Confidential by defaultEstablished 201072 Jurisdictions

Business Email Compromise (BEC)

Business email compromise is a fraud in which an attacker impersonates or takes control of a business email account to manipulate payments or obtain sensitive information. Independent verification of changed bank instructions is one of the most important defenses.

Business email compromise covers several related frauds that all exploit trust in email. In one version, the attacker gains access to a real mailbox at the supplier or buyer and watches the correspondence until an invoice is due. In another, the attacker registers a look-alike domain that differs by a single character and impersonates a known contact. In a third, the attacker poses as a senior executive and pressures a finance employee to send an urgent transfer.

In cross-border trade the usual goal is to redirect a supplier payment: a genuine-looking message announces new bank details or attaches an altered invoice, which leads directly to payment diversion fraud. Because the message arrives within a real email thread, refers to real orders and uses the right names, it can be difficult to spot. The fraudulent account is commonly opened shortly before the attack and emptied soon after funds arrive.

Controls work best when they assume email can be compromised. Confirm any change of payment instructions by calling a known number, require a second approver for new or changed beneficiaries, and treat urgency and secrecy as warning signs. Technical measures such as multi-factor authentication and domain-spoofing protection help, but they do not replace verification. If a business suspects it has paid a fraudster, it should contact its bank immediately and, in the United States, can report the incident to the FBI's IC3.

In practice

An email from a familiar address is not proof that the sender is genuine. Changes to bank details should never be accepted on the strength of email alone.

Example

Hypothetically, a finance assistant receives a message from a domain that differs from the supplier's real one by a single letter, quoting the right purchase order and asking for the US$48,000 balance to go to a new account because of an audit. The company's rule requires a call-back to the supplier on a number held on file, which exposes the impersonation before any money moves.

Commonly confused with

TermHow it differs
Payment diversion fraudPayment diversion fraud is the redirection of a genuine payment to a fraudster's account. Business email compromise is one of the main ways it is carried out.

See also

Go deeper

← All glossary terms

Page Last Updated: 02/Oct/2026