
You receive an email from your CEO.
“Can you process this payment today? It’s urgent.”
The email address looks right. The writing sounds like them. The conversation even fits something your company is currently working on.
So you make the payment.
Except your CEO never sent the email.
This is the basic idea behind Business Email Compromise (BEC)—a cyberattack designed to exploit trust rather than simply exploit software.
And it is far from a minor problem.
The FBI recorded more than 305,000 BEC incidents and approximately$55.5 billion in exposed losses between October 2013 and December 2023.
More recently, Microsoft observed approximately 10.7 million BEC attacks during Q1 2026 alone. Interestingly, 82–84% of the initial BEC messages Microsoft observed were generic messages such as “Are you at your desk?” rather than obvious requests for money.
That tells us something important:
BEC doesn't always start with a suspicious email. Sometimes, it starts with a normal conversation.
Business Email Compromise is a form of social engineering in which attackers impersonate or compromise a trusted person, organization, or business email account to manipulate someone into taking an action that benefits the attacker.
That action could be:
The attacker doesn't necessarily need to break into your entire network.
Sometimes, they only need access to one mailbox and enough information to sound convincing.
A successful BEC attack is rarely just one malicious email. It can be a process.

Before contacting anyone, attackers may study your website, LinkedIn profiles, social media accounts, company announcements, organizational structure, vendors, executives, and publicly available documents.
They are looking for answers to simple questions:
Who approves payments?
Who reports to whom?
Who works with which vendors?
When are invoices normally paid?
The more they know, the more believable their story becomes.
There are two common approaches.
Account compromise:
The attacker obtains legitimate credentials through phishing, credential theft, malware, password reuse, or other techniques.
Impersonation:
The attacker creates a lookalike email address or domain and pretends to be someone the victim trusts.
Compromised credentials are particularly dangerous because they can provide legitimate access to business systems. Verizon's 2025 DBIR found compromised credentials were an initial access vector in 22% of the breaches it reviewed.
This is where BEC can become difficult to detect.
If an attacker has compromised a legitimate mailbox, they may not immediately send a fraudulent request.
They can first observe:
The attacker is essentially learning how your business communicates.
Now comes the manipulation.
For example:
“I'm travelling today. Please use the new bank details attached for this invoice.”
Or:
“We're closing this acquisition today. Please send the requested documents to our legal team.”
Or:
“I'm in a meeting. Can you handle this payment urgently?”
The request doesn't necessarily look malicious.
It looks normal enough to act on.
The employee sends the money, changes the bank details, shares the documents, or provides the requested information.
At that point, the attacker has achieved the objective without needing to deploy ransomware or exploit a critical vulnerability.
BEC comes in several forms, and attackers often combine multiple techniques.

The attacker pretends to be the CEO, CFO, director, or another senior executive.
The objective is usually to pressure an employee into making a payment, sharing information, or bypassing normal procedures.
The classic tactic is urgency:
“I need this done immediately.”
An attacker impersonates an existing supplier and requests that future payments be sent to a new bank account.
This can be especially effective because the employee may already be expecting an invoice.
The invoice itself might look legitimate.
The bank account is the part that has changed.
An attacker impersonates an employee and requests that their salary be redirected to a different bank account.
HR and finance teams can become targets because they regularly handle sensitive employee information and financial instructions.
Instead of creating a fake identity, the attacker compromises a real business email account.
This can be much more convincing because messages are coming from a legitimate account and may appear inside existing conversations.
Attackers may impersonate lawyers, auditors, regulators, banks, business partners, or other trusted authorities.
The goal is to create a sense of legitimacy and urgency.
An attacker registers a domain that resembles the organization's legitimate domain.
For example:
Real: company.com
Lookalike: cornpany.com
A small visual difference can be surprisingly effective when someone is reading quickly.
This is also why domain protection cannot stop at configuring your own email infrastructure. Your organization should also know when suspicious domains are impersonating your brand.
Email security tools are important.
But BEC is fundamentally a trust problem.
A message can contain:
…and still be malicious.
Consider an attacker who has compromised a legitimate employee account.
The email is technically coming from the correct mailbox.
The problem isn't necessarily:
“Is this email real?”
The better question is:
“Is this request legitimate?”
That distinction matters.
Employees should be trained to slow down when an email involves unusual or sensitive actions.
Watch for:
Especially requests involving large amounts, new accounts, or unusual payment methods.
A vendor suddenly requesting a new bank account should always trigger independent verification.
Words such as:
should increase scrutiny rather than reduce it.
Attackers may use domains or addresses that look almost identical to legitimate ones.
For example, an executive asking an employee to skip an established approval process.
Unexpected locations, devices, authentication events, or account behavior can indicate account compromise.
Credentials, financial records, employee information, customer data, contracts, or internal documents should never be shared simply because the request appears to come from a familiar person.
There is no single tool that eliminates BEC risk.
You need layers.

