BEC (Business Email Compromise): Prevention Strategies

Among cyberattacks carried out through email, Business Email Compromise, or BEC, remains a significant and widespread threat. It causes billions of dollars in financial losses to organizations around the world. This article explains the essential aspects of BEC, including what it is and how organizations can protect against it.

What is a Business Email Compromise?

Business Email Compromise (BEC) is a form of cybercrime in which fraudulent email activity is used to target organizations.

It commonly involves attackers obtaining access to a corporate email account and then using that account to manipulate the company, its employees, or its business partners into transferring money or disclosing sensitive information.

Unlike large-scale phishing campaigns, BEC attacks are typically highly targeted. They often require extensive research into the organization being targeted.

50%

Of cybercrime losses
are due to BCE

6+

Months
Average Recovery Time after a BEC attack

65%

Increase
BEC attacks over the past five years

Types of Business Email Compromise

Business Email Compromise can take several different forms. The most common types are outlined below.

CEO Fraud

In CEO fraud, also referred to as executive impersonation, attackers pretend to be the company’s CEO or another senior executive. They contact employees, most often members of the finance department, and instruct them to urgently transfer funds or provide sensitive information. These messages often take advantage of the authority associated with senior management and create a strong sense of urgency.

Example: An attacker may impersonate the CEO and email the CFO, asking for an immediate wire transfer to a designated account to complete a high-value business transaction.

Account Compromise

This form of BEC occurs when a legitimate corporate email account is compromised.

Attackers obtain access to an employee’s email account through phishing or other techniques. They then use the compromised account to send fraudulent messages.

Because these emails are sent from a trusted account, they are more likely to pass through security controls and appear legitimate to recipients.

Example: An attacker may take control of an employee’s email account and use it to send payment requests to customers. The requested payments are then redirected to a bank account controlled by the attacker.

Invoice Scams

In invoice scams, attackers pose as legitimate vendors or suppliers and send fraudulent invoices to the company’s accounts payable team.

The message may originate from a spoofed email address or from a compromised supplier account. It typically instructs the organization to send payments to a new bank account controlled by the attacker.

Example: A company receives an email that appears to come from a long-standing supplier and states that the supplier’s banking details have changed for future payments. The company updates its records and sends the next payment to the attacker-controlled account.

Attorney Impersonation

In this type of attack, cybercriminals pose as attorneys or legal representatives and often refer to confidential or urgent legal matters. The messages typically target senior executives or finance staff and use legal terminology to create a sense of importance and urgency.

Example: An attacker pretending to be an attorney may contact the CFO and claim to be handling a confidential acquisition. The message then requests an immediate payment to secure the transaction.

Data Theft

Although many BEC attacks are designed to steal money, others are intended to obtain sensitive information. This may include employee records, financial data, or intellectual property. The stolen information may later be used in additional attacks or sold on the black market.

Example: An attacker compromises the HR director’s email account and sends messages requesting employees’ tax documents and personal information. The collected data may then be used for identity theft or sold to other criminals.

How Business Email Compromise Works

Business Email Compromise attacks typically unfold through a sequence of stages that together form a carefully designed social engineering operation.

Most BEC attacks follow the process outlined below:

  1. Research: Attackers collect information about the target organization and its employees, often relying on publicly available sources such as LinkedIn, corporate websites, and social media platforms. This information helps them create convincing and highly targeted messages.
  2. Initial Contact: Attackers use phishing, spoofing, or similar techniques to establish initial contact. The objective is usually to compromise an email account or create a line of communication that appears legitimate.
  3. Account Compromise: If the attempt succeeds, attackers gain access to a legitimate email account. This allows them to send messages that are more likely to bypass security filters and attract less suspicion from recipients.
  4. Execution: Attackers send fraudulent messages either from the compromised account or from spoofed email addresses. These messages may request wire transfers, sensitive information, or changes to payment details. They often rely on urgency and perceived authority to encourage rapid action without sufficient verification.
  5. Monetization: After the fraudulent request is fulfilled, attackers quickly transfer the stolen funds through multiple accounts, which makes recovery more difficult. If sensitive information has been obtained instead, it may be sold on the black market or used to support additional attacks.
  6. Cover-up: Attackers may remove sent messages or configure email forwarding rules to hide their activity. These actions can delay detection of the compromise and allow the attackers to remain unnoticed for longer.

Business Email Compromise Techniques

Business Email Compromise can involve multiple techniques that may be used separately or in combination. Their purpose is generally to take control of legitimate accounts or impersonate real individuals, often people in positions of authority.

