Business Email Compromise (BEC): How Attackers Impersonate Executives and Steal Company Funds
- ESKA ITeam
- Jul 26
- 12 min read
Business Email Compromise (BEC) is a targeted cyberattack in which criminals impersonate a CEO, CFO, executive, employee, supplier, or business partner to trick someone into transferring money, changing payment details, or disclosing sensitive information.
Unlike mass phishing campaigns, BEC attacks are often carefully researched and highly personalized. Attackers may study a company's organizational structure, executives, suppliers, communication style, and payment processes before sending a single fraudulent email.
That preparation is what makes Business Email Compromise particularly dangerous: the email may contain no malware, malicious attachment, or suspicious link at all. Instead, the attacker exploits trust and legitimate business processes.
What Is a BEC Attack?
Business Email Compromise (BEC) is a form of social engineering that uses email impersonation or compromised email accounts to manipulate employees into performing fraudulent actions.
The attacker's objective may be to:
steal company funds;
redirect legitimate payments;
change supplier banking details;
gain access to corporate accounts;
obtain confidential documents;
steal payroll or employee information;
bypass normal payment approval procedures.
BEC is sometimes referred to as CEO fraud, but executives are not the only identities attackers impersonate.
Cybercriminals may pose as:
CEOs and company founders;
CFOs and finance directors;
accountants;
HR managers;
procurement teams;
lawyers;
suppliers;
contractors;
trusted business partners.
A successful BEC email often looks completely legitimate. It may use the correct signature, company branding, writing style, terminology, and even information from previous conversations.
What Does a BEC Attack Look Like?
Imagine a company that regularly works with international suppliers.
A finance manager receives the following email:
Hi,We need to finalize payment for the new contract today.Please use the updated bank details attached to the invoice.The payment must be completed before 4 PM.I'm in meetings, so please handle this directly.Thanks,CEO
Nothing about the message immediately looks malicious.
The writing style sounds familiar. The signature is correct. The request is related to an actual business transaction. The attacker may even reference previous conversations or a real contract.
There is only one problem:
The CEO never sent the email.
The employee transfers the money, but the "updated" bank account belongs to the attacker.
By the time the company realizes what happened, the funds may already have been transferred through additional accounts, making recovery extremely difficult.
This is a typical example of BEC payment fraud.
Why Do Employees Fall for BEC Emails?
BEC attacks primarily exploit human psychology and business processes, rather than technical vulnerabilities.
Attackers commonly create pressure through:
urgency;
authority;
confidentiality;
fear of delaying an important transaction;
fear of questioning senior management;
pressure to complete a task quickly.
Typical BEC messages may include phrases such as:
"I need this handled urgently."
"Don't call me right now."
"I'm in a meeting."
"This is confidential."
"The transfer must be completed today."
"Use these new banking details."
"I'll explain later."
"Please don't involve anyone else yet."
The objective is simple: prevent the employee from verifying the request through another communication channel.
That is why BEC prevention requires more than cybersecurity technology. It also requires financial controls and clear verification procedures.
How Business Email
Compromise Works
There are several common ways attackers execute BEC attacks.
1. Corporate Email Account Compromise
One of the most dangerous scenarios occurs when an attacker gains access to a legitimate corporate mailbox.
The compromised account may belong to a:
CEO;
CFO;
finance employee;
accountant;
procurement specialist;
HR employee;
administrator;
supplier or business partner.
Once inside the mailbox, the attacker may remain undetected while monitoring communications.
They can:
read previous conversations;
learn how executives communicate;
identify customers and suppliers;
understand payment schedules;
monitor invoices and contracts;
identify employees authorized to make payments;
wait for an appropriate financial transaction.
The attacker can then send a fraudulent request from the real corporate email account.
This scenario is particularly difficult to detect because the email is technically legitimate.
The sender address is correct. The account is real. The email infrastructure is authorized.
As a result, mechanisms such as SPF, DKIM, and DMARC may not stop the message.
2. Lookalike Domain Attacks
Another common BEC technique is registering a domain that looks almost identical to the legitimate company's domain.
For example:
company.com → cornpany.com
company.com → company.co
company.com → company-payments.com
company.com → company-inc.com
A single changed character can be difficult to notice, particularly when reading email on a smartphone.
Attackers can configure SPF, DKIM, and DMARC correctly for their own fraudulent domain. Technically, the email authentication checks may therefore succeed, they simply authenticate the attacker's domain rather than the legitimate company's domain.
3. Display Name Spoofing
Sometimes attackers do not need to imitate the domain at all.
Instead, they manipulate the sender's display name.
An employee may see:
John Smith — CEO
while the actual sender address is something completely unrelated.
