Business Email Compromise (BEC), explained
Business Email Compromise is phishing that skips the malware and goes straight for the money. Instead of a mass campaign, BEC is a targeted con: an attacker poses as someone you trust and asks for a transfer, an invoice payment, or sensitive data. It is one of the costliest forms of cybercrime, precisely because it looks so ordinary.
The common forms
- CEO fraud — a message "from the CEO" demanding an urgent, confidential wire transfer.
- Invoice fraud — a real supplier relationship hijacked to change the bank details on an invoice.
- Account compromise — a genuine mailbox is taken over and used to make requests from a trusted address.
- Lookalike domains — a near-identical domain (a swapped letter) used to impersonate a colleague or vendor.
Why it works
BEC exploits authority, urgency and routine. A junior employee is unlikely to question the CEO; a finance team processes invoices all day. The request fits the normal flow of work, so it does not trigger suspicion — and by the time anyone double-checks, the money is gone.
BEC rarely contains a malicious link to scan. The attack is the message itself, which is why email authentication and process controls matter more than any filter.
How to defend
- Lock down your domain with SPF, DKIM and DMARC so attackers can't spoof your real address.
- Verify out of band — confirm payment and bank-detail changes by a known phone number, never by replying to the email.
- Watch for lookalike domains impersonating your company and your key suppliers.
- Train the money-movers — finance and leadership are the real targets.
Phish Plug monitors for lookalike domains that impersonate your organisation and its partners — a core ingredient of BEC — and helps take them down before they are used.
The takeaway
BEC is social engineering aimed at the people who move money. The defence is equal parts technical and procedural: authenticate your domain, verify requests out of band, and watch for the lookalike domains that make impersonation convincing.
Keep reading
Related articles
Spear phishing vs. mass phishing: what's the difference?
One is a net, the other a spear. How targeted spear phishing differs from mass campaigns, why it works, and what defences actually apply to each.
Read article Threats · 6 minWhaling: phishing that targets the executives
Whaling aims at leadership, where one approval moves money. How executive-targeted phishing works and the controls that stop a convincing impersonation.
Read article Threats · 6 minClone phishing: when a real email comes back poisoned
Clone phishing copies a legitimate message and swaps the link or attachment. Why the familiarity makes it dangerous and how to recognise and stop it.
Read articleProtect your brand from impersonation
Run a free clone check on one domain — Phish Plug proves the cloaking and builds the takedown case for you.