(518) 292-4500|sales@logical.net|M-F 8am-5pm · 24/7 SOC
MSP 501 Winner 2025Client Portal →
Threats & Attacks

What is BEC (Business Email Compromise)?

Business Email Compromise (BEC) is a targeted email fraud technique where attackers impersonate executives, vendors, or trusted partners to trick employees into wiring money, changing payment details, or sharing sensitive data.

How BEC works

Three-step view of how it operates in practice.

  • Research. Attackers identify the target, usually finance, HR, or executive assistants. They study public information, prior emails, vendor relationships.
  • Impersonate. The attacker spoofs a known sender (CEO, CFO, vendor AP contact) or compromises a real mailbox and sends from it directly.
  • Request. A plausible request arrives: wire a payment, update vendor banking details, buy gift cards, send a payroll file. The sense of urgency and legitimate voice bypass normal checks.

Why BEC matters

The FBI's IC3 reports have ranked BEC among the costliest cybercrime categories for years, and a single fraudulent wire can exceed what a small company's insurance will reimburse — social engineering losses are often capped at a low sublimit. Recovery is only realistic if the bank is contacted within hours, so the callback-verification habit is worth more than any product you can buy.

The four common BEC schemes

  • CEO fraud. A message that appears to come from the owner or CEO pressures someone in finance to send an urgent, confidential wire. The authority of the sender is the whole trick.
  • Vendor invoice fraud. A real supplier's mailbox is compromised or convincingly spoofed, and a routine invoice arrives with new banking details. Payments flow to the attacker for weeks before anyone notices.
  • Payroll diversion. HR receives a polite request, apparently from an employee, to change their direct deposit account. The paycheck lands in a mule account on the next pay run.
  • Attorney or acquisition impersonation. Someone posing as outside counsel or an M&A advisor demands a confidential transfer tied to a deal. Secrecy is built into the pretext, which keeps the victim from asking around.

Common BEC mistakes

  • Trusting the reply button. If the attacker controls the thread, replying to ask 'is this real?' goes straight to the criminal, who happily confirms. Verify any payment change by phone using a number you already had on file — never one from the email signature.
  • No dual approval on money movement. A single person who can initiate and approve a wire or a banking-detail change is a single point of failure. Require two people for wires above a threshold and for every vendor bank change, no exceptions for urgency.
  • Assuming filters will catch it. Many BEC messages contain no link and no attachment — just well-written text from a plausible address, which sails past technical controls. The defense is process: verification callbacks and approval workflows that hold even when the email looks perfect.
Related terms

Need this in your environment?

We turn these controls on for Capital Region organizations every day. Let's talk about yours.