Because many email applications prominently display the sender's name while hiding or minimizing the full email address, employees may trust the message without checking the underlying address.
4. Email Thread Hijacking
Thread hijacking can make BEC attacks extremely convincing.
If an attacker compromises the mailbox of an employee, supplier, or business partner, they may monitor existing conversations and wait for an appropriate opportunity.
They can then reply directly within a legitimate email thread.
The conversation history is real.
The invoice may be real.
The supplier is real.
The transaction is expected.
Only the new payment instructions are fraudulent.
For example, an attacker may wait until an invoice is about to be paid and then send:
Please note that our banking details have recently changed. Use the updated account for this payment.
Because the request appears inside an existing conversation with a trusted partner, employees are much more likely to believe it.
Why SPF, DKIM, and DMARC Cannot Completely Stop BEC
SPF, DKIM, and DMARC are essential email security controls, but they should not be treated as complete protection against Business Email Compromise.
Together, they help verify whether an email was sent through authorized infrastructure and whether the message was altered.
However, they do not determine whether the person controlling a legitimate account is actually the legitimate user.
SPF: Sender Policy Framework
SPF defines which mail servers are authorized to send email on behalf of a domain.
For example, a company can configure its DNS records so that email from company.com should only originate from its authorized Microsoft 365 infrastructure.
If another unauthorized server attempts to send mail claiming to represent that domain, the recipient's mail system can treat the message as suspicious.
However, SPF does not protect against an attacker who has already gained access to a legitimate corporate mailbox.
DKIM: DomainKeys Identified Mail
DKIM uses cryptographic signatures to help verify that an email was sent by an authorized mail system and was not modified during transmission.
The recipient's email server verifies the signature using a public key published in the sender's DNS records.
But if an attacker sends an email through a compromised legitimate account, that message may receive a valid DKIM signature.
DMARC: Domain-based Message Authentication, Reporting and Conformance
DMARC works with SPF and DKIM and defines how receiving mail systems should handle messages that fail authentication or domain alignment checks.
Depending on the policy, suspicious emails may be:
monitored;
sent to spam or quarantine;
rejected completely.
DMARC also provides reporting that can help organizations identify attempts to abuse their domain.
However, DMARC does not fully protect against:
compromised legitimate mailboxes;
lookalike domains;
compromised suppliers;
compromised business partners;
internal account abuse;
social engineering sent from legitimate infrastructure.
Therefore, SPF, DKIM, and DMARC should be considered one layer of BEC protection, not the entire security strategy.
How to Recognize a BEC Email
A Business Email Compromise message may not contain obvious technical indicators of phishing.
Instead, employees should look for unusual business behavior.
Warning signs include:
an unexpected request to change bank details;
unusual urgency;
instructions not to call the sender;
a new or unfamiliar bank account;
slight changes in the sender's domain;
unusual communication style;
requests to bypass standard payment procedures;
requests to keep the transaction confidential;
unexpected requests for sensitive documents;
sudden changes to supplier payment instructions;
requests for gift cards or unusual purchases;
requests involving payroll or employee data.
One suspicious indicator may be enough to justify verification through a separate communication channel.
How to Protect Your Company From BEC Attacks
Effective BEC prevention requires several security layers.
No single control is enough.
Email authentication cannot prevent every compromised-account attack. Employee awareness cannot stop credential theft on its own. Email filtering cannot prevent an employee from voluntarily approving a fraudulent payment.
Organizations should combine identity security, email security, monitoring, employee awareness, and financial controls.
Use MFA for Corporate Email Accounts
Multi-Factor Authentication (MFA) requires users to provide more than a password when accessing an account.
The additional authentication factor may include:
an authentication app;
a hardware security key;
a passkey;
biometrics;
a one-time verification code.
MFA is particularly important for BEC prevention because many attacks begin with stolen Microsoft 365, Google Workspace, or other corporate email credentials.
If an attacker obtains a password but cannot complete the second authentication step, taking control of the mailbox becomes significantly more difficult.
However, not every form of MFA provides the same level of protection.
SMS codes and basic push notifications can still be vulnerable to phishing and MFA fatigue attacks, where attackers repeatedly send authentication requests hoping the victim eventually approves one.
For high-value accounts, organizations should consider phishing-resistant MFA, such as FIDO2 security keys and passkeys.
Configure SPF, DKIM, and DMARC
Organizations should correctly configure:
SPF;
DKIM;
DMARC.
These mechanisms significantly reduce the ability of attackers to directly spoof legitimate corporate domains.
DMARC should also be monitored rather than configured once and forgotten. Reporting can reveal unauthorized services or infrastructure attempting to send email using the organization's domain.
However, these technologies must remain part of a broader security strategy because they cannot stop every form of BEC.
