Business Email Compromise (BEC)

Business Email Compromise (BEC) is a fraud technique in which attackers impersonate a trusted party, typically an executive, vendor, or partner, using email to trick employees into transferring funds, changing payment details, or releasing sensitive information.

Why BEC Is a Distinct Threat Category

Most cyber attacks target technology. BEC targets people, through email, without necessarily compromising any system. That difference matters. Traditional technical controls (firewalls, endpoint protection, network segmentation) do little against a well-crafted email that impersonates a CEO and requests an urgent wire transfer.

The economic impact is substantial. BEC has consistently produced some of the largest reported cyber-related financial losses, often exceeding losses from ransomware in reported totals.

Common BEC Patterns

Recurring BEC techniques include vendor invoice fraud (attacker impersonates a vendor and requests payment redirection), CEO fraud (attacker impersonates an executive and requests urgent transfer), payroll diversion (attacker impersonates an employee and requests direct deposit change), and W-2 or tax data theft during filing season.

Attackers often compromise or spoof legitimate email accounts, making the messages difficult to distinguish from real correspondence.

BEC in Cyber Risk Programs

Effective BEC controls combine technical measures (email authentication, banner warnings for external senders, endpoint protection) with process measures (out-of-band verification for payment changes, dual approval for wire transfers, awareness training). Quantified programs model BEC as a distinct loss scenario with its own frequency and magnitude distributions.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.