Business Email Compromise (BEC) is a sophisticated form of cybercrime where attackers target organisations, employees, or business partners through deceptive email communications. Unlike traditional cyberattacks that depend on malware or code, BEC uses social engineering. It primarily relies on impersonation to push victims to transfer funds. It also aims to obtain sensitive data or surrender credentials.
Despite BEC attacks not needing a password or password guessing, they remain financially devastating. They are a significant threat to organisations small and large. In these schemes, cybercriminals gain access to a corporate email account or spoof (impersonate) a trusted identity to send urgent, legitimate-looking requests.
Here is a breakdown of how Business Email Compromise works, the common tactics threat attackers employ, and practical steps organisations can take to protect themselves.
BEC is Thriving
According to recent statistics from the Australian Signals Directorate (ASD) and the National Anti-Scam Centre (NASC), email-based deception is not just growing – it is thriving. While other forms of cyber fraud have begun to plateau or decline due to increased public awareness, payment redirection losses climbed to a staggering $166.8 million, representing a 9.3% year-on-year increase.
Today, email compromise accounts for over one-third (34%) of all business cybercrime reports nationwide. This includes both BEC with immediate financial extraction (15%) and credential-harvesting compromises (19%) that lay the groundwork for future attacks.
BEC is Cyber-born Fraud
BEC is a perfect example of technology-enabled fraud (often referred to as cyber-enabled or cyber-born fraud) as addressed under the Australian Standard AS 8001:2021 Fraud and Corruption Control.
AS 8001:2021 mandates that organisations must plan to prevent, detect, and respond to external “cyber-born” attacks. To satisfy the strict minimum requirements of AS 8001:2021, organisations must meet ‘shall’ statements. They align their fraud control systems with security frameworks like ISO/IEC 27001 (Information Security Management Systems). This involves implementing technical and operational hurdles specifically designed to break the BEC attack chain.
How Does Business Email Compromise Work?
At its core, BEC relies on research, deception, and authority. The process typically unfolds through a sequence of calculated steps:
- Target Selection and Intelligence Gathering: The attacker selects an organisation and gathers intelligence on key personnel, often key decision-makers, executives, or finance staff. They map out company structure, vendor relationships, and standard administrative routines using public data, social media, or compromised company directories. They may make assumptions where data is missing, e.g. assuming there is an accounts@company.com email in use.
- Establishing the Foothold or Spoof: The attacker either compromises a legitimate employee email account (via phishing or credential harvesting) or sets up a look-alike domain (such as company-group.com instead of company.com).
- Executing the Deception: The attacker sends a carefully structured email designed to generate immediate compliance. The communication often carries an urgent tone such as an urgent wire transfer request, a sudden update to vendor banking details, or an immediate demand for tax records. More recently, the communication starts with a softer tone or simple request to first build rapport.
- Exfiltration or Financial Transfer: Once the recipient acts on the instructions, funds are diverted into attacker-controlled accounts or sensitive internal data is exposed.

Ultimately, the success of a Business Email Compromise attack hinges not on breaking security, but on exploiting human behaviour and organisational trust. Because attackers carefully mimic standard operational routines, these emails often appear entirely legitimate to busy employees. Understanding this multi-step progression is the first crucial step toward identifying subtle red flags before an unauthorised transfer or data breach occurs.
Types of BEC Attacks
Cybercriminals tailor BEC attacks depending on their objectives and the access they possess. Common variations include:
CEO Fraud / Executive Impersonation
The attacker impersonates a senior executive (such as a CEO or CFO) and emails an employee in finance or HR. The email typically requests an urgent wire transfer or confidential data transfer for an time-sensitive transaction or confidential acquisition. This may even be from a Gmail account timed to coincide when a C-level staff member is away on leave.
Account Compromise (Email Account Takeover)
Instead of spoofing a domain, the attacker gains full control of an internal employee’s actual email account. Using this legitimate email address, they send requests for payments, distribute malicious links to internal colleagues, or alter vendor routing details directly from a genuine mailbox.
