BEC is the costliest attack in email, and the emptiest: no malware, no link, just a credible instruction from the wrong person. Sentaro detects the impersonation itself, in Microsoft 365 and Google Workspace, payload or not.
A typical BEC message would pass any payload scanner ever built, because there is no payload. The attack is pure social engineering delivered as routine correspondence: the “CFO” needing an urgent transfer, the supplier with new bank details in a genuine invoice thread. Filters ask “does this contain something malicious?” and the honest answer is no. The right question is “does this instruction fit this sender, this relationship, this thread?” and answering it requires knowing what normal looks like.
The engine builds a live picture of each organization’s communication graph: who instructs whom, how payments are actually discussed, which addresses, devices and tones belong to which relationships. The Message vector reads intent, recognizing the urgent-confidential-payment pattern and its variants in any language. The Identity vector catches the infrastructure side: lookalike domains, newly registered senders, spoofing that slips past authentication. The verdict weighs all of it, so fraud is caught by its deviation, not its content.
The classic whaling play: an instruction “from” leadership to finance staff, timed for quarter close or the executive’s travel. Sentaro knows the executive’s real sending patterns and flags the impostor, whether the address is spoofed, lookalike or a display-name trick.
The hardest BEC to spot: a real supplier thread, real invoice history, and new bank details injected by an attacker inside the vendor’s compromised mailbox. Every technical signal passes. Sentaro flags the behavioral break: payment details changing in a relationship whose pattern never included such changes, and tone or timing shifts mid-thread.
“Update my direct deposit before payday”, sent as an employee to HR. Sentaro evaluates whether the request fits the claimed sender’s history and infrastructure, not just whether the name matches.
BEC rarely starts with the payment ask. It starts with clean smalltalk, “Are you at your desk?”, which builds trust while showing filters nothing. Intent analysis recognizes the pretexting pattern early, including the channel-switch attempts that move fraud off monitored ground.
Every flagged attempt comes with its reasoning: what deviated, from which baseline, with what confidence. That serves the immediate decision, and it doubles as the incident documentation your reporting duties may require: an internal post-mortem, or a regulatory clock under NIS2 or DORA.
Coverage compared
| Native filtering | Secure email gateway | Sentaro | |
|---|---|---|---|
| Payload-free payment fraud | Limited | No | Core strength |
| Lookalike domain detection | Partial | Partial | Yes, at first contact |
| Compromised vendor threads | No | No | Yes: behavioral break detection |
| Display-name and reply-to tricks | Partial | Partial | Yes, with relationship context |
| Internal mail after account takeover | Limited | No | Yes |
| Learns your payment communication patterns | No | No | Yes |
Phishing usually carries something malicious to click. BEC carries only trust: an impersonated sender and a fraudulent instruction. That is why payload-based defenses miss it and behavioral detection is required.
Yes. When the mailbox is genuine but the behavior breaks pattern, with new bank details, changed tone or unusual urgency in a relationship with an established history, the deviation itself is the signal.
No, and it should not. Callback verification and dual approval remain essential controls. Sentaro reduces how often they are your last line, and catches the attempts that never reach a human decision.
Yes. DMARC prevents exact forgery of your own domain and protects your brand toward others. Sentaro covers what DMARC cannot: lookalike domains, display-name tricks and compromised real accounts. They are complements.
Four minutes, via API connection to Google Workspace or Microsoft 365. Relationship-aware detection uses existing mailbox history to establish baselines quickly rather than requiring a long learning period.
The message is removed or flagged according to policy, finance- and HR-facing lookalikes can be blocked domain-wide, and the full reasoning and evidence trail is available for follow-up and reporting.
Connect Google Workspace or Microsoft 365 in four minutes and behavioral BEC protection starts immediately.