Business Email Compromise (BEC): How It Works
Business email compromise (BEC) is one of the costliest cyber scams. There is often no malware, just a convincing email that impersonates someone you trust, an executive, a vendor, or HR, to trick an employee into sending money or sensitive data.
Because BEC targets people and processes rather than technology, awareness and simple verification steps are the best defense.
Common types of BEC
BEC shows up in a few recurring forms:
- CEO fraud: a message that looks like it is from a boss asks for an urgent wire transfer or gift cards.
- Vendor or invoice fraud: an attacker impersonates a supplier and asks you to update their bank details.
- Payroll diversion: a fake employee request to change direct-deposit details.
- Data theft: a request (often to HR or finance) for W-2s, tax forms, or employee records.
Red flags to watch for
BEC emails tend to share the same tells:
- Urgency and secrecy ("handle this quietly before the meeting").
- A change to payment details or a new bank account.
- A reply-to address that is slightly off from the real one.
- A request that skips the normal approval process.
- Pressure that discourages you from picking up the phone to check.
How to defend against it
A few controls stop most BEC:
- Verify any payment or bank-detail change by calling a known number, never the one in the email.
- Require a second approver for wire transfers above a threshold.
- Be suspicious of urgency plus secrecy, together they are a classic BEC signature.
- Enable MFA on email so attackers cannot take over real accounts.
- When in doubt, report it, checking is never an overreaction.
Real BEC emails, annotated
Illustrative training examples based on the two most common BEC plays. Notice that neither contains a link or an attachment; the attack is the request itself.
Example 1: CEO fraud (urgent wire, secrecy)
Are you available? I need a payment handled in the next hour and you are the only one I can reach. I am walking into a board meeting so I cannot take calls, just reply to this email.
Wire $24,750 to the account details below for the Hartley acquisition deposit. Keep this between us until the deal is announced, it is market sensitive.
- The "CEO" is writing from a personal address. The display name matches your CEO, but the actual address is robert.chen.ceo@gmail.com, not a company address. Attackers use free webmail or a look-alike domain (yourcompany.co instead of yourcompany.com) so your reply goes to them.
- Urgency plus unavailability. "In the next hour" combined with "cannot take calls" is deliberate: it pressures you to act fast and blocks the one step that would expose the scam, a quick call or walk to the CEO’s office.
- Secrecy and a payment outside the normal process. A real acquisition deposit goes through finance with approvals. "Keep this between us" exists so you will not mention it to anyone who would recognize the fraud.
Example 2: vendor impersonation (bank-detail change)
Hope you are doing well! A quick heads-up from our accounts team: we have switched banks, effective this week.
Please use the updated account and routing number below for invoice #2231 and all future payments. Our old account closes on Friday, so anything sent there will bounce and may incur a late fee.
- The domain is one word off. Your real vendor is apexbuilding.com; this came from apexbuilding-services.net. Attackers register near-identical domains and copy the real employee’s name and signature, often lifted from a hacked mailbox, so the thread reads exactly like past emails.
- A bank-detail change is the single biggest BEC signal. Payment diversion is how most BEC money is actually lost. Treat every change of account details as fraudulent until you verify it by phone, using the number already in your records, never a number from the email.
- A deadline with a penalty. "Closes on Friday" plus a late fee pushes accounts payable to skip verification. A real vendor expects you to confirm a banking change and will not punish you for checking.
Test yourself
Train your team to spot BEC with a free quiz.
Frequently asked questions
How is BEC different from regular phishing?
Regular phishing usually casts a wide net for passwords or clicks. BEC is targeted and often malware-free: it impersonates a specific trusted person to authorize a payment or data transfer. It relies on social pressure, not links.
Why do BEC emails feel so convincing?
Attackers research the company first, using LinkedIn and public info to mimic real names, roles, tone, and timing (for example, sending a "CEO" request while the CEO is traveling). That context makes the request feel normal.
What should I do if I get a suspicious payment request?
Do not act on the email. Verify it by calling the requester on a number you already know, confirm through your normal approval process, and report it to your security or finance team.