Business Email Compromise, commonly known as BEC, is a category of social-engineering attacks that targets trusted business relationships to obtain money or sensitive information.
What does a BEC attack look like?
An attacker may impersonate an executive, accountant, supplier or business partner. The message is often designed to look like an ordinary business request.
Common BEC scenarios
- Requests to change bank details
- Urgent wire-transfer requests
- Fraudulent invoices
- Confidential requests supposedly from executives
- Requests for employee or customer data
BEC may contain no malware
A dangerous aspect of BEC is that the message may contain no malicious attachment or link at all. The attack may rely entirely on social engineering.
How can companies reduce the risk?
Critical payment instructions should be verified through a second channel, employees should understand phishing and spoofing, and mailbox security should be monitored.
Compromised real accounts
Some BEC incidents use a legitimate employee mailbox that has already been compromised, making fraudulent messages much more convincing.
If you suspect compromise, read What to Do If a Business Email Account Is Compromised.