← Back to Scams

Business Email Compromise (BEC)

Unlike many cyberattacks that rely on technical vulnerabilities, BEC primarily exploits human psychology and trust. Scammers research their targets carefully so their emails look as legitimate as possible. It remains one of the costliest crimes reported to the FBI, accounting for more than $3 billion in losses in 2025.

How Business Email Compromise Works:

  • Identity Research: Scammers identify key personnel and understand organizational hierarchies using public info like LinkedIn.
  • Impersonation: Attackers alter sender names (Email Spoofing), register lookalike domains (Domain Mimicry), or hack legitimate accounts.
  • Social Engineering: Scammers use urgency, confidentiality, authority, and emotional appeal to induce immediate action without verification.

Common Types of BEC Scams:

  • CEO Fraud: The attacker poses as a high-ranking executive requesting an urgent wire transfer to a fraudulent account.
  • Fake Invoice Scams: The attacker impersonates a legitimate vendor and requests a change in bank account details for recurring payments.
  • Account Compromise: An employee's email account is hacked and used to send fraudulent requests to internal staff, vendors, or customers.
  • Data Theft: Attackers target sensitive company data, such as employee PII or W-2 forms, to sell on the dark web.
  • Real Estate Wire Fraud: The most devastating version for individuals. Criminals monitor a compromised mailbox at a title company, law firm, or realtor's office, then email the buyer revised wiring instructions days before closing. The buyer sends their entire down payment to the scammer. Always call the title company on a number you looked up yourself, never one from the email, and confirm the wire details verbally before sending anything.
  • Deepfake Video Authorization: When a suspicious employee asks to verify a request in person, attackers now supply the meeting. Victims have joined routine-looking video calls with a synthetic "CFO" and several fake colleagues, all AI-generated, and approved transfers on the strength of seeing familiar faces. See AI Deepfake & Voice Cloning Scams.

How to Protect Yourself:

  • Implement Strong Technical Controls: Use Email Authentication Protocols (DMARC, SPF), Multi-Factor Authentication (MFA), and Advanced Email Security Solutions.
  • Establish Strict Procedures: Enforce dual-approval processes for all financial transactions. Always verify unexpected payment requests using an out-of-band communication method (like a known phone number).
  • Never accept a video call as proof of identity: A face and a voice can both be synthesized in real time. Verification has to happen on a separate channel you initiated, using a number from your own directory.
  • Treat every change of bank details as hostile until proven otherwise: A request to update account numbers is the single highest-risk email a finance team receives. Verify it by phone, every time, with no exceptions for urgency or seniority.
  • Continuous Training: Conduct regular phishing simulations and train employees to spot urgency, secrecy, and mismatched email addresses.

Where to Report It

Report scams even if you didn't lose money. Every report helps investigators spot patterns and warn others.

  • FBI Internet Crime Complaint Center (IC3): ic3.gov
  • Federal Trade Commission: reportfraud.ftc.gov
  • AARP Fraud Watch Network Helpline: 877-908-3360