Business Email Compromise (BEC)
Abbreviation: BEC
Pronunciation: BIZ-nis EE-mayl KUM-pruh-myze
Also known as: Email Account Compromise, BEC
Definition
Business Email Compromise (BEC) is a fraud scheme in which attackers impersonate or compromise a trusted business email identity to redirect payments, steal information, or induce unauthorized actions. It is used to exploit established relationships and normal business processes rather than relying only on obviously suspicious messages. It differs from ordinary phishing, because BEC commonly uses targeted knowledge of executives, suppliers, invoices, payroll, or settlement routines and may originate from a genuinely compromised account.
Overview
Business Email Compromise (BEC) is a fraud scheme in which attackers impersonate or compromise a trusted business email identity to redirect payments, steal information, or induce unauthorized actions. Its operational purpose is to exploit established relationships and normal business processes rather than relying only on obviously suspicious messages. It should be considered alongside Beneficiary Name Check. The relevant distinction is ordinary phishing, because BEC commonly uses targeted knowledge of executives, suppliers, invoices, payroll, or settlement routines and may originate from a genuinely compromised account.
A typical workflow is as follows: Attackers obtain account access or spoof a trusted identity, study conversations, choose a payment moment, alter beneficiary details or instructions, and pressure staff to act. They may also create mailbox rules that hide warnings and replies.
Core controls include phishing-resistant multifactor authentication, payment-detail verification through a known channel, dual approval, mailbox monitoring, domain protections, least privilege, staff training, and rapid recall procedures.
In payment and crypto operations, Crypto addresses and bank accounts can both be substituted. Any unexpected change to beneficiary, wallet, urgency, secrecy, or payment method should trigger independent confirmation before release. Messages should state the result without overstating what it proves.
Evidence should include full message headers, mailbox audit events, login history, changed rules, invoice versions, beneficiary data, approval records, payment timestamps, recall attempts, and law-enforcement reports. Because the payment may be genuinely authorized by an employee, transaction controls must test the instruction’s authenticity, not only the user’s login session. Records should preserve sources, versions, actors, timestamps, decisions, and corrections.
A production treatment of Business Email Compromise (BEC) should test Business Email Compromise (BEC) is a fraud scheme in which attackers impersonate or compromise a trusted business email identity to redirect payments, steal information, or induce unauthorized actions within the relevant asset, decision, or service state. The Business Email Compromise context record for steal information, and induce unauthorized actions should preserve source data, configuration or policy version, responsible actor, exception, and outcome. Review of Business Email Compromise (BEC) should determine whether safeguards addressing steal information, and induce unauthorized actions changed exposure in practice, not merely whether a document or setting existed.
Key Takeaway
BEC prevention requires secure email accounts plus independent verification of changed payment instructions, especially when urgency or secrecy is introduced.
Sources
- Advisory to Financial Institutions on Email Compromise Fraud Schemes — FinCEN (2026-08-03)
- Cyber Essentials — CISA (2026-08-03)
- Instant Payments Regulation and Verification of Payee — European Central Bank (2026-08-03)