Cybercriminals are increasingly using manipulation and employee trust instead of classic security breaching techniques. Today, companies around the world are facing an increasing number of email scams targeting finance departments, management and administrative staff.
What is Business Email Compromise (BEC) and how does it work?
Business Email Compromise (BEC) is a social engineering attack that involves impersonating a trusted person or organization to extort money or data.
The BEC attack very often uses spoofing (impersonating another element of the same system) or impersonation. Cybercriminals send fake emails resembling genuine business correspondence and trick victims into transferring money, changing transfer details or sending sensitive data.
Unlike classic phishing, Business Email Compromise Attack is usually more precise and is based on the analysis of the organization’s structure. Therefore, BEC vs phishing comparisons often emphasize that BEC attacks are more personalized and more difficult to detect.
Types of BEC attacks – CEO fraud, fake invoice, account compromise
Business Email Compromise attacks can take various forms depending on the target of the attack and the modus operandi of cybercriminals. One of the most common scenarios remains CEO fraud, i.e. fraud on the president by impersonating a superior or management board member.
Commonly used Business Email Compromise also includes:
- invoice fraud, i.e. replacing payment details or transfer fraud,
- compromising the employee’s email account,
- false invoices and false legal documents,
- spear-phishing targeting specific people or departments, e.g. finance, administration or HR
- whaling, i.e. an attack aimed at members of the management board, financial directors or other decision-makers.
BEC scams also use compromised mailboxes and prior analysis of company communications. This makes fraudulent messages can look credible and can go unnoticed by employees. Therefore, social-engineering tests and employee training play an important role in detecting this type of threat today.
Financial and operational effects of BEC attacks on companies
The most common effects of Business Email Compromise Scams are:
- transferring money to fake accounts
- data loss and leakage of sensitive data,
- disruption of the work of financial departments,
- loss of trust of customers and partners,
- the need to report incidents and conduct audits.
How to protect your company against BEC?
Protecting against BEC requires a combination of technical protections and employee education. It is crucial to verify the identity of senders, confirm changes to account numbers through another communication channel and additionally accept high-risk transfers.
Organizations should implement:
- Multi-factor authentication, or MFA,
- DMARC, SPF and DKIM,
- monitoring logins, email rules, redirects and unusual email account activity,
- regular security audits, email configuration tests and permission reviews,
- simple procedures for reporting suspicious messages and phishing attempts.
An important role is also played by employee awareness and regular training on recognizing social engineering attacks, e.g. phishing simulations and BEC scenarios carried out as part of the Practical Anti-Phishing Training. A helpful element of protection against BEC may also be OSINT open-source intelligence, which allows you to check what information about the organization, employees and business processes is publicly available and can be used by cybercriminals.
FAQ – Business Email Compromise (BEC)
BEC vs phishing – what’s the difference?
BEC is a more personalized form of attack than classic phishing. Cybercriminals often impersonate specific people, e.g. management board members, supervisors or business partners, and use real company communications to increase the credibility of the message and persuade the victim to make a transfer, change payment details or provide confidential information.
How to report a BEC attack?
A BEC attack should be reported to the security department, IT administrator or appropriate services. It is also worth securing messages and checking whether email accounts have not been compromised.