Deploy Modern Email Security
Traditional spam filters primarily focus on known malicious attachments, URLs, malware, and high-volume phishing campaigns.
BEC attacks often contain none of these.
Modern email security and Secure Email Gateway solutions can analyze additional signals, including:
sender reputation;
domain reputation;
domain age;
lookalike domains;
unusual sender behavior;
suspicious payment-related language;
external senders impersonating executives;
abnormal communication patterns;
suspicious links and attachments.
For example, an email security system may flag a message when the display name matches the company's CEO but the message originates from an external domain.
This is particularly useful for detecting executive impersonation and CEO fraud.
Require Out-of-Band Verification for Payment Changes
Technical controls should be supported by strict financial procedures.
One of the most effective controls is out-of-band verification — confirming a request through a communication channel independent from the original email.
If an employee receives a request to:
change supplier banking information;
make an urgent payment;
transfer funds to a new account;
modify payroll information;
the email alone should not be considered sufficient authorization.
The employee should verify the request using a trusted channel, such as:
calling a previously verified phone number;
contacting the person through the company's corporate messenger;
arranging a video call;
obtaining confirmation from another authorized employee.
Importantly, employees should not use the phone number or contact information provided in the suspicious email itself.
The attacker may have included their own contact information specifically to intercept the verification attempt.
Introduce Dual Approval for Financial Transactions
Organizations should consider dual approval, sometimes called the four-eyes principle, for high-value or unusual financial transactions.
One person should not be able to independently create and authorize a significant payment.
For example:
An accountant creates the payment.
A finance manager or another authorized employee independently verifies the beneficiary and approves it.
This process creates an additional barrier between a convincing fraudulent email and the actual transfer of company funds.
Payment thresholds can also trigger additional verification requirements.
Train Employees to Recognize BEC
Because Business Email Compromise relies heavily on social engineering, employees must understand what these attacks actually look like.
Training should be particularly focused on:
finance teams;
accounting;
procurement;
HR;
administrative staff;
executives;
employees authorized to approve payments.
Security awareness training should go beyond obvious phishing emails.
Employees should practice recognizing realistic business scenarios, including:
urgent CEO payment requests;
supplier bank account changes;
gift card requests;
payroll data requests;
confidential document requests;
executive impersonation;
compromised vendor communications.
Phishing simulations can help organizations measure how employees react to realistic attacks and identify users or departments that require additional training.
Monitor Email Accounts for Suspicious Activity
A BEC attack may begin days or weeks before the fraudulent payment request appears.
After compromising an email account, an attacker may quietly monitor communications while learning how the organization operates.
Companies should therefore monitor corporate email systems for suspicious behavior, including:
logins from unusual countries or IP addresses;
access from previously unseen devices;
repeated failed login attempts;
unusual authentication activity;
newly created forwarding rules;
automatic deletion or movement of emails;
forwarding corporate email to external addresses;
changes to MFA settings;
changes to account recovery methods;
unusual mailbox access outside normal working hours.
Pay Particular Attention to Mailbox Forwarding Rules
Mailbox forwarding rules are especially important in BEC investigations.
Attackers may create hidden rules that:
forward copies of emails to external addresses;
automatically move selected emails into another folder;
delete security notifications;
hide messages from specific suppliers or employees.
This allows criminals to monitor invoices, contracts, payment schedules, and conversations without constantly logging into the account.
Connect Email Security to SIEM or SOC Monitoring
For organizations with hundreds or thousands of users, manually reviewing email security events is unrealistic.
Events from systems such as:
Microsoft 365;
Google Workspace;
email security platforms;
identity providers;
EDR;
firewalls;
cloud infrastructure;
can be collected by a SIEM (Security Information and Event Management) platform.
A SIEM can correlate signals that might appear harmless individually.
For example:
A user signs into Microsoft 365 from an unusual location.
A new mailbox forwarding rule is created.
The account begins accessing large volumes of financial correspondence.
Authentication or account settings are modified.
Together, these events may indicate an account takeover and trigger an investigation.
Organizations using a SOC (Security Operations Center) can continuously monitor such activity and investigate suspicious behavior before an attacker successfully executes a fraudulent payment request.
Monitor Lookalike Domains and Brand Impersonation
Companies should also monitor domains that resemble their legitimate corporate domain.
Attackers may register variations involving:
substituted letters;
additional hyphens;
extra words;
different top-level domains;
visually similar characters.
For example:
company.com → cornpany.com
company.com → company-payments.com
company.com → company.co
These domains can then be used to impersonate executives, employees, or suppliers.
Domain monitoring and brand impersonation detection can help security teams discover suspicious registrations before they are used in a full-scale BEC campaign.
