Glossary
What is business email compromise (BEC)?
Business email compromise (BEC) is a fraud in which an attacker impersonates, or takes over, a trusted business email account, such as a supplier, executive or colleague, to trick staff into sending money or sensitive data.
- Also known as
- BEC, CEO fraud, invoice fraud
- Channel
- Email, sometimes followed by phone or chat
- Typical goal
- Redirected payments or sensitive data
- Related term
- Spear-phishing
How it works
A trusted inbox,
a changed account number.
- 01
Access or imitate
The attacker compromises a real mailbox, or registers a look-alike domain for a supplier or executive.
- 02
Watch
With access, they read threads to learn invoice cycles, names and tone.
- 03
Request
A message asks to change bank details, pay an urgent invoice, buy gift cards or send payroll data.
- 04
Cash out
Money goes to an account the attacker controls, often before anyone notices.
How to defend against it
Verify every change
out of band.
Because BEC often carries no malicious link, filters may not catch it. The strongest control is a process: any change to payment details is confirmed by phone on a number you already hold.
Before you pay
- Is this a change to bank or payment details?
- Does the domain exactly match previous emails?
- Have I called the requester on a known number?
- Is someone asking me to bypass approval?
- Have I reported it to security and finance?
General guidance; follow your organisation’s payment policy.
Questions buyers ask
Frequently asked questions.
What is the difference between BEC and phishing?
Phishing usually relies on a malicious link or attachment sent widely. BEC is targeted and often has neither: it relies on a believable request from a trusted business contact.
What is CEO fraud?
CEO fraud is a type of BEC where the attacker poses as a senior leader and asks an employee to make an urgent payment or share sensitive information.
Why is BEC hard to detect?
Messages may come from a genuine but compromised account, or a near-identical domain, and contain no malware. Detection depends heavily on people and verification processes.
Let’s connect the dots
See the human risk.
Change what happens next.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo