Social Engineering & FraudMANIPULATIVE

Business Email Compromise (BEC)

What it is

A fraud in which an attacker uses a compromised or spoofed business email account to redirect legitimate payments, typically by changing the bank details on a real invoice or requesting a plausible transfer.

How it works

Business email compromise rarely involves malware and often involves no claim the victim could easily check. The attacker either takes over a real mailbox (through a phished password) or registers a lookalike domain, then reads existing threads to learn who pays whom, for how much, and in what tone. The fraudulent message is inserted into a genuine transaction: the same invoice number, the same amounts, the same signature block, with only the bank account changed. Because everything else is true, the recipient's consistency check ("this matches what I expected") does the attacker's work. Real-estate closings, tuition payments, and long-standing supplier relationships are favored because large transfers are routine there. The FBI logged more than 21,000 BEC complaints and about 2.9 billion dollars in reported losses for 2023 alone, and estimated cumulative exposed losses above 50 billion dollars for the decade to 2022, making it the costliest cybercrime category after investment fraud.

Real-world examples

  • Between 2013 and 2015 a Lithuanian man, Evaldas Rimasauskas, induced Facebook and Google to pay more than 100 million dollars against forged invoices in the name of a real Taiwanese hardware supplier; he pleaded guilty in 2019.
  • Homebuyers have lost entire down payments after receiving "updated wiring instructions" from what looked like their title company days before closing; the message arrived inside a thread the attacker had been quietly reading.
  • In 2019 Toyota Boshoku, a Toyota subsidiary, reported a loss of roughly 37 million dollars after staff acted on fraudulent payment instructions that appeared to come from a business partner.
  • Vendor email compromise reverses the direction: the attacker hijacks a supplier's mailbox and emails all of that supplier's customers with new bank details, harvesting many victims from a single intrusion.

Historical case studies

The $120 million fake-vendor invoices paid by two technology companies

2013–2015Corporate Fraud

Evaldas Rimasauskas of Lithuania registered a company in Latvia with the same name as a real Asian hardware manufacturer that did business with two large US internet companies, since identified in press reports as Facebook and Google. He then emailed their accounts departments forged invoices, contracts and letters, and staff wired more than $120 million to his bank accounts in Latvia and Cyprus. He was extradited, pleaded guilty to wire fraud, and was sentenced to five years in prison in 2019. The targets employed some of the best security staff in the world; the attack went through accounts payable.

Source →

The FBI's "$55 billion scam" tally

2013–2023Law Enforcement Data

The FBI's Internet Crime Complaint Center counted 305,033 reported business email compromise incidents worldwide between October 2013 and December 2023, with exposed losses of about $55.5 billion. The typical case involves a spoofed or hijacked email account of an executive, supplier, lawyer or title company asking for a routine payment to be sent to new bank details. The Bureau notes that the scam keeps adapting, moving into real-estate closings, payroll diversion and cryptocurrency, while the underlying request stays the same: an authoritative voice asking for a normal transfer under time pressure.

Source →

Ethical guidelines

  • BEC is wire fraud and usually money laundering; there is no legitimate version.
  • Organizations that process payments owe their counterparties reasonable verification controls; skipping them to save time shifts the loss onto the victim.
  • Banks and payment providers should build friction into first-time payees and changed bank details rather than treating speed as the only measure of service.

How to defend against it

  • Any change to a payee's bank details is confirmed by phone to a number on file from before the change, never a number in the email requesting it; a two-minute call is the entire defense.
  • For a large one-time transfer (a home purchase, tuition, a deposit), call the recipient using a number from the original contract, read back the account number, and send a small test amount before the balance.
  • Enable MFA on business email and review mailbox forwarding rules regularly; attackers commonly add a silent rule that forwards or hides messages containing "invoice" or "payment".
  • If money has already moved, call your bank immediately and ask for a recall, then file at ic3.gov; the FBI's Financial Fraud Kill Chain can sometimes freeze international wires reported within about 72 hours.
  • Publish DMARC, DKIM, and SPF records for your own domain so that spoofed mail from "you" fails at the recipient's gateway.

From the Defense Playbook

Out-of-Band Verificationminutes

Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.

The Callback Ruleminutes

When anyone contacts you claiming to be your bank, a government agency, a utility, or a company you deal with, hang up and call back on the number printed on your card, statement, or the organization's official website, never the number they gave you.

Gift Cards Mean Scamseconds

Treat any demand to pay a debt, fine, fee, bail, or "security deposit" with gift cards, cryptocurrency, a wire to a stranger, a payment app, or cash handed to a courier as proof of fraud, because no legitimate institution collects money that way.

Tell Someone Before You Send Moneyminutes

Before sending money or sharing account details in response to any unexpected request, describe the situation out loud to one person who is not involved, because scams depend on the target deciding alone.

Verify, Then Trust (for Authority Claims)minutes

Separate the symbols of authority (a title, a uniform, a badge, a confident tone, an official-looking letterhead) from the fact of authority, and check the fact through a source the claimant does not control before you comply.

Multi-Factor Authentication and Passkeysminutes

Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Federal Bureau of Investigation, Internet Crime Complaint Center (2024). Internet Crime Report 2023. FBI IC3 · link
    21,489 BEC complaints and adjusted losses above 2.9 billion dollars in 2023; BEC ranked among the costliest crime types.
  2. Federal Bureau of Investigation, Internet Crime Complaint Center (2023). Business Email Compromise: The $50 Billion Scam (Public Service Announcement I-060923-PSA). FBI IC3 · link
    Cumulative exposed losses of more than 50 billion dollars from October 2013 to December 2022, reported in all 50 states and 177 countries.
  3. Mitnick, K. D., & Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. Wiley
    Foundational account of how attackers insert themselves into routine business processes so that fraudulent requests look ordinary.
Last reviewed
Suggest a correction

Detect Business Email Compromise (BEC) in any text

Paste any message, email, or article into our free Manipulation Detector to see if Business Email Compromise (BEC) or other techniques are being used on you.

Related Articles