Business Email Compromise (BEC)
Introduction
Section titled “Introduction”Business Email Compromise (BEC) is a socially engineered attack where attackers impersonate executives, vendors, or partners to trick employees into transferring funds or sensitive data. No malware is required — pure social engineering.
BEC Types
Section titled “BEC Types”| Type | Description | Typical Loss |
|---|---|---|
| CEO Fraud | Impersonate CEO → urgent wire transfer | $50K-$1M+ |
| Vendor Invoice Fraud | Compromise vendor email → fake invoice | $10K-$500K |
| Payroll Diversion | HR/payroll target → direct deposit change | $5K-$100K |
| Attorney Impersonation | Fake legal counsel → urgent compliance | $50K+ |
| Data Theft | W-2 / PII requests → identity theft | Identity fraud |
Attack Flow
Section titled “Attack Flow”1. RECONNAISSANCE └─ LinkedIn, company website, breach data, org chart
2. IMPERSONATION SETUP ├─ Similar domain (ceo@company-services.com) ├─ Display name spoofing (display: "John Smith", email: attacker@x.com) ├─ Compromised executive account (credential theft) └─ Compromised vendor account (supply chain)
3. SOCIAL ENGINEERING ├─ Urgency ("Need this today") ├─ Authority ("CEO requests") ├─ Secrecy ("Confidential, don't tell anyone") └─ Legitimacy ("Reference invoice #12345")
4. EXECUTION └─ Wire transfer to mule account └─ Payroll direct deposit change └─ Gift card / crypto purchase
5. LAUNDERING └─ Mule network → crypto → mixer → cashoutNotable Incidents
Section titled “Notable Incidents”| Incident | Year | Loss | Method |
|---|---|---|---|
| Facebook/Google | 2013-15 | $100M+ | Vendor impersonation |
| Ubiquiti Networks | 2015 | $46.7M | CEO fraud |
| Austrian Aerospace | 2016 | €50M | CEO fraud |
| Toyota Boshoku | 2019 | $37M | Vendor invoice fraud |
| Puerto Rico Govt | 2020 | $2.6M | Payroll diversion |
Prevention
Section titled “Prevention”- ✅ DMARC/DKIM/SPF —
p=reject; monitor reports - ✅ FIDO2 MFA — Phishing-resistant for all finance/HR
- ✅ Verification Protocol — Out-of-band verification for:
- Wire transfers >$X
- Payroll/banking changes
- Vendor invoice changes
- ✅ Email Security — DMARC
p=reject, DMARC reporting - ✅ User Training — BEC-specific scenarios; finance/HR focus
- ✅ Payment Controls — Dual approval; amount thresholds
- ✅ Vendor Management — Verify changes via phone (known number)
MITRE ATT&CK
Section titled “MITRE ATT&CK”| Technique | ID | Description |
|---|---|---|
| Phishing | T1566 | Initial access |
| Spearphishing | T1566.001/002 | Targeted |
| Financial Theft | T1657 | Wire transfer fraud |
Related
Section titled “Related”- Phishing — Delivery method
- Credential Theft — Account takeover
- User Awareness — Training