Glossary

What is business email compromise (BEC)?

Business email compromise (BEC) is a fraud in which an attacker impersonates, or takes over, a trusted business email account, such as a supplier, executive or colleague, to trick staff into sending money or sensitive data.

Also known as
BEC, CEO fraud, invoice fraud
Channel
Email, sometimes followed by phone or chat
Typical goal
Redirected payments or sensitive data
Related term
Spear-phishing

How it works

A trusted inbox,
a changed account number.

  1. 01

    Access or imitate

    The attacker compromises a real mailbox, or registers a look-alike domain for a supplier or executive.

  2. 02

    Watch

    With access, they read threads to learn invoice cycles, names and tone.

  3. 03

    Request

    A message asks to change bank details, pay an urgent invoice, buy gift cards or send payroll data.

  4. 04

    Cash out

    Money goes to an account the attacker controls, often before anyone notices.

How to defend against it

Verify every change
out of band.

Because BEC often carries no malicious link, filters may not catch it. The strongest control is a process: any change to payment details is confirmed by phone on a number you already hold.

CHECKLIST

Before you pay

  • Is this a change to bank or payment details?
  • Does the domain exactly match previous emails?
  • Have I called the requester on a known number?
  • Is someone asking me to bypass approval?
  • Have I reported it to security and finance?

General guidance; follow your organisation’s payment policy.

Questions buyers ask

Frequently asked questions.

What is the difference between BEC and phishing?

Phishing usually relies on a malicious link or attachment sent widely. BEC is targeted and often has neither: it relies on a believable request from a trusted business contact.

What is CEO fraud?

CEO fraud is a type of BEC where the attacker poses as a senior leader and asks an employee to make an urgent payment or share sensitive information.

Why is BEC hard to detect?

Messages may come from a genuine but compromised account, or a near-identical domain, and contain no malware. Detection depends heavily on people and verification processes.

Let’s connect the dots

See the human risk.
Change what happens next.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo