← Glossary

Business Email Compromise

Business Email Compromise (BEC) is fraud where attackers impersonate executives, colleagues or vendors in email to trick an organization into transferring money or sensitive data. It is consistently the costliest cybercrime category the FBI's IC3 reports.

Updated

Business email compromise (BEC) is a fraud where attackers impersonate executives, colleagues or vendors in email to trick an organization into transferring money or sensitive data. It is consistently the costliest cybercrime category in the FBI's IC3 reporting, and its signature is what it lacks: usually no malware, no link, no attachment. Just a credible instruction.

Key facts

  • BEC monetizes trust: the message succeeds because the sender looks right and the request sounds routine.
  • Delivery relies on spoofing, lookalike domains or genuinely compromised accounts, often entered via phishing or consent phishing.
  • AI has industrialized BEC: fluent multilingual messages and coherent multi-turn fraud conversations at scale.

The five classic BEC types

Vendor fraud deserves the extra paragraph: it is the hardest to spot because the thread is often real. Attackers compromise a supplier's mailbox, read invoice history, and inject new payment details into a genuine conversation. Every technical signal passes; only the behavior (new account number, subtle urgency) is wrong.

Why BEC beats filters

Traditional email security asks "does this contain something malicious?" BEC contains nothing but text. The right question is behavioral: does this instruction fit this sender, this relationship, this thread? A payment request appearing in a relationship that never discussed payments, an executive suddenly writing from a lookalike domain, a reply chain whose tone shifts, these are the detectable signals.

How to defend

Payment verification procedures that email alone cannot override (second-channel callback on known numbers, two-person approval, no urgency exceptions), DMARC enforcement so your own domain cannot be forged, training on the pretexting patterns, and behavioral email security for the impersonation and thread-hijack detection humans miss.

How Sentaro stops BEC

Sentaro's Behavioral Defense learns each organization's real communication graph: who instructs whom, how payments are discussed, which vendors use which addresses and tone. Message Defense reads intent (the urgent-confidential-payment pattern) and catches lookalike infrastructure at first contact, and App Defense closes the consent phishing route into mailbox takeover. No payload needed for detection, because the signal is the deviation. When BEC is part of a regulated compliance program, Sentaro also supplies the detection, evidence and reporting inputs your framework depends on: see Sentaro for compliance.

Questions we get asked.

What does BEC mean?

Business email compromise: fraud where attackers impersonate trusted people or companies in email to obtain money transfers or sensitive data, usually without any malware.

What is the difference between BEC and phishing?

Phishing is the broad family of deceptive messages; BEC is its most targeted, payload-free form aimed at payments and data. Many BEC attacks begin with phishing that compromises the account they then abuse.

How much money is lost to BEC?

Billions of dollars annually according to the FBI's IC3 annual reports, which have ranked BEC among the costliest cybercrime categories for years.

Can email filters detect BEC?

Payload-based filters largely cannot, because there is nothing malicious to scan. Detection requires behavioral analysis: sender authenticity, relationship history and the intent of the request.

What should we do if we already paid a BEC invoice?

Contact your bank immediately to attempt recall, report to police and (in the US) the FBI's IC3, preserve the emails as evidence, and check whether a mailbox compromise is still active before attackers strike again.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.