Business email compromise attacks

Last reviewed:

Business Email Compromise Attacks

Business Email Compromise (BEC) attacks are a form of cybercrime that targets organizations by exploiting email systems to deceive employees into transferring funds or sensitive information. These attacks often involve impersonating a trusted figure within the company or a known external partner. As of October 2023, BEC attacks remain a significant threat to businesses globally, with financial losses reaching billions of dollars annually. The attacks leverage social engineering tactics and often bypass traditional security measures, making them challenging to detect and prevent.

Overview

Business Email Compromise attacks are sophisticated scams that target businesses and individuals who perform legitimate transfer-of-funds requests. The attackers typically gain unauthorized access to a business email account or create a similar-looking account to deceive employees into making unauthorized wire transfers or divulging confidential information. According to the Federal Bureau of Investigation (FBI), BEC scams have resulted in significant financial losses, with reported incidents increasing annually.

The primary goal of BEC attacks is financial gain. Attackers often target high-level executives, finance departments, or employees with access to sensitive information. The attacks can take various forms, including CEO fraud, account compromise, and false invoice schemes. Despite the simplicity of the approach, the impact of a successful BEC attack can be devastating for organizations, to financial losses, reputational damage, and legal consequences.

How it works

Business Email Compromise attacks typically follow a multi-step process:

  1. Reconnaissance: Attackers gather information about the target organization, identifying key personnel and their roles. This phase may involve researching social media profiles, company websites, and other publicly available information.
  1. Email Compromise: Attackers gain access to a legitimate email account within the organization. This can be achieved through phishing attacks, where the victim is tricked into providing their login credentials, or through malware that captures keystrokes or credentials.
  1. Impersonation: Once access is obtained, attackers impersonate the compromised account holder or create a similar-looking email address. They craft convincing emails that appear to come from trusted sources within the organization or from known external partners.
  1. Deception: The attackers send fraudulent emails to employees, often requesting urgent wire transfers, changes to payment details, or sensitive information. The emails are designed to appear legitimate and may include official-looking signatures, logos, and language.
  1. Execution: If the target falls for the deception, they may unknowingly transfer funds to the attackers' accounts or provide sensitive information that can be used for further attacks.
  1. Cover-up: Attackers may attempt to cover their tracks by deleting emails or setting up forwarding rules to monitor responses and intercept any potential warnings.

Applications

Business Email Compromise attacks can be applied in various scenarios, including:

  • CEO Fraud: Attackers impersonate a high-ranking executive, such as the CEO or CFO, and instruct employees to transfer funds to an account controlled by the attackers.
  • Account Compromise: Attackers gain access to an employee's email account and use it to request unauthorized transfers or changes to payment details.
  • Invoice Scams: Attackers impersonate a supplier or vendor and send fake invoices to the target organization, requesting payment to a fraudulent account.
  • Data Theft: In some cases, BEC attacks are used to steal sensitive information, such as employee tax forms or customer data, which can be sold on the black market or used for further attacks.

Limitations

Despite their effectiveness, Business Email Compromise attacks have limitations:

  • Detection: Organizations with robust email security measures, such as multi-factor authentication and advanced threat detection, can identify and block BEC attempts.
  • Awareness: Employee training and awareness programs can reduce the likelihood of falling victim to BEC scams by teaching employees to recognize suspicious emails and verify requests through alternative channels.
  • Legal and Regulatory Measures: Governments and regulatory bodies are increasingly focusing on combating BEC attacks through legislation and guidelines, which can deter attackers and provide recourse for victims.
  • Recovery: While financial losses can be significant, some organizations may recover funds if the attack is detected quickly and reported to authorities.

Business Email Compromise Attack Process

Financial Losses from BEC Attacks (Annual)

See also

Sources

Categories: Threat Actors | Incidents
Last updated: October 1, 2026