Vendor Email Compromise (Invoice Schemes)
Attackers target established supply-chain relationships. By posing as a recognised vendor or contractor, the attacker informs the company of a “change in banking details” and requests that upcoming invoice payments be directed to a fraudulent account. This method is especially dangerous as the attacker has access to previous communication, processes and identifiers (such as vendor account ID). Often, a vendor will not even know they have been compromised as the victim’s account is still accessible as normal.
Data and Credential Harvesting
Not all BEC attacks demand direct money transfer. Many target HR or administrative staff to request W-2 forms (USA) or Single Touch Payroll (STP) in Australia, Personally Identifiable Information (PII), or system credentials, which are later monetised on secondary markets or used for broader network intrusion.
Why Do Cybercriminals Love BEC?
Attackers heavily utilise Business Email Compromise due to several distinct advantages:
- Extremely High Financial Return: Directing a single corporate wire transfer can net attackers hundreds of thousands or millions of dollars in a single operation. According to data from the FBI Internet Crime Complaint Centre (IC3), BEC consistently ranks among the costliest of cybercrime categories, generating over US$3 billion in annual reported losses from tens of thousands of corporate victims.
- Evasion of Standard Security Filters: Many BEC emails contain no malware attachments, executable payload code, or malicious links, allowing them to pass cleanly through traditional email security filters and anti-malware software.
- Exploitation of Human Trust: BEC relies on social engineering, authority bias, and perceived urgency rather than technical exploits, exploiting established organisational processes.
- Low Entry Threshold: Due to the nature of BEC attack methods, threat actors could range from technical to non-technical. The entry level for threat actors is significantly lowered with BEC as and entire invoice fraud attack can be undertaken with zero malware or technical hacking capability.
Indicators of a Potential BEC Attack
Recognising the subtle signs of BEC is critical for preventing unauthorised data or fund transfers. They include:
- Mismatched Email Domains: Small, subtle deviations in the sender’s address (e.g., john.doe@micros0ft.com or jane@compnay.com).
- Unusual Requests for Urgency or Secrecy: Demands to bypass normal operational procedures, keep a transaction confidential, or complete a transfer immediately.
- Changes to Payment Instructions: Unsolicited requests from vendors or executives to modify bank account numbers, contact information, routing details, or payment methods.
- Replies Sent to External Addresses: An email thread where the “Reply-To” header differs from the visible sender’s domain.
- Requesting Existing Information: When a vendor asks for information they should already have. This includes the last remittance, a reminder of when payment is due, reiterating what their vendor ID is. If the vendor should already have that information, you could be providing them with identifiers to seem more legitimate in further communications.
How to Protect Your Organisation From BEC
Defending against BEC requires combining clear administrative process controls with layers of hard and soft cyber security controls:
1. Enforce Strong Email Authentication Protocols
Implement domain authentication mechanisms to block email spoofing:
- SPF (Sender Policy Framework): Specifies which mail servers are authorised to send email on behalf of your domain.
- DKIM (DomainKeys Identified Mail): Adds a cryptographic signature to outgoing emails to verify content integrity.
- DMARC (Domain-based Message Authentication, Reporting, and Conformance): Uses SPF and DKIM to instruct receiving servers how to handle unauthenticated emails from your domain.
2. Implement Strict Financial Verification Procedures
Establish multi-person authorisation policies for financial transactions, such as Dual Control. Any request to update vendor contact details, banking details or process unscheduled wire transfers should require out-of-band verification. Call the party using a verified, pre-established phone number rather than using the contact details inside the email request or searching their contact information on a website. Attackers can scrape and spoof websites to break the verification process.
3. Leverage Automated Payment Verification Systems
Technical controls like email filters try to stop fake messages, but payment verification platforms (such as Eftsure) safeguard the actual point of execution. These tools cross-check payment files against independently verified database records in real time. If a vendor’s bank details have been altered due to a compromised email account, the platform presents a warning signal, preventing the transaction before funds leave your account.
