What is Business email compromise (BEC)?
A fraud where attackers take over or impersonate a business email account to trick staff, customers or suppliers into sending money or sensitive data.
How it works
BEC often starts with a phished Microsoft 365 or Google Workspace account. The attacker reads mail quietly, sets up forwarding or hiding rules, then sends a convincing request, such as changed bank details on a real invoice.
Because the messages come from a genuine account and contain no malware, email filters often miss them. Detection relies on spotting unusual sign-ins, new inbox rules and changes in behaviour.
Key points
- Usually involves no malware at all
- Often starts with credential phishing
- Inbox rules and forwarding are common warning signs
- Payment verification processes are a key control
Common questions
How is BEC different from phishing?
Phishing is the technique. BEC is the fraud that often follows, using a compromised or spoofed business account.
What should we do if an account is compromised?
Revoke sessions, reset credentials, remove malicious inbox rules and check what the attacker sent and accessed.
Talk to someone who does this every day
Questions about BEC? Our team will give you a straight answer.