Business Email Compromise (BEC)
Business email compromise is a fraud in which an attacker impersonates or takes control of a business email account to manipulate payments or obtain sensitive information. Independent verification of changed bank instructions is one of the most important defenses.
Business email compromise covers several related frauds that all exploit trust in email. In one version, the attacker gains access to a real mailbox at the supplier or buyer and watches the correspondence until an invoice is due. In another, the attacker registers a look-alike domain that differs by a single character and impersonates a known contact. In a third, the attacker poses as a senior executive and pressures a finance employee to send an urgent transfer.
In cross-border trade the usual goal is to redirect a supplier payment: a genuine-looking message announces new bank details or attaches an altered invoice, which leads directly to payment diversion fraud. Because the message arrives within a real email thread, refers to real orders and uses the right names, it can be difficult to spot. The fraudulent account is commonly opened shortly before the attack and emptied soon after funds arrive.
Controls work best when they assume email can be compromised. Confirm any change of payment instructions by calling a known number, require a second approver for new or changed beneficiaries, and treat urgency and secrecy as warning signs. Technical measures such as multi-factor authentication and domain-spoofing protection help, but they do not replace verification. If a business suspects it has paid a fraudster, it should contact its bank immediately and, in the United States, can report the incident to the FBI's IC3.
In practice
An email from a familiar address is not proof that the sender is genuine. Changes to bank details should never be accepted on the strength of email alone.
Example
Hypothetically, a finance assistant receives a message from a domain that differs from the supplier's real one by a single letter, quoting the right purchase order and asking for the US$48,000 balance to go to a new account because of an audit. The company's rule requires a call-back to the supplier on a number held on file, which exposes the impersonation before any money moves.
Commonly confused with
| Term | How it differs |
|---|---|
| Payment diversion fraud | Payment diversion fraud is the redirection of a genuine payment to a fraudster's account. Business email compromise is one of the main ways it is carried out. |
See also
- Payment Diversion FraudPayment diversion fraud redirects a legitimate payment to an account controlled by a fraudster. It commonly involves altered invoices, compromised communications or false instructions announcing a change in beneficiary bank details.
- Beneficiary-Account MismatchA beneficiary-account mismatch occurs when the account holder’s name does not agree with the expected supplier or contractual payee. It can indicate a clerical error, undisclosed collection arrangement, payment-diversion fraud or an unrelated third party.
- Payment RecallA payment recall is a request by the sending institution to recover or stop a transfer after it has been released. A recall is not guaranteed because the funds may already have been credited, withdrawn or made subject to the beneficiary bank’s procedures.