The Best BEC Defense Combines Technology and Business Processes
There is no single technology that can completely eliminate Business Email Compromise.
A resilient BEC security strategy combines:
phishing-resistant MFA;
SPF, DKIM, and DMARC;
modern email security;
identity and mailbox monitoring;
SIEM or SOC monitoring;
lookalike domain detection;
employee security awareness;
out-of-band verification;
dual approval for financial transactions.
The most important business rule is simple:
An email alone should never be sufficient authorization to change banking details or execute an unusual financial transaction.
What to Do After a Successful BEC Attack
If an employee has already transferred money to an attacker, the first hours are critical.
The organization should:
Contact the bank immediately. Request that the transfer be stopped, recalled, or frozen if possible.
Secure compromised accounts. Revoke active sessions, reset credentials, and review MFA settings.
Inspect mailbox rules. Look for unauthorized forwarding, deletion, and inbox rules.
Preserve evidence. Collect email headers, authentication logs, mailbox audit logs, endpoint data, and other relevant security records.
Investigate the wider environment. Determine whether additional accounts, devices, or systems were compromised.
Check other financial transactions. Attackers may have attempted multiple fraudulent payments.
Notify management and relevant stakeholders.
Contact law enforcement or relevant authorities when appropriate.
Review financial approval procedures. Identify which control failed and introduce measures to prevent recurrence.
Organizations should avoid immediately deleting compromised accounts, emails, or logs before evidence has been preserved, as this information may be critical for incident response and investigation.
Business Email Compromise FAQ
What is a BEC attack?
A Business Email Compromise (BEC) attack is a targeted social engineering attack in which criminals impersonate or compromise a trusted business email account to trick employees into transferring money, changing payment details, or revealing sensitive information.
What is the difference between BEC and phishing?
Traditional phishing is often distributed to a large number of recipients and commonly uses malicious links or attachments.
BEC is typically more targeted. Attackers research a specific company, employee, executive, supplier, or transaction and create a convincing business request. Many BEC emails contain no malicious attachment or URL.
What is CEO fraud?
CEO fraud is a type of Business Email Compromise in which an attacker impersonates a company's CEO or another senior executive.
The attacker typically asks an employee to perform an urgent or confidential action, such as transferring money, purchasing gift cards, sharing documents, or changing payment information.
Can BEC bypass SPF, DKIM, and DMARC?
Yes.
If an attacker controls a legitimate corporate email account, the fraudulent message may successfully pass SPF, DKIM, and DMARC checks.
Attackers can also use lookalike domains or compromised supplier accounts rather than directly spoofing the victim company's domain.
Who is most commonly targeted by BEC attacks?
Common targets include:
CEOs;
CFOs;
finance directors;
accountants;
procurement employees;
HR teams;
executive assistants;
employees authorized to make or approve payments.
However, any employee who has access to valuable information or trusted business communications can become a target.
Does MFA prevent Business Email Compromise?
MFA significantly reduces the risk of account takeover, but it cannot prevent every BEC scenario.
For example, MFA does not stop an attacker from using a lookalike domain to impersonate an executive. Some forms of MFA can also be defeated through phishing or MFA fatigue attacks.
Organizations should combine MFA with email security, monitoring, employee awareness, and financial verification procedures.
Is employee training enough to prevent BEC?
No.
Employee awareness is important, but effective BEC protection requires multiple layers of security, including MFA, SPF, DKIM, DMARC, modern email security, account monitoring, SIEM or SOC monitoring, and robust payment approval procedures.
What should employees do when someone requests new bank details by email?
Employees should not change payment information based solely on an email request.
The change should be independently verified through a trusted communication channel using previously known contact information. For sensitive or high-value transactions, a second authorized employee should also approve the change.
Business Email Compromise remains one of the most dangerous forms of cyber-enabled fraud because attackers exploit something every organization depends on: trust between employees, executives, customers, and business partners.
A convincing message from a CEO or supplier may contain no malware and no suspicious link. From a technical perspective, it may even originate from a legitimate email account.
That is why stopping BEC requires more than a spam filter.
Organizations need a layered approach combining secure email infrastructure, phishing-resistant MFA, SPF, DKIM and DMARC, email security, continuous account monitoring, SIEM or SOC capabilities, employee awareness, and strict financial verification procedures.
Most importantly, companies should build processes around one fundamental rule: Never allow a single email to authorize an unexpected payment or change of banking details.
ESKA Security helps organizations strengthen their defenses against Business Email Compromise through security assessments, email and identity security reviews, phishing simulations, security awareness training, SIEM implementation, SOC monitoring, and incident response.
By combining technical security controls with mature business processes, organizations can significantly reduce both the likelihood and financial impact of BEC attacks.



Comments