What Is Business Email Compromise (BEC)?

Business email compromise is a fraud scheme that uses impersonation or a compromised communication channel to redirect a business action or payment.

Business email compromise, or BEC, is a fraud scheme that uses impersonation or a compromised communication channel to redirect a business action or payment. The message may appear to come from an executive, supplier, employee or trusted adviser and often relies on urgency or secrecy.

Which requests are common?

  • Changing supplier bank details
  • Sending an urgent wire or advance payment
  • Buying gift cards or releasing payroll data
  • Redirecting an invoice or customer receipt
  • Sharing credentials or sensitive documents

How should a suspicious request be handled?

  1. Pause the requested payment or record change.
  2. Preserve the message and associated metadata.
  3. Verify through a previously established contact channel.
  4. Review account access and related transactions.
  5. Escalate under the incident and fraud procedure.
  6. Notify financial institutions promptly if funds moved.

Why is email confirmation insufficient?

An attacker may control the sender’s mailbox or a lookalike domain and can reply within the same conversation. Verification should use an independent channel and known contact information, not phone numbers supplied in the change request.

What preventive controls help?

Use strong authentication, domain protection, restricted bank-detail changes, separation of duties, payment limits and staff training. Monitor for mailbox rules, unusual logins and last-minute changes to beneficiary information.

Related Terms