Free Phishing Test
CYBER THREATS

Why Business Email Compromise Threatens Your Company

05-apr-2022 4 minutes read

What is Business Email Compromise (BEC)?

Business Email Compromise is a targeted phishing attack in which a criminal impersonates an employee, manager, supplier or business partner to obtain money, data or another benefit.

The attack often has two stages. First, the criminal compromises the mailbox of an intermediary or creates a lookalike address. The impersonated person may be a board member, finance director, accountant or trusted partner. The attacker then studies the mailbox, learns the company’s communication style and uses an existing thread or a new message to make the request look credible.

The goal may be to persuade an employee to transfer money to a new bank account, pay a false invoice or disclose confidential information. BEC attacks often target management and finance or HR teams, but every employee can become the entry point.

Attackers use social engineering and detailed reconnaissance. They may observe a victim for months or finish the attack in only a few messages. The more context they collect, the more convincing the correspondence becomes.

The employee is the first line of defense

BEC is effective because it exploits trust. A message that appears to come from a colleague or supplier may not trigger suspicion, especially when it continues an existing conversation. Technical controls and procedures are important, but they cannot replace an employee who knows how to recognize an unusual request.

Continuous security awareness training and realistic simulations help employees develop safe habits, recognize manipulation and report an attempted attack before money or data leaves the company.

BEC attacks are the most costly form of phishing

FBI data cited in the original article shows the financial scale of the problem: in 2021, reported BEC losses reached almost USD 2.4 billion. The real scale is likely higher because many incidents are not reported.

Examples include a US university that transferred almost USD 2 million after criminals impersonated a construction company; a European branch of a Japanese car manufacturer that lost more than USD 37 million; and a Polish trading company that lost approximately PLN 4 million after receiving a fraudulent bank-account-change request. Polish airlines lost PLN 2.6 million in another case, while a provincial roads authority transferred PLN 3.7 million to criminals impersonating a contractor.

Companies of every size and in every industry are exposed. A single successful request can cause financial loss, interrupt operations and damage trust.

How does a BEC attack work?

Criminals may first compromise a supplier’s mailbox or obtain credentials from a data leak. Reused passwords make this easier. They may also use phishing or information collected from LinkedIn, Facebook and other social networks.

Once inside a mailbox, the attacker looks for orders, invoices and payment discussions. They copy the company’s documents, signatures and writing style, then contact a customer with a request to change the bank account, settle an overdue invoice or pay a correction invoice. The message looks credible because it comes from a valid or very similar address, uses the right language and refers to a real contract or delivery.

The fraud may continue for months before the victim realizes that payments are reaching a criminal’s account. This is why every change to payment details must be verified through a separate, trusted channel.

Example BEC attack scenarios

  • Account takeover and email interception: after accessing a finance employee’s mailbox, the attacker asks customers to send a payment to a new account.
  • Impersonation of a CEO or manager: the attacker asks an employee to transfer money or send confidential information.
  • Impersonation of a lawyer: a fake lawyer contacts a senior employee with a request for a transfer or sensitive data.
  • Fake supplier arrears: the attacker finds a real supplier conversation, impersonates the supplier and demands payment to a different account.

BEC is a serious threat regardless of company size or industry. Security awareness is a process: management must set priorities, provide clear procedures and give employees regular opportunities to practice safe responses.

Gain specialised knowledge about cybersecurity

Build a resilient cybersecurity culture with our support

Let's discuss your organization's cyber needs

Fill in the form

Would you like to test the resilience of your systems?

Fill in the form to schedule a free, no-obligation consultation. We will discuss the scope of the penetration tests and prepare a proposed approach tailored to your organization and infrastructure.
Would you prefer to speak to us directly?
+48 732 123 579