Credential Harvesting Phishing Attacks

Phishing is a common technique for obtaining initial access to an employee’s email account.

Attackers send deceptive messages designed to appear as though they originate from legitimate sources. The goal is to persuade recipients to open malicious attachments or click harmful links.

These links often direct recipients to fraudulent login pages, where email credentials are entered without realizing that the page is fake.

Spoofing

Email spoofing involves falsifying the sender’s email address so that the message appears to originate from a trusted source within the target organization or from an associated party.

This method can make a fraudulent message appear legitimate and increase the likelihood that recipients will follow its instructions without questioning its authenticity.

Attackers can use several techniques to create this effect. These include altering domain extensions, creating domain doppelgangers, registering lookalike domains, and using typosquatting. Such methods are intended to make a fraudulent address appear close enough to a legitimate one that the difference may go unnoticed.

Malware

Malware is another technique used to compromise email accounts. Common examples include keyloggers, remote access trojans (RATs), and infostealers.

These malicious programs may be delivered through email attachments or links. Once installed on a victim’s device, they can record keystrokes, steal authentication credentials, and give attackers remote access to the system.

Social Engineering

More broadly, social engineering extends beyond phishing, which is one email-based form of social engineering.

It involves manipulating individuals into taking specific actions or revealing confidential information.

BEC attackers often conduct extensive research on their targets before creating fraudulent messages. This allows them to exploit trust, authority, and urgency more effectively.

Warning Signs of BCE

Business Email Compromise can be especially difficult to detect when attackers have taken control of a legitimate email account. Even so, several warning signs can indicate that a BEC attack may be taking place.

Unusual Requests

BEC messages often include requests that fall outside normal business procedures.

These can include sudden or unexpected instructions to transfer money, requests for confidential information, or demands to update payment details.

Email Anomalies

Messages used in BEC attacks often contain subtle irregularities that may reveal their fraudulent nature to attentive recipients.

Such signs can include minor misspellings in the sender’s email address, unusual wording or tone, and unexpected links or attachments.

Unexpected Urgency

Attackers frequently create a strong sense of urgency to pressure recipients into acting before verifying whether the request is legitimate.

These messages may stress the need for immediate action, refer to opportunities that are available only for a limited time, or warn of serious consequences if the request is not completed quickly.

Verification Failures

BEC messages may attempt to bypass the standard verification procedures an organization normally applies to sensitive transactions.

This can include instructions to disregard established processes or continue the conversation through channels that are not normally used.

Abnormal Communication Patterns

A message that differs from the sender’s usual communication style or arrives at an unusual time may indicate a BEC attack.

Possible warning signs include emails sent outside normal working hours, an unusual level of urgency, or wording and tone that do not match the sender’s typical behavior.

Real-World Examples

Toyota Boshoku Corporation (2019)

Toyota Boshoku Corporation, a Toyota Group subsidiary, became the victim of a BEC scheme in which attackers impersonated a company executive. An employee was then instructed to transfer a large sum of money to a fraudulent account.

The company lost approximately $37 million as a result of the scheme.

The attackers used social engineering to collect information about the company’s financial processes and executive team. This allowed them to create a convincing email that succeeded in bypassing standard verification procedures.

Facebook і Google (2013-2015)

A Lithuanian cybercriminal posed as a hardware supplier and sent fraudulent invoices to Facebook and Google over a two-year period. Because the invoices appeared legitimate, both companies transferred funds to accounts controlled by the attacker.

The scheme caused combined losses of more than $100 million.

The attacker took advantage of the existing business relationship between the companies and their supplier. Carefully prepared emails and fraudulent invoices were designed to match the format and details of genuine transactions.

Ubiquiti Networks (2015)

Ubiquiti Networks, a technology company, was targeted in an attack in which cybercriminals gained access to an employee’s email account. They then used that access to initiate unauthorized international wire transfers.

The company reported losses of $39 million from the attack.

The employee’s email account was compromised through phishing, which allowed the attackers to send fraudulent wire transfer requests that appeared to originate from inside the organization. The absence of two-factor authentication and weaknesses in the company’s verification procedures contributed to the success of the attack.

Impact of Business Email Compromise

As with other types of cyberattacks, a successful Business Email Compromise incident can affect an organization in several different ways.

Financial Losses

The most immediate and measurable consequence of Business Email Compromise (BEC) is financial damage.

