Attack Techniques

Business email compromise (BEC)

Fraud that uses a compromised or spoofed business email account to redirect a payment.

Business email compromise (BEC) is fraud that uses a compromised or convincingly spoofed business email account to redirect a payment that the organisation was already expecting to make. There is usually no malware and no exploited software flaw. The attacker changes who gets paid, and the finance process does the rest.

It is the most expensive pattern in this library. Across the documented cases here, BEC and its close variants account for more disclosed loss than any other technique, including several eight- and nine-figure single incidents.

How the attack runs

The sequence is consistent across cases, and each step is a point where it could be interrupted.

  1. Selection. The attacker identifies an organisation that makes large outbound payments and an employee who can initiate them.
  2. Access or imitation. Either a real mailbox is compromised, or a convincing imitation is set up. Compromise is more dangerous because the attacker can read genuine correspondence first.
  3. Observation. Real invoices, real vendors and real payment timing are studied so the fraudulent request matches what the recipient expects.
  4. The request. A payment instruction arrives, usually changing bank details or asking for an urgent transfer, framed as routine or confidential.
  5. Pressure and cover. Urgency, seniority, or a confidentiality demand discourages the recipient from checking through another channel.
  6. Payout. Funds move, often split across several transfers to complicate recovery.

Documented cases

Every case below is recorded in this library with sources.

How it differs from related techniques

CEO fraud is a subtype in which the impersonated party is a senior executive. Invoice fraud redirects a specific expected payment rather than inventing an instruction from above. W-2 phishing uses the same spoofed-executive method but targets employee tax records instead of money. Ordinary phishing is broader and usually aims at credentials or malware rather than a single large transfer.

The control that would have stopped it

Across these cases the same small number of checks recur in the defence analysis:

  • Out-of-band verification. Any change to bank details, and any unusual transfer, confirmed by calling a number sourced independently rather than one supplied in the message.
  • Dual authorisation above a threshold, with no exemption for seniority. Several of these losses required only one person to act.
  • Treat confidentiality demands as an escalation trigger. In Ubiquiti, Scoular and Tecnimont the secrecy was the mechanism that prevented normal checking.
  • Per-transaction caps, so a scheme cannot be split into tranches that each clear individually.
  • Vendor bank-detail changes handled as a controlled process with a verification step, not as an email request.

Mattel is the useful counter-example. In its 2015 case, $3M left the company on a forged email from a brand-new CEO, but the money was recovered because the transfer was identified quickly and the receiving jurisdiction cooperated. Speed of detection changed the outcome.

Explore more

Related techniques and attack types

Parent attack type