Infosecurity Europe
8-10 June 2027
Excel London

Business email compromise: A practical guide for preventing costly email fraud

Business Email Compromise (BEC) attacks are one of the most financially damaging forms of cybercrime which impact organisations today.

According to the FBI’s Internet Crime Complaint Center (IC3), the total sum lost to BEC attacks which targeted firms in the US during 2025 amounted to $3bn (£2.25bn).

To put that figure in perspective, the report said that during the same period, financial loss attributed to ransomware attacks was $12.5m ($9.35m).

Ransomware attacks typically receive more attention because of the noticeable impact they have. They are fundamentally noisy. They disrupt online and in-person services, sometimes to the extent that large organizations must cease production

Meanwhile, BEC attacks - also known as BEC scams - are far stealthier and that’s by design. An organisation which falls victim to a successful BEC attack might not even by aware of what has happened until sometime later.

Even if the organisation realises what has happened almost immediately, by then it is already too late, because the money has already been lost. 

Types of BEC Attack

A Business Email Compromise attack (BEC attack) is a type of phishing attack where cybercriminals impersonate a business executive, a colleague or other professional contact of the victim, and use social engineering to manipulate them into making a financial transfer with a legitimate looking request.

Some common examples of what BEC attacks can look like include:

CEO Fraud

Attackers pose as the CEO or another high-level company executive and email a real person within that firm requesting an urgent financial transaction must be made, often claiming that time is of the essence to ensure a business transaction is fulfilled.

The attacker will ask the target to transfer the funds – which could potentially be millions of dollars – into a bank account they control. With CEO fraud attacks, cybercriminals use social engineering and psychology to manipulate the target into doing what they want because the victim will be reluctant to ignore what looks like a request from senior management.

False Invoice Fraud

Invoice fraud is a form of BEC attack in which the attacker poses as a legitimate supplier of the organization they are targeting. The fraudster sends an invoice which requests payment for services rendered, with instructions on how to transfer the money into an account owned by the attackers.

Sometimes the attackers will simply try their luck, relying on how paying invoices is a common task for financial departments. Other times, they will put additional planning into the scheme, especially if they have compromised email accounts of a supplier, posing as a known individual to the victim and requesting the payment be made to a ‘new address.’

Account Compromise Fraud

Many instances of BEC scams see fraudsters spoof personas and email addresses to manipulate victims into transferring funds. However, these attempts can sometimes be blocked by DMARC and other anti-phishing protections which recognise the spoofed email address as illegitimate.

Cybercriminals get around this by hijacking legitimate business accounts, commonly via stealthy phishing attacks. With these, they have access to the real accounts of real users, and it is common for the fraudsters to monitor the user, their business relationships and the type of transactions they are responsible for to ensure their own fraudulent attempt is as convincing as possible.

With this information, they can send an email as the real invoice sender but use their out their own account details in place of the legitimate information.

It’s also known for attackers to hijack email threads regarding a real business transaction with their own invoice. Either way, if the invoice is paid, the money is gone, lost to the business and now set for laundering by the attacker.

Why BEC Attacks Are So Successful

BEC attacks are lucrative for cybercriminals because they target people, not technology. People can be prone to manipulation, especially if the request is coming from an authority figure and claims to be urgent.

Preventing BEC attacks is particularly challenging because they often appear indistinguishable from the legitimate requests, transactions and business communications employees handle every day.

AI and BEC Attacks

The rise of AI applications and services has created additional challenges around defending against BEC attacks. Cybercriminals can use large language models (LLMs) to tailor messages that look legitimate and mimic the tone of any individual they are posing as.

It is even possible for fraudsters to use AI deepfake audio and video to make live calls to victims, requesting that a transfer is made. CEOs and other executives are public facing figures, meaning scammers can find real footage of them online and use this to create convincing deepfakes. If an employee thinks their boss is on the phone and asking them to do something, they may find it difficult to decline the request. 



How to Defend Against BEC Attacks

The nature of BEC attacks means that they can be difficult to defend against, but there are steps which organizations can take to help employees avoid falling victim.

Training is a key component of BEC prevention. Employees should be taught to recognize common warning signs that a request may be fraudulent, such as messages sent from an unfamiliar email address or requests containing new banking details. Extra caution should be exercised when such requests are unexpected or accompanied by a sense of urgency.

Verifying if a request is real and if the account sending the request is legitimate can be difficult. In this case, employees should be encouraged to verify if the request is real by contacting the requester via separate channel. For example, if the request comes via email, the employee should contact the requester via phone or another method to double check if the request is legitimate. If it is not, it should be reported to the security team.

AI-generated deepfakes add another layer of complexity to BEC defense. To counter this threat, organizations should establish verification procedures that confirm the identity of anyone making sensitive requests. These can include the use of pre-agreed code words or challenge-response questions that only the genuine individual would be able to answer. Such measures helped an executive at Ferrari identify and thwart an attempted BEC scam.

Conclusion

The reason BEC attacks are so successful is because at their core, they are fundamentally simple for cybercriminals to carry out. Unlike ransomware or malware attacks, they do not require specific tools – almost any fraudster with a laptop and an internet connection can fire off malicious emails.

However, while BEC attacks are designed to take advantage of humans, with the right guidance, people can also be provided with the information they need to detect and protect against BEC attacks. 


Enjoyed this article? Make sure to share it!



Looking for something else?