Skip to content

Business Email Compromise (BEC)

Risk Level

Business Email Compromise (BEC) is a socially engineered attack where attackers impersonate executives, vendors, or partners to trick employees into transferring funds or sensitive data. No malware is required — pure social engineering.

TypeDescriptionTypical Loss
CEO FraudImpersonate CEO → urgent wire transfer$50K-$1M+
Vendor Invoice FraudCompromise vendor email → fake invoice$10K-$500K
Payroll DiversionHR/payroll target → direct deposit change$5K-$100K
Attorney ImpersonationFake legal counsel → urgent compliance$50K+
Data TheftW-2 / PII requests → identity theftIdentity fraud
1. RECONNAISSANCE
└─ LinkedIn, company website, breach data, org chart
2. IMPERSONATION SETUP
├─ Similar domain (ceo@company-services.com)
├─ Display name spoofing (display: "John Smith", email: attacker@x.com)
├─ Compromised executive account (credential theft)
└─ Compromised vendor account (supply chain)
3. SOCIAL ENGINEERING
├─ Urgency ("Need this today")
├─ Authority ("CEO requests")
├─ Secrecy ("Confidential, don't tell anyone")
└─ Legitimacy ("Reference invoice #12345")
4. EXECUTION
└─ Wire transfer to mule account
└─ Payroll direct deposit change
└─ Gift card / crypto purchase
5. LAUNDERING
└─ Mule network → crypto → mixer → cashout
IncidentYearLossMethod
Facebook/Google2013-15$100M+Vendor impersonation
Ubiquiti Networks2015$46.7MCEO fraud
Austrian Aerospace2016€50MCEO fraud
Toyota Boshoku2019$37MVendor invoice fraud
Puerto Rico Govt2020$2.6MPayroll diversion
  • DMARC/DKIM/SPFp=reject; monitor reports
  • FIDO2 MFA — Phishing-resistant for all finance/HR
  • Verification Protocol — Out-of-band verification for:
    • Wire transfers >$X
    • Payroll/banking changes
    • Vendor invoice changes
  • Email Security — DMARC p=reject, DMARC reporting
  • User Training — BEC-specific scenarios; finance/HR focus
  • Payment Controls — Dual approval; amount thresholds
  • Vendor Management — Verify changes via phone (known number)
TechniqueIDDescription
PhishingT1566Initial access
SpearphishingT1566.001/002Targeted
Financial TheftT1657Wire transfer fraud