and invoices are most at risk.

How do attackers spoof executive emails?

Attackers spoof executives’ emails by exploiting basic flaws in email protocols and social engineering. They register lookalike domains that differ by a single character from the real domain, manipulating employees into trusting a fake sender. They may even change the display name to an executive's while the actual address differs, or compromise a real mailbox and send instructions directly from it.

Share

Keep reading

All articles →

Browse by topic

Run your last week of traffic through Sign3.

We'll score it, surface the fraud patterns your current stack missed, and walk you through what we found. Your data, our scoring. No commitment, no integration, no decision required until you've seen the result.