What Is Business Email Compromise?
Business Email Compromise (BEC) is a category of fraud in which attackers use email, either compromised legitimate accounts or convincing impersonations, to deceive employees into making fraudulent wire transfers, sharing sensitive credentials, or redirecting payroll. BEC does not require malware and often bypasses technical security controls entirely because it exploits human trust rather than software vulnerabilities. The FBI's 2024 Internet Crime Report cited BEC as the most financially damaging cybercrime category, accounting for billions in losses annually.
How BEC Attacks Work
The most effective BEC attacks are patient and deliberate. Attackers may spend weeks monitoring a compromised email account before acting, learning communication styles, identifying key personnel, understanding upcoming transactions, and timing their attack to coincide with a legitimate business process like a real estate closing, acquisition payment, or payroll run.
- CEO fraud: Impersonating the CEO or another executive to pressure an employee into an urgent wire transfer
- Vendor impersonation: Pretending to be a known vendor with updated payment instructions
- Account compromise: Using a legitimately compromised email account to redirect payments or collect credentials from business partners
- Payroll diversion: Convincing HR to update direct deposit information to an attacker-controlled account
Why Technical Controls Alone Are Not Enough
A BEC attack conducted through a legitimately compromised account passes through email filters, anti-malware systems, and even multi-factor authentication checks for the email itself. The attack vector is trust, the recipient trusts the email because it appears to come from a legitimate source they know. Technical controls reduce risk but cannot eliminate it. Human detection ability is the last line of defense.
How Social Engineering Testing Addresses BEC
Grid32's phishing and vishing assessments include BEC-style scenarios, impersonation of executives, urgency manipulation, and pretexts designed to elicit wire transfers or credential disclosure. These tests measure your employees' ability to recognize and report suspicious requests under realistic conditions. The results directly identify which employees and which processes are most vulnerable, enabling targeted training and process improvements such as out-of-band verification requirements for wire transfers.
Recovering From a BEC Incident
If a fraudulent wire has gone out, speed matters more than anything. Contact your bank immediately to attempt a recall, report the fraud to law enforcement, and preserve the email evidence rather than deleting it. Then investigate whether the account was truly compromised or merely spoofed, because a compromised mailbox often hides forwarding rules that maintain the attacker's access. Testing and hardening email afterward, along with out-of-band payment verification, prevents the repeat attempt that frequently follows.
Frequently Asked Questions
What is business email compromise (BEC)?
Business email compromise is a scam in which attackers compromise or spoof a trusted email account to trick employees into wiring funds or sharing sensitive data. It relies on deception rather than malware, which makes it hard for technical controls alone to stop.
How do BEC attacks work?
Attackers gain access to or impersonate an executive, vendor, or partner, study communication patterns, then send urgent payment or data requests at the right moment. The messages look legitimate because they come from real or convincing accounts.
How does social engineering testing address BEC?
Testing simulates BEC scenarios to reveal whether employees verify requests and follow payment procedures under pressure. It exposes the process and awareness gaps attackers exploit, so they can be fixed before a real loss occurs.
Test your human defenses against BEC.
Grid32's social engineering assessments include BEC-style scenarios targeting your financial and administrative staff, the people attackers specifically try to deceive.
Get a Quote →