What Is Business Email Compromise?

    Subscribe to our newsletter

    By submitting this form, you agree to the Allure Security privacy policy.

    Share Article

    Illustration of a Microsoft Outlook business email inbox with a warning symbol representing Business Email Compromise (BEC), vendor impersonation, phishing, and email fraud.

    Business email compromise is the most financially damaging form of cybercrime the FBI tracks, and every successful attack depends on the same mechanism: borrowing the identity of someone the target already trusts.

    Business email compromise, commonly referred to as BEC, is a targeted form of social engineering in which an attacker impersonates a trusted figure, typically an executive, a vendor, or a legal representative, to trick an employee into authorizing a wire transfer, redirecting a payment, or disclosing sensitive information. Unlike mass phishing campaigns that cast a wide net with generic lures, BEC operations are researched, patient, and specific. The attacker studies the target organization’s leadership, vendor relationships, payment cycles, and communication norms before sending a single message, and that message often contains no malicious links or attachments at all. It reads like a routine business email because the attacker has spent weeks making sure it does.

    The financial scale of BEC is difficult to overstate. The FBI’s Internet Crime Complaint Center attributed more than $55 billion in cumulative losses to BEC since 2013, with losses exceeding $3 billion in 2025 alone. Arctic Wolf’s 2025 Threat Report found that BEC accounted for 27% of all incident response cases the firm handled, and that phishing was the root cause in 72.9% of those cases, a figure that places credential theft through brand impersonation at the start of the chain that ends in wire fraud.

    How business email compromise works

    BEC attacks vary in execution but follow a consistent structure: reconnaissance, impersonation, and extraction.

    The reconnaissance phase is what distinguishes BEC from commodity phishing. Attackers may spend days or weeks studying a target organization through publicly available information, breached data, or compromised email accounts. They identify who handles payments, who approves them, which vendors are active, and when large transactions are expected. In cases where the attacker has gained access to a real inbox through credential stuffing or a prior phishing campaign, they can monitor email threads in real time, learning the cadence and tone of the communications they will eventually hijack.

    The impersonation itself takes several forms. In CEO fraud, the attacker poses as a senior executive and sends an urgent request for a wire transfer, often marked confidential. In vendor impersonation, the attacker inserts themselves into an existing payment relationship, typically by spoofing or compromising the vendor’s email to request a change in banking details just before a scheduled payment. In attorney impersonation, the attacker poses as outside legal counsel handling a time-sensitive matter, pressuring junior employees into acting without verification. Palo Alto Networks’ Unit 42 found that among the BEC cases it investigated, the average financial loss from a successful wire fraud reached $286,000.

    What makes BEC particularly difficult to detect is the absence of the signals that traditional email security tools are designed to catch. There is no malicious attachment to scan, no suspicious link to flag, and no known-bad domain to block. The message arrives from what appears to be a legitimate address, references a real business relationship, and makes a request that falls within the recipient’s normal responsibilities. Cisco’s analysis describes BEC as “notoriously difficult to prevent” precisely because its effectiveness lies in social engineering rather than technical exploitation.

    Why BEC is a brand impersonation problem

    The standard framing of BEC is an internal security issue: protect your employees from being tricked into sending money. That framing is accurate but addresses only half of the problem.

    Every BEC attack involves the impersonation of a specific identity, and in the case of vendor impersonation, that identity belongs to an organization that has no visibility into how its name is being used. When an attacker spoofs a vendor’s email domain to redirect a payment, the vendor’s brand is the mechanism that makes the fraud convincing. The target organization pays the fraudulent invoice because the communication appears to come from a partner they do business with regularly. The vendor, meanwhile, discovers the impersonation only when the real invoice goes unpaid and both parties begin investigating.

    This dynamic becomes more pronounced as attackers move from email spoofing to actual account compromise. An attacker who gains access to a vendor’s real email account, whether through phishing, credential harvesting, or a supply chain breach, can send payment redirection requests that are indistinguishable from legitimate correspondence because they originate from the legitimate account. The recipient has no technical reason to question the request, and the impersonated vendor has no way of knowing its account is being used until the damage surfaces.

