Fraud that uses a compromised or spoofed business email account to redirect a payment.
Business email compromise (BEC) is fraud that uses a compromised or convincingly spoofed business email account to redirect a payment that the organisation was already expecting to make. There is usually no malware and no exploited software flaw. The attacker changes who gets paid, and the finance process does the rest.
It is the most expensive pattern in this library. Across the documented cases here, BEC and its close variants account for more disclosed loss than any other technique, including several eight- and nine-figure single incidents.
The sequence is consistent across cases, and each step is a point where it could be interrupted.
Every case below is recorded in this library with sources.
CEO fraud is a subtype in which the impersonated party is a senior executive. Invoice fraud redirects a specific expected payment rather than inventing an instruction from above. W-2 phishing uses the same spoofed-executive method but targets employee tax records instead of money. Ordinary phishing is broader and usually aims at credentials or malware rather than a single large transfer.
Across these cases the same small number of checks recur in the defence analysis:
Mattel is the useful counter-example. In its 2015 case, $3M left the company on a forged email from a brand-new CEO, but the money was recovered because the transfer was identified quickly and the receiving jurisdiction cooperated. Speed of detection changed the outcome.