4. Deploy Multi-Factor Authentication (MFA) and Dongle Security
Ensure MFA is mandatory across all corporate email platforms and remote portals. Requiring a secondary verification factor prevents unauthorised access to mailboxes even if user passwords are compromise through phishing or secondary data breaches. Financial systems must utilise a second step in verification such as rolling-code Dongle security.
5. Provide Targeted Security Awareness Training
Regularly train employees, especially those in accounting, finance, and human resources, to identify social engineering tactics, verify suspicious requests, and recognise domain spoofing attempts. This is not your typical cyber risk awareness training. Provide specialist, targeted training that tabletops the tactics used and involve staff in problem-solving real threats.
Frequently Asked Questions
How does BEC differ from standard phishing?
Standard phishing often broadcasts generic messages to thousands of recipients simultaneously. BEC is highly targeted, research-driven, and designed to impersonate specific individuals or trusted business partners to manipulate business processes. This is better known as spear phishing. Often, targeting of C-level staff is referred to as “whaling” as they set their sights on the big fish.
Can technical email filters detect BEC attacks?
While traditional signature-based spam filters can miss BEC emails that contain only plain text, modern AI-driven email security tools analyse communication patterns, behavioural traits, domain reputation, and header anomalies to flag potential impersonation attempts. They are less common, but there are tools that exist that are successful in capturing fraudulent persuasion tactics.
What immediate steps should be taken if a BEC attack succeeds?
If a fraudulent transfer occurs, immediately contact the originating bank to request a recall or freeze on the funds. The faster this happens, the higher the chances of recovering funds. Generally speaking, the first 24-48 hours is critical. Also notify local law enforcement or cybercrime authorities (such as the FBI’s IC3, Australian Cyber Security Centre, UK National Cyber Security Centre or equivalent national reporting bodies), and audit the compromised email accounts to contain unauthorised access.
Take outs
In summary, Business Email Compromise (BEC) is primarily a process exploit that bypasses traditional technical controls by targeting human trust, organisational urgency, and executive authority.
While technical safeguards like SPF, DKIM, and DMARC are vital for preventing domain spoofing, an organisation’s strongest defence lies in strict protocols, specifically mandatory Dual Control authorisation and out-of-band phone verifications for all payment changes.
Ultimately, resilience against BEC requires a two-pronged approach: proactively hardening internal workflows to prevent attacks, alongside establishing a tested incident response framework to act swiftly in the event of a fraudulent transfer.
We can help reduce the risk
Navigating the threat of Business Email Compromise requires a balance of technical rigour, operational policy, and rapid emergency response. As a specialised cyber risk advisory firm, we partner with organisations at every stage of the BEC life cycle from proactive defence to crisis management and even post-incident review and training.
Pre-Event: Resilience & Risk Mitigation
-
BEC Readiness & Process Audits: We review your financial control workflows, authorisation hierarchies, and payment modification procedures to identify structural vulnerabilities before attackers do.
-
Email Security & DMARC Enforcement: Our technical team assesses your mail infrastructure, configures robust SPF/DKIM/DMARC policies, and deploys advanced impersonation-defence controls.
-
Pressure Testing/ Executive & Finance Threat Simulation: We design realistic, role-specific social engineering scenarios targeting high-risk teams (Finance, HR, C-Suite) to measure readiness and build practical awareness. This form of ‘pressure testing’ is recommended by AS 8001:2021 Fraud and Corruption Control.
Post-Event: Incident Response & Fund Recovery
-
Post-Incident Remediation & Board Reporting: Following an incident, we deliver comprehensive root-cause analyses, assist with regulatory and insurance reporting, implement remediation road maps to ensure long-term resilience, and provide compromise education training to key roles to prevent recurrences.
Reach out to see how we can help strengthen your email security and BEC risk exposure.