    The connection to the broader impersonation supply chain is direct. Phishing-as-a-service platforms generate the credential theft campaigns that compromise accounts. Those compromised accounts become the infrastructure for BEC. The vendor whose brand was impersonated in the original phishing lure may find its name used again in the BEC attack that follows, this time as the trusted sender rather than the trusted login page. For organizations whose brands appear in phishing kits or whose vendor relationships are targeted in BEC campaigns, the two threats are phases of the same operation rather than separate categories of risk.

    How to defend against business email compromise

    Defending against BEC requires controls at both the technical and procedural layers because the attack exploits trust in business relationships rather than vulnerabilities in software.

    On the authentication side, phishing-resistant MFA (FIDO2/WebAuthn, passkeys) prevents the credential theft that frequently precedes account-based BEC by ensuring that stolen passwords alone cannot grant access to email accounts. Domain-based authentication protocols including DMARC, DKIM, and SPF reduce the effectiveness of email spoofing by allowing recipient servers to verify whether a message genuinely originated from the claimed domain.

    On the procedural side, verification workflows for payment changes are the single most effective control. Requiring out-of-band confirmation, a phone call to a known number rather than the number provided in the email, before executing any change to vendor banking details interrupts the attack at the point of extraction. The FBI, Microsoft, and Arctic Wolf all cite this control as the highest-priority recommendation for BEC defense.

    For brands being impersonated in BEC campaigns, the defensive requirements extend beyond internal controls. Monitoring for lookalike domains and spoofed email addresses that use your brand name, tracking whether your domain is being used in phishing campaigns that harvest credentials for downstream BEC, and maintaining the ability to take down fraudulent infrastructure before it reaches its targets are the operational practices that reduce the likelihood of your brand becoming the trusted name on someone else’s fraudulent invoice.

    The Bottom Line

    Business email compromise is the costliest form of cybercrime the FBI tracks, and every successful attack runs on the same fuel: a name the target already trusts. For the organizations being targeted, the defense is authentication controls and verification workflows. For the brands being impersonated in those attacks, the defense is visibility into how and where their names are being used, and the ability to disrupt the impersonation before the fraudulent request is sent. The two are different sides of the same problem, and addressing only one leaves the other exposed.

    Key Takeaways

    What is business email compromise?

    BEC is a targeted social engineering attack in which an attacker impersonates a trusted executive, vendor, or legal representative to trick an employee into authorizing a wire transfer, redirecting a payment, or disclosing sensitive information. It relies on research and trust rather than malicious links or attachments.

    How much does BEC cost?

    The FBI attributes more than $55 billion in cumulative losses to BEC since 2013, with over $3 billion lost in 2025 alone. The average loss per successful wire fraud reaches $286,000 according to Palo Alto Networks’ Unit 42.

    How does BEC connect to brand impersonation?

    In vendor impersonation, the most common form of BEC, the attacker uses a trusted vendor’s identity to redirect payments. The vendor’s brand is the mechanism that makes the fraud convincing. Compromised vendor accounts often originate from phishing campaigns that impersonated brands to steal credentials in the first place.

    What is the most effective defense against BEC?

    Out-of-band verification for payment changes, specifically a phone call to a known number before executing any change to vendor banking details. Phishing-resistant MFA prevents the credential theft that often precedes account-based BEC.

    What should impersonated brands do about BEC?

    Monitor for lookalike domains and spoofed email addresses using your brand name, track whether your domain appears in phishing campaigns that harvest credentials for downstream BEC, and maintain the ability to take down fraudulent infrastructure before it reaches its targets.

    Categories:

    See the threats targeting your brand right now

    Get a customized assessment showing active impersonation, phishing infrastructure, and exposed credentials specific to your organization. No commitment required.