Skip to content
All Articles
Email Security

Business Email Compromise (BEC): What It Is and How to Protect Your Domain

BEC attacks cost businesses billions annually. Learn how attackers exploit email to commit fraud, and the email security measures that stop them.

6 min read

What is Business Email Compromise?

Business Email Compromise (BEC) is a type of email fraud where attackers impersonate executives, vendors, or employees to trick organizations into transferring money or sensitive information. The FBI's Internet Crime Complaint Center (IC3) has consistently ranked BEC as the top cybercrime by financial losses — over $51 billion in total losses between 2013 and 2023.

Unlike phishing attacks that target many people with the same message, BEC attacks are precisely targeted and carefully researched, making them much harder to detect.

$2.9B
BEC losses (2023)

FBI IC3 annual report — top cybercrime by financial losses

$51B+
Total BEC losses (2013–2023)

Cumulative losses across 10 years of IC3 reporting

$125,000+
Avg loss per BEC incident

Average wire transfer loss per successful attack

180+
Countries targeted

BEC attacks have been reported in over 180 countries

Common BEC attack types

CEO fraud: Attacker impersonates the CEO and emails the CFO requesting an urgent wire transfer.

Vendor invoice fraud: Attacker impersonates a supplier and sends a legitimate-looking invoice with changed payment details.

Payroll diversion: Attacker impersonates an employee and asks HR to change their direct deposit information.

Attorney impersonation: Impersonates a law firm handling a transaction, requesting funds be sent to an attacker-controlled account.

Data theft: Requests sensitive documents (W-2 forms, employee data) rather than money.

BEC attack types — indicators and defenses

Attack TypeWho Is ImpersonatedRed Flag IndicatorsKey Defense
CEO fraud (wire transfer)CEO/CFO/executiveUrgent request, 'don't tell anyone', sent when executive is travelingVerbal confirmation via known number before any wire transfer
Vendor invoice fraudSupplier or vendorBank details changed on otherwise legitimate invoiceCall vendor's known number to verify any payment detail changes
Payroll diversionEmployee in HR requestEmail from personal address or slight variation, sent near payroll dateHR policy: payroll changes only via in-person or verified phone request
Attorney impersonationLaw firm or attorneyUrgency due to legal deadline, funds requested via wire onlyVerify attorney identity via official firm contact information
Data theftExecutive or IT adminW-2/HR data request, often before tax seasonNo sensitive data sent via email; verify requests through official channels
Account takeoverCompromised real accountSlightly unusual language, requests from known contactDMARC won't help — use MFA, email security gateway scanning

How BEC attacks bypass traditional security

BEC attacks often don't use malware, phishing links, or attachments — the things traditional security tools look for. They rely purely on social engineering: a convincing email requesting an action that seems legitimate.

Many BEC attacks come from: - Compromised legitimate email accounts (no spoofing at all) - Lookalike domains that bypass SPF/DKIM/DMARC - Display name spoofing that fools casual readers

Technical defenses against BEC

DMARC p=reject: Stops exact domain spoofing completely. Your domain cannot be impersonated in the From: header if DMARC is enforced.

Email authentication monitoring: Continuous monitoring of SPF, DKIM, and DMARC status. If authentication breaks, you're vulnerable.

Lookalike domain monitoring: Register common misspellings of your domain and monitor for new registrations of similar names.

Inbound email security: Use email gateways that flag external emails impersonating internal domains, add [EXTERNAL] banners, and analyze sender patterns.

Process controls: Verify large transfers through a second channel (phone call to a known number). Wire transfer requests via email alone should never be acted on without verbal confirmation.

Check your domain's email health

Run a free scan against 60 blacklists. Validate SPF, DKIM, DMARC, and MX records in seconds.