How BEC works
The attacker either takes over a real email account, often through phishing or a stolen password, or uses a lookalike domain. They study ongoing conversations and then send a well timed request: a change of bank details on a pending invoice, an urgent transfer for a confidential deal, or a request for employee tax data.
Common variants
CEO fraud impersonates an executive asking finance for an urgent payment. Supplier invoice fraud impersonates a vendor with new bank details. Payroll fraud asks HR to redirect an employee's salary.
Why it is so damaging
BEC messages often contain no malware or links, so email filters rarely catch them. BEC is consistently among the most costly types of cybercrime reported to the FBI.
How to prevent it
Confirm any change of bank details or unusual payment through a separate, known channel. Enforce MFA on email accounts. Configure SPF, DKIM and DMARC to make domain spoofing harder. Train finance and HR teams on the specific patterns.




