Business Email Compromise (BEC)
What it is
A fraud in which an attacker uses a compromised or spoofed business email account to redirect legitimate payments, typically by changing the bank details on a real invoice or requesting a plausible transfer.
How it works
Real-world examples
- •Between 2013 and 2015 a Lithuanian man, Evaldas Rimasauskas, induced Facebook and Google to pay more than 100 million dollars against forged invoices in the name of a real Taiwanese hardware supplier; he pleaded guilty in 2019.
- •Homebuyers have lost entire down payments after receiving "updated wiring instructions" from what looked like their title company days before closing; the message arrived inside a thread the attacker had been quietly reading.
- •In 2019 Toyota Boshoku, a Toyota subsidiary, reported a loss of roughly 37 million dollars after staff acted on fraudulent payment instructions that appeared to come from a business partner.
- •Vendor email compromise reverses the direction: the attacker hijacks a supplier's mailbox and emails all of that supplier's customers with new bank details, harvesting many victims from a single intrusion.
Historical case studies
Ethical guidelines
- ●BEC is wire fraud and usually money laundering; there is no legitimate version.
- ●Organizations that process payments owe their counterparties reasonable verification controls; skipping them to save time shifts the loss onto the victim.
- ●Banks and payment providers should build friction into first-time payees and changed bank details rather than treating speed as the only measure of service.
How to defend against it
- ►Any change to a payee's bank details is confirmed by phone to a number on file from before the change, never a number in the email requesting it; a two-minute call is the entire defense.
- ►For a large one-time transfer (a home purchase, tuition, a deposit), call the recipient using a number from the original contract, read back the account number, and send a small test amount before the balance.
- ►Enable MFA on business email and review mailbox forwarding rules regularly; attackers commonly add a silent rule that forwards or hides messages containing "invoice" or "payment".
- ►If money has already moved, call your bank immediately and ask for a recall, then file at ic3.gov; the FBI's Financial Fraud Kill Chain can sometimes freeze international wires reported within about 72 hours.
- ►Publish DMARC, DKIM, and SPF records for your own domain so that spoofed mail from "you" fails at the recipient's gateway.
From the Defense Playbook
Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.
When anyone contacts you claiming to be your bank, a government agency, a utility, or a company you deal with, hang up and call back on the number printed on your card, statement, or the organization's official website, never the number they gave you.
Treat any demand to pay a debt, fine, fee, bail, or "security deposit" with gift cards, cryptocurrency, a wire to a stranger, a payment app, or cash handed to a courier as proof of fraud, because no legitimate institution collects money that way.
Before sending money or sharing account details in response to any unexpected request, describe the situation out loud to one person who is not involved, because scams depend on the target deciding alone.
Separate the symbols of authority (a title, a uniform, a badge, a confident tone, an official-looking letterhead) from the fact of authority, and check the fact through a source the claimant does not control before you comply.
Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Federal Bureau of Investigation, Internet Crime Complaint Center (2024). Internet Crime Report 2023. FBI IC3 · link21,489 BEC complaints and adjusted losses above 2.9 billion dollars in 2023; BEC ranked among the costliest crime types.
- Federal Bureau of Investigation, Internet Crime Complaint Center (2023). Business Email Compromise: The $50 Billion Scam (Public Service Announcement I-060923-PSA). FBI IC3 · linkCumulative exposed losses of more than 50 billion dollars from October 2013 to December 2022, reported in all 50 states and 177 countries.
- Mitnick, K. D., & Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. WileyFoundational account of how attackers insert themselves into routine business processes so that fraudulent requests look ordinary.
Related Articles
Social Engineering: Why Smart People Fall for It
Social engineering does not target stupidity. It targets helpfulness, deference, and time pressure, which are the same habits that make people good at their jobs. Here is how the attacks are built and which procedures actually stop them.
The Disinformation Playbook: How Campaigns Are Built and Where They Break
Disinformation campaigns follow a recognizable sequence: seed, launder, amplify, and let real people carry it the rest of the way. A field guide to the stages, drawn from the research, with the defences that work at each one.