Passwords alone are not enough.
CISA recommends that organizations use phishing-resistant MFA wherever possible, particularly for accounts such as email, administrative accounts, and other sensitive systems.
Prioritize:
Where supported, phishing-resistant methods such as FIDO/WebAuthn provide stronger protection against credential phishing than traditional authentication methods.
Email authentication controls help organizations reduce domain spoofing.
SPF helps specify which servers are authorized to send email for your domain.
DKIM adds a cryptographic signature that helps verify message authenticity.
DMARC allows organizations to define how receiving mail systems should handle messages that fail authentication.
But remember:
DMARC does not stop someone from registering a completely different lookalike domain.
That's why email authentication should be combined with external domain and brand monitoring.
This is one of the simplest and most effective controls.
If someone requests:
verify the request through a separate communication channel.
Don't reply to the same email and ask:
“Did you really send this?”
If the mailbox is compromised, the attacker can simply answer:
“Yes.”
Call the person using a known phone number.
Your security shouldn't depend on whether one employee notices something suspicious.
Create rules for:
For high-value transactions, consider requiring multiple approvals.
Your organization should know what normal account behavior looks like.
Monitor for:
Early detection can significantly reduce the amount of time an attacker has to operate inside a compromised account.
Credentials stolen through phishing or infostealer malware can eventually become an entry point into business systems.
CISA recommends considering credential monitoring services that identify compromised credentials.
Businesses should know whether employee credentials associated with corporate accounts have appeared in known leaks or other exposed sources.
Annual cybersecurity training is not enough.
Employees should regularly encounter realistic examples of:
The objective isn't to make employees paranoid.
It is to build the habit of stopping and verifying before acting.
Security controls should not only exist on paper.
Organizations can assess their security posture through activities such as:
A penetration test won't magically prevent someone from sending money to a fraudulent account. But it can uncover weaknesses in the systems, applications, authentication controls, and access paths that attackers may exploit to gain a foothold.
The goal is simple:
Find the weaknesses before an attacker does.
Speed matters.
If money has already been transferred, immediately contact the relevant financial institution and request a recall or fraud investigation where applicable.
Then:
Do not assume that changing one password means the incident is over.
If an attacker had access to the mailbox, they may have learned enough about your business to attempt another attack later.
Before assuming your organization is protected, ask:
Identity
Finance
People
External Exposure
Testing
If several answers are “No,” your organization probably has work to do.
Business Email Compromise sits at the intersection of identity, social engineering, email security, human behavior, and financial controls.
That's why buying another email security tool isn't necessarily the complete answer.
Your organization needs to think about the entire attack path.
An attacker may start with a leaked credential.
Then compromise an account.
Then observe internal conversations.
Then impersonate a trusted person.
Then manipulate an employee.
Then move money.
Every layer is an opportunity to stop the attack.
The strongest defense is therefore not one product or one policy.
It is a combination of strong authentication, secure systems, employee awareness, continuous monitoring, clear verification procedures, and regular security testing.
Because when an attacker sends an email, the real target isn't your inbox.
It's your trust.
Cybersecurity shouldn't begin after an incident.
A proper security assessment can help identify vulnerabilities, exposed systems, weak configurations, authentication weaknesses, and other attack paths before they become an incident.
Cynical Technology helps businesses assess and strengthen their security through VAPT, penetration testing, vulnerability disclosure programs, bug bounty programs, and other security services.
Find the weakness before someone else does.
Talk to Cynical Technology about your organization's security posture.
Business Email Compromise is a cyberattack where criminals impersonate or compromise a trusted person or business email account to trick victims into transferring money, sharing sensitive information, or performing another unauthorized action.
Not exactly. Phishing is commonly used to steal credentials or information, while BEC focuses on impersonation or account compromise to manipulate business processes, payments, or sensitive information. The two techniques can overlap.
MFA can significantly reduce the risk of account compromise, but it does not eliminate BEC. Phishing-resistant MFA provides stronger protection against credential phishing, while business processes and employee verification controls help address fraudulent requests that may still reach users.
No. SPF, DKIM and DMARC help protect against certain forms of email spoofing, but they do not prevent all BEC attacks—particularly attacks involving compromised legitimate accounts or separately registered lookalike domains.
Look for unusual login activity, unfamiliar devices, unexpected forwarding rules, suspicious sent messages, password-reset notifications, or other account behavior you cannot explain. A proper investigation should also review authentication and mailbox logs.
Yes. The FBI states that BEC continues to target organizations ranging from small local businesses to large corporations.
Contact your bank or financial institution immediately and request a fraud investigation or transfer recall where possible. Then secure the affected accounts, investigate the compromise, preserve evidence, and report the incident through the appropriate channels.
Penetration testing does not directly stop fraudulent email requests. However, it can uncover vulnerabilities in applications, authentication mechanisms, access controls, and other systems that could contribute to account compromise or broader attacks.