BEC

What Is Business Email Compromise (BEC)?

Business Email Compromise is fraud that impersonates a trusted contact to trick someone into making a payment or sharing data. Here is how it works.

What Is Business Email Compromise (BEC)?

Business Email Compromise, usually shortened to BEC, is a type of fraud where an attacker impersonates a trusted figure inside or connected to an organization, typically an executive, supplier, or finance contact, in order to trick an employee into making a payment, sharing data, or changing account details.

Unlike traditional phishing, BEC rarely involves malware or a suspicious link. The email often looks ordinary. It may come from a lookalike domain, a compromised real account, or a spoofed address, and it relies almost entirely on convincing language, urgency, and a plausible business reason for the request.

A typical BEC attempt might involve a message that appears to come from the CEO asking finance to process an urgent wire transfer, or a fake supplier email requesting a change to bank details ahead of an upcoming invoice. Because these messages mimic normal business communication so closely, they are difficult for email filters to catch and depend heavily on employee judgment to stop.

BEC is consistently one of the costliest forms of cybercrime, precisely because it targets people and process rather than technical vulnerabilities. Verification steps for payment changes and a culture where employees feel comfortable double-checking unusual requests are the strongest practical defenses.