Business Email Compromise (BEC)
Business email compromise is fraud that impersonates a trusted party in order to induce a payment or the release of sensitive data. It is defined by what it exploits rather than by any technical method: an organization’s own payment processes, operated by people who believe they are following a legitimate instruction. In most cases nothing is hacked at all.
| What it is | Impersonation of a trusted party to trigger a payment or data release |
| Usually not a breach | The typical attack compromises a person, not a system |
| Main variants | Executive impersonation, vendor invoice fraud, attorney impersonation, payroll diversion, data requests |
| Hardest variant | A fully compromised mailbox, which passes every authentication check |
| Preparation | Research into suppliers, approvals, projects and who is away |
| Timing | Chosen — month end, a known acquisition, an executive travelling |
| Recovery window | Hours, and it closes fast |
| Escalation | Synthetic audio and video used to defeat callback verification |
The variants, and which one costs most
| Variant | Who is impersonated | What is requested |
|---|---|---|
| Executive impersonation | A CEO or CFO | An urgent confidential transfer |
| Vendor invoice fraud | An existing supplier | Payment to updated bank details |
| Attorney impersonation | External counsel | A confidential payment under time pressure |
| Payroll diversion | An employee | A change of salary destination account |
| Data request | An executive or authority | Employee tax or identity records |
Executive impersonation gets the attention, and vendor invoice fraud is usually the larger loss. A supplier relationship already exists, invoices are expected, and the amounts are ordinary for the business. The attack is a single email changing bank details on a genuine payment that was going to happen anyway — which means there is no unusual transaction to detect, only a correct payment to the wrong account.
The data request variant deserves its own mention because it produces no immediate loss and a great deal of later harm. A request for employee tax records, apparently from an executive, hands over the identity data that becomes refund fraud and new account fraud months afterwards.
Why technical controls reach so little of it
Email authentication protocols verify that a message came from a domain authorized to send it. They work, and they address the crudest version of the attack — outright domain spoofing.
They do not address the two that matter. A lookalike domain registered by the attacker is a domain they legitimately control, so it authenticates correctly. And a fully compromised mailbox sends mail that is authentic in every technical sense, because it is.
The compromised-mailbox case is the hardest thing in this category. The attacker reads months of correspondence before acting, learns the vocabulary, the approval chain and the supplier relationships, and replies within an existing thread at a plausible moment. There is nothing anomalous to detect because nothing anomalous has happened technically.
Why this matters for identity verification
BEC is a process problem before it is an identity problem, and saying so is more useful than claiming otherwise. The controls that work are dual authorization above a threshold, a verified change-of-bank-details procedure that does not accept email as evidence, a mandatory delay on new payees, and explicit permission for staff to question an instruction from someone senior.
Identity verification enters at two specific points.
The callback has a hole in it. The standard advice — confirm out of band before paying — assumed that hearing the right voice was verification. Synthetic audio removed that, and live video deepfakes removed the video-call version. What survives is contact the recipient initiates from independently held details, and deepfake detection where the interaction is mediated. GenAI and deepfake fraud controls exist because the human verification step is now attackable.
Supplier and payee changes are identity events. A request to change where money goes deserves the same scrutiny as opening an account, because it has the same effect — redirecting funds to a party whose identity nobody has established. Treating bank detail changes as an administrative update rather than an identity decision is the gap the vendor variant walks through.
What controls can’t do
Email authentication does not stop lookalike domains. The attacker owns the domain, so it authenticates correctly.
Nothing detects a compromised mailbox by its mail. The message is genuine; only the intent is not.
Callbacks fail on attacker-supplied numbers. The control works only when the recipient sources the contact details independently.
Recovery is measured in hours. Funds are moved on quickly, and the window for recall closes before most organizations notice.
Frequently asked questions
What is business email compromise?
Fraud that impersonates a trusted party — an executive, a supplier, a lawyer, an employee — to induce a payment or the release of sensitive data. In most cases no system is breached; the attack exploits an organization’s payment process through people following what appears to be a legitimate instruction.
Which BEC variant causes the biggest losses?
Vendor invoice fraud, usually. The supplier relationship already exists, invoices are expected, and the amounts are normal for the business, so a single email changing bank details redirects a payment that was going to be made anyway. There is no unusual transaction to detect.
Does email authentication stop BEC?
Only the crudest version. Lookalike domains registered by the attacker authenticate correctly because the attacker owns them, and a truly compromised mailbox sends mail that is authentic in every technical sense. Neither is addressed by sender authentication.
How should an urgent payment request be verified?
Through a channel the recipient initiates using independently held contact details — never a number or address supplied in the request. Recognizing a voice or face is no longer sufficient given synthetic audio and video, so the verification has to rest on process and dual authorization rather than recognition.