Business email compromise (BEC) is a fraud where attackers impersonate executives, colleagues or vendors in email to trick an organization into transferring money or sensitive data. It is consistently the costliest cybercrime category in the FBI's IC3 reporting, and its signature is what it lacks: usually no malware, no link, no attachment. Just a credible instruction.
Key facts
- BEC monetizes trust: the message succeeds because the sender looks right and the request sounds routine.
- Delivery relies on spoofing, lookalike domains or genuinely compromised accounts, often entered via phishing or consent phishing.
- AI has industrialized BEC: fluent multilingual messages and coherent multi-turn fraud conversations at scale.
The five classic BEC types
Vendor fraud deserves the extra paragraph: it is the hardest to spot because the thread is often real. Attackers compromise a supplier's mailbox, read invoice history, and inject new payment details into a genuine conversation. Every technical signal passes; only the behavior (new account number, subtle urgency) is wrong.
Why BEC beats filters
Traditional email security asks "does this contain something malicious?" BEC contains nothing but text. The right question is behavioral: does this instruction fit this sender, this relationship, this thread? A payment request appearing in a relationship that never discussed payments, an executive suddenly writing from a lookalike domain, a reply chain whose tone shifts, these are the detectable signals.
How to defend
Payment verification procedures that email alone cannot override (second-channel callback on known numbers, two-person approval, no urgency exceptions), DMARC enforcement so your own domain cannot be forged, training on the pretexting patterns, and behavioral email security for the impersonation and thread-hijack detection humans miss.
How Sentaro stops BEC
Sentaro's Behavioral Defense learns each organization's real communication graph: who instructs whom, how payments are discussed, which vendors use which addresses and tone. Message Defense reads intent (the urgent-confidential-payment pattern) and catches lookalike infrastructure at first contact, and App Defense closes the consent phishing route into mailbox takeover. No payload needed for detection, because the signal is the deviation. When BEC is part of a regulated compliance program, Sentaro also supplies the detection, evidence and reporting inputs your framework depends on: see Sentaro for compliance.