GRC Careers

HomeResourcesBusiness Email Compromise (BEC)

CS-035 · Email Security

Business Email Compromise (BEC)

Email fraud that impersonates trusted parties to trick staff into transferring money or data.

Executive Summary

Business email compromise, or BEC, is a form of email fraud in which an attacker impersonates a trusted party such as an executive, vendor, or partner to trick employees into transferring funds or sensitive information. Unlike malware-driven attacks, BEC often relies purely on deception and social pressure, so it can slip past technical filters. It is among the most financially damaging categories of cybercrime because it targets normal business processes rather than software flaws.

What It Is

BEC is fraud carried out over email by exploiting trust in routine business communication. The attacker poses as someone the target already deals with, an executive, a supplier, a lawyer, or a colleague, and requests an action that seems ordinary but redirects money or data to the attacker. Common variants include invoice fraud, where a supplier's payment details are altered; executive impersonation, where a fake leadership request pressures a wire transfer; and payroll diversion, where an employee's direct deposit is redirected. BEC often involves little or no malware. Instead it may use a spoofed or look-alike address, or a genuinely compromised account, which makes the request appear authentic and the fraud especially hard to catch.

Why It Matters

BEC causes enormous financial losses worldwide, often in single transactions large enough to harm an organization materially. Because it manipulates legitimate processes and frequently avoids malware, spam filters and antivirus tools may never flag it, and the fraud is often discovered only after funds have moved. Recovery is difficult once money leaves the account, especially across borders. Beyond direct loss, BEC can expose sensitive employee or customer data and damage vendor relationships. For professionals, BEC underscores that security is as much about business process and verification as about technology, and it is a central concern for finance, security, and governance teams alike.

How It Works

A BEC attack typically starts with research and often with account access, gained through an earlier phish or credential theft. Armed with knowledge of who pays whom and how, the attacker inserts a fraudulent request into a believable context: a supplier updating bank details, an executive requesting an urgent transfer, or a change to payroll information. The message is timed and worded to fit normal operations and discourage double-checking, sometimes citing confidentiality or a deadline. If the target complies, funds are wired to an account the attacker controls and quickly moved onward. Because the whole scheme relies on convincing a person to follow a normal-looking instruction, the strongest defenses are verification procedures and payment controls, backed by strong authentication to prevent account takeover in the first place.

Architecture Diagram

Attacker researches or compromises an accountImpersonates an executive, vendor, or colleagueSends altered or urgent payment instructionsStaff follow the normal-looking requestFunds or data are diverted to the attacker
BEC inserts a fraudulent payment or data request into a normal business process to divert funds.

Visual Workflow

The attacker gathers details on payment relationships, often via a prior phish or account access.They impersonate a trusted party using a spoofed, look-alike, or compromised account.A fraudulent request is inserted into a normal process, such as an invoice or transfer.Urgency or confidentiality is used to discourage verification.An employee approves the payment or shares the requested data.Funds move to an attacker-controlled account and are quickly dispersed.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

Multi-factor authentication
Prevents the account takeover that enables the most convincing BEC
Email security gateway
Flags impersonation, look-alike domains, and external senders
DMARC with SPF and DKIM
Reduces spoofing of your own domain in fraudulent requests
Payment verification controls
Enforces callback and dual approval before funds move

Industry Standards

NIST SP 800-177
Trustworthy email and sender authentication against impersonation
NIST SP 800-61
Incident handling for responding to a BEC fraud or account takeover
CIS Critical Security Controls
Authentication and account safeguards that reduce BEC exposure

Career Relevance

BEC bridges cybersecurity and financial controls. Incident responders lead the race to recall funds and reset compromised accounts, SOC analysts detect the account takeovers that precede fraud, and security awareness leads train finance and payroll teams on the pretexts used. GRC analysts design and audit the verification and dual-authorization controls that stop payment fraud. For the AI-Governance-Jobs.com audience, BEC is a high-stakes topic across security, finance, and governance roles.

Interview Questions

Related Certifications

CompTIA Security+ ISC2 Certified in Cybersecurity (CC) ISACA CISM (for leadership tracks)

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

How is BEC different from ordinary phishing?

Phishing usually seeks credentials or delivers malware at scale. BEC is targeted fraud that manipulates a legitimate business process, such as a payment or a bank-detail change, often with no malware at all. That makes it harder for technical tools to catch.

Why is BEC so financially damaging?

BEC targets real payment workflows and often moves large sums in a single transaction. Because the request looks normal and the fraud is discovered late, recovery of funds is difficult, especially once money crosses borders.

What is the single best control against BEC?

Out-of-band verification. Confirming any payment or bank-detail change through a separate, known channel, combined with dual authorization for large transfers, stops most BEC even when the email looks completely convincing.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

CompTIA Security+ISC2 Certified in Cybersecurity (CC)ISACA CISM (for leadership tracks)

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: Business Email Compromise (BEC)
  3. Go deeper: Whaling
  4. Go deeper: Spear Phishing
  5. Validate it: work toward CompTIA Security+
  6. Find the role: browse current openings

Related sheets

More in Email Security

Share this LinkedIn Facebook X Email