Business Email Compromise (BEC): What It Is and How to Protect Your Domain
BEC attacks cost businesses billions annually. Learn how attackers exploit email to commit fraud, and the email security measures that stop them.
What is Business Email Compromise?
Business Email Compromise (BEC) is a type of email fraud where attackers impersonate executives, vendors, or employees to trick organizations into transferring money or sensitive information. The FBI's Internet Crime Complaint Center (IC3) has consistently ranked BEC as the top cybercrime by financial losses — over $51 billion in total losses between 2013 and 2023.
Unlike phishing attacks that target many people with the same message, BEC attacks are precisely targeted and carefully researched, making them much harder to detect.
- $2.9B
- BEC losses (2023)
- $51B+
- Total BEC losses (2013–2023)
- $125,000+
- Avg loss per BEC incident
- 180+
- Countries targeted
FBI IC3 annual report — top cybercrime by financial losses
Cumulative losses across 10 years of IC3 reporting
Average wire transfer loss per successful attack
BEC attacks have been reported in over 180 countries
Common BEC attack types
CEO fraud: Attacker impersonates the CEO and emails the CFO requesting an urgent wire transfer.
Vendor invoice fraud: Attacker impersonates a supplier and sends a legitimate-looking invoice with changed payment details.
Payroll diversion: Attacker impersonates an employee and asks HR to change their direct deposit information.
Attorney impersonation: Impersonates a law firm handling a transaction, requesting funds be sent to an attacker-controlled account.
Data theft: Requests sensitive documents (W-2 forms, employee data) rather than money.
BEC attack types — indicators and defenses
| Attack Type ↕ | Who Is Impersonated ↕ | Red Flag Indicators ↕ | Key Defense ↕ |
|---|---|---|---|
| CEO fraud (wire transfer) | CEO/CFO/executive | Urgent request, 'don't tell anyone', sent when executive is traveling | Verbal confirmation via known number before any wire transfer |
| Vendor invoice fraud | Supplier or vendor | Bank details changed on otherwise legitimate invoice | Call vendor's known number to verify any payment detail changes |
| Payroll diversion | Employee in HR request | Email from personal address or slight variation, sent near payroll date | HR policy: payroll changes only via in-person or verified phone request |
| Attorney impersonation | Law firm or attorney | Urgency due to legal deadline, funds requested via wire only | Verify attorney identity via official firm contact information |
| Data theft | Executive or IT admin | W-2/HR data request, often before tax season | No sensitive data sent via email; verify requests through official channels |
| Account takeover | Compromised real account | Slightly unusual language, requests from known contact | DMARC won't help — use MFA, email security gateway scanning |
How BEC attacks bypass traditional security
BEC attacks often don't use malware, phishing links, or attachments — the things traditional security tools look for. They rely purely on social engineering: a convincing email requesting an action that seems legitimate.
Many BEC attacks come from: - Compromised legitimate email accounts (no spoofing at all) - Lookalike domains that bypass SPF/DKIM/DMARC - Display name spoofing that fools casual readers
Technical defenses against BEC
DMARC p=reject: Stops exact domain spoofing completely. Your domain cannot be impersonated in the From: header if DMARC is enforced.
Email authentication monitoring: Continuous monitoring of SPF, DKIM, and DMARC status. If authentication breaks, you're vulnerable.
Lookalike domain monitoring: Register common misspellings of your domain and monitor for new registrations of similar names.
Inbound email security: Use email gateways that flag external emails impersonating internal domains, add [EXTERNAL] banners, and analyze sender patterns.
Process controls: Verify large transfers through a second channel (phone call to a known number). Wire transfer requests via email alone should never be acted on without verbal confirmation.
Check your domain's email health
Run a free scan against 60 blacklists. Validate SPF, DKIM, DMARC, and MX records in seconds.
Related free tools