GlossarySecurity awareness

BEC

Short answer

BEC (Business Email Compromise) is a fraud in which attackers impersonate or take over the email account of an executive, employee or supplier to trick someone into making a payment or sharing sensitive data. It includes what is often called CEO fraud.

How BEC works

The attacker either takes over a real email account, often through phishing or a stolen password, or uses a lookalike domain. They study ongoing conversations and then send a well timed request: a change of bank details on a pending invoice, an urgent transfer for a confidential deal, or a request for employee tax data.

Common variants

CEO fraud impersonates an executive asking finance for an urgent payment. Supplier invoice fraud impersonates a vendor with new bank details. Payroll fraud asks HR to redirect an employee's salary.

Why it is so damaging

BEC messages often contain no malware or links, so email filters rarely catch them. BEC is consistently among the most costly types of cybercrime reported to the FBI.

How to prevent it

Confirm any change of bank details or unusual payment through a separate, known channel. Enforce MFA on email accounts. Configure SPF, DKIM and DMARC to make domain spoofing harder. Train finance and HR teams on the specific patterns.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub