Business Email Compromise (BEC)
Business Email Compromise (BEC) is the term for fraudulent emails that deliberately exploit trust in order to obtain payments, sensitive data or access. Unlike classic malware campaigns, BEC attacks often work without a malicious attachment. Instead, attackers rely on identity misuse, spoofed senders, pressuring language and realistic business contexts – and thereby frequently target finance departments, executive management or supplier communication.
Typical forms are CEO fraud (supposed instructions from management), invoice fraud with changed bank details, payroll diversion and the takeover of ongoing conversations (thread hijacking). Unlike classic phishing, BEC emails usually contain neither links nor attachments and are therefore hardly detectable for signature-based filters. A special form is vendor email compromise, in which compromised supplier accounts are misused.
Effective defense combines several layers: authentication standards such as SPF, DKIM and DMARC make sender spoofing more difficult, behavioral and language analyses detect atypical payment requests, defined approval processes secure financial transactions, and trained employees question unusual requests. Because BEC frequently begins with taken-over accounts, protection is also closely linked to Identity Security.