Organizations may suffer substantial losses through fraudulent wire transfers, falsified invoices, and unauthorized changes to account or payment information.

The financial impact may extend beyond the original loss. Additional costs can include recovery expenses, legal fees, and higher insurance premiums.

Reputational Damage

Incidents, as such, can cause serious harm to an organization’s reputation.

When customers, business partners, and other stakeholders become aware of a security breach, confidence in the organization’s ability to safeguard sensitive information may decline.

This erosion of trust can result in fewer business opportunities, customer loss, and damage to the company’s brand reputation.

Operational Disruption

BEC attacks can interfere with normal business operations in several ways.

Responding to the incident, investigating the compromise, and implementing corrective measures can require substantial time and resources. This may divert attention away from core business activities.

In addition, affected systems may need to be taken offline for remediation, creating further disruption to day-to-day operations.

Legal and Regulatory Consequences

Organizations affected by BEC may also face legal and regulatory consequences.

Depending on the nature of the incident and the type of data that was compromised, companies may be exposed to fines, penalties, or legal claims. Requirements under data protection frameworks such as GDPR, CCPA, or industry-specific regulations may also result in increased regulatory scrutiny and mandatory incident reporting.

Psychological and Emotional Impact

Employees involved in a BEC incident, particularly those who were manipulated through social engineering, may experience considerable stress and anxiety.

Concerns about potential consequences, along with feelings of guilt or embarrassment, can negatively affect employee morale and productivity.

Prevention and Protection Strategies

A defense-in-depth approach is particularly important for reducing the risk of BEC. Effective protection depends on combining multiple security strategies and defensive layers rather than relying on a single control.

Employee training

Employees often serve as an important first line of defense against BEC attacks.

Training programs should explain the common methods used in BEC schemes, teach employees how to identify suspicious email messages, and emphasize the need to verify requests involving sensitive information or financial transactions.

Effective programs should combine theoretical instruction with practical exercises, including phishing simulations and phishing tests.

  • Regular Training Sessions: Provide recurring training to keep employees informed about current BEC techniques and relevant prevention measures.
  • Phishing Simulations: Run phishing simulation exercises to assess and strengthen employees’ ability to recognize phishing emails, including scenarios that reproduce BEC techniques.
  • Awareness Campaigns: Use posters, newsletters, and email communications to reinforce recommended security practices and remind employees of common warning signs.

Email Security Measures

Technical security controls can substantially lower the risk of BEC by detecting and blocking suspicious messages before they reach employee inboxes.

Key tools and technologies include:

  • Email Filtering: Deploy advanced email filtering technologies to identify and block phishing messages, spoofed sender addresses, and malicious attachments.
  • Multi-Factor Authentification (MFA): Enforce MFA for email accounts to introduce an additional security layer. This makes unauthorized access more difficult even when attackers obtain valid login credentials.
  • Domain-Based Message Authentification, Reporting, and Conformance (DMARC): Apply DMARC policies to reduce the risk of email spoofing by validating whether incoming messages originate from authorized sources.

Verification Processes

Strong verification procedures for financial transactions and requests involving sensitive information can help prevent BEC attempts from succeeding.

Key procedures include the following:

  • Dual Authorization: Require two-person approval for significant financial transactions so that each request is independently reviewed and authorized by at least two individuals.
  • Out-of-Band Verification: Confirm requests for sensitive information or financial transfers through a separate communication channel, such as a phone call, to verify that the request is legitimate.
  • Vendor Management: Regularly review and update vendor contact details. Establish formal procedures for confirming changes to payment information through trusted contacts.

Incident Response Plans

A clearly defined incident response plan helps organizations respond to BEC attacks quickly and effectively, reducing both the potential damage and the time required for recovery.

Key components include the following:

  • Detection and Reporting: Define clear procedures for identifying and reporting suspected BEC incidents. Employees should be encouraged to report suspicious messages or unusual activity without delay.
  • Containment and Eradication: Establish specific actions for containing the incident, including isolating compromised accounts and affected systems. Any malware or unauthorized access should also be identified and removed.
  • Investigation and Recovery: Perform a detailed investigation to determine the extent of the attack, identify affected systems and data, and implement the necessary recovery measures.
  • Communication: Prepare a communication plan for informing relevant stakeholders, including employees, customers, business partners, and regulatory authorities, about the incident and the actions being taken in response.

Request for free Arsen trial

Leave your contact details, and we will get in touch with you



    Subscribe to news