Business email compromise (BEC) is a distinct category of financial crime, not a variant of phishing that happens to target executives. Phishing succeeds by getting someone to click something they shouldn’t. Business email compromise succeeds without any of that machinery: the entire attack is a well-researched email asking a specific person to do something that fits plausibly inside a normal working day. The largest incidents can move six figures in a single transfer, and by the time anyone notices, the money has usually already left the country.

None of the signals a phishing filter or a well-trained employee would normally look for are detected. That’s what separates business email compromise from ordinary phishing, and it’s why general phishing awareness can’t do much to stop it. We’ll show you how to spot business email compromise and protect your organization.

What is business email compromise?

Business email compromise is a targeted attack in which a criminal impersonates someone the target trusts, usually a senior executive, a supplier, or an internal colleague, and requests a wire transfer, a change to payment details, or sensitive credentials. 

There’s typically no malware(nueva ventana) and no malicious link involved. What varies is how the sender’s identity gets faked, and attackers have more options than most people assume:

  • Lookalike domains: the attacker registers a domain almost identical to the real one, swapping a single letter or adding a hyphen, and counts on nobody reading the address closely.
  • Display name spoofing: the “from” display name is set to match the trusted person — “John Smith” — while the actual address is something unrelated. Many mobile email clients show only the display name by default, so the real address never even appears on screen.
  • Header spoofing: SMTP, the protocol that moves email, doesn’t verify the “From” header on its own, so an attacker can send a message that claims to come from the real address without ever controlling it. Whether it reaches the inbox depends on the receiving domain’s authentication checks.
  • Reply-to manipulation: the visible “From” address looks legitimate, but a different Reply-To address is set behind it, so the moment the target hits reply, the conversation quietly routes to the attacker.
  • Account compromise: the attacker gains access to a genuine email account and sends the request from inside it.

The last of these, account compromise, is the hardest to catch, because there’s genuinely nothing technically wrong with the email. It came from the real address, on the real custom email domain, and it may even continue a thread the target has seen before. 

How the business email compromise playbook works

Business email compromise attacks are built, not improvised, and the preparation is usually where most of the criminal’s effort goes.

Research

It starts with reconnaissance: LinkedIn profiles reveal who holds which title and who reports to whom, company press releases announce mergers, funding rounds, or new supplier relationships, and an out-of-office reply can hand an attacker the one detail they need most, confirmation that the real executive is unreachable right now.

Choosing a target

From there, the attacker moves to target selection. Not every employee is useful to a business email compromise attempt; the target has to be someone with the authority to actually move money or change payment details, which usually narrows the field to finance, accounts payable, HR, or payroll.

Impersonation begins

Once a target and a plausible narrative are chosen, impersonation follows, either through a spoofed lookalike domain or a genuinely compromised mailbox, matched to the tone, signature, and level of formality the real sender would use.

Contact is made

The attacker interacts with someone within the business, making an urgent request or demand. This may be an acquisition that has to close today, an auditor who needs the figures immediately, or a stranded colleague who can’t get through on the phone. 

Usually, the request will be a wire transfer, a change of bank details, or a request for login credentials, framed as something that simply needs to happen, not something that needs to be questioned.

Four common business email compromise scenarios 

Here are a few of the most common business email compromise tactics attackers use.

CEO fraud

An email appears to come from the CEO, managing director, or another senior leader, asking a finance team member to process an urgent, often confidential, payment. The apparent seniority of the sender is doing most of the work here, since few employees feel comfortable questioning a request that looks like it comes from the top.

Invoice fraud

A supplier the business already works with appears to notify a change of bank details, usually timed to land just before a real invoice is due. Because a genuine business relationship and a genuine payment already exist, this version is often the hardest for a finance team to catch, and it accounts for some of the largest single losses businesses report.

Payroll redirect

An email impersonating an employee, or occasionally HR itself, asks payroll to update bank details ahead of the next pay run. The request is small and mundane enough that it rarely gets a second look, which is exactly why it works.

IT support impersonation

A message posing as internal IT or a helpdesk asks an employee to confirm a password or approve a login prompt before a system update. Unlike the other three, this scenario isn’t after money directly. It’s after the credentials that make every other form of business email compromise easier to run.

What business email compromise actually costs

Business email compromise losses are reported differently to ordinary card fraud, which is part of why the scale of the problem is easy to underestimate. The FBI’s Internet Crime Complaint Center recorded $2.77 billion(nueva ventana) in business email compromise losses across 21,442 reported incidents in 2024, and its running tally of the scam puts global exposed losses above $55 billion(nueva ventana) over the past decade. Averages hide the real story, though. The cases that made headlines show what a single well-built email can move.

Between 2013 and 2015, a Lithuanian fraudster billed Facebook and Google out of a combined $121 million(nueva ventana) using fake invoices from a company impersonating Quanta Computer, a hardware supplier both firms genuinely used. Because the invoices fit an existing business relationship, the accounts teams paid them, and kept paying them for two years.

In 2016, Austrian aerospace supplier FACC was hit by an email impersonating its then CEO, requesting a transfer of roughly €50 million(nueva ventana) for a supposed acquisition project, the exact pretext described at the top of this article. The company stopped part of the transfer after discovering the fraud, but the rest was never recovered.

These cases describe a category of crime that behaves differently from most phishing statistics. Phishing is measured in volume: millions of near-identical emails, most of them caught by a filter before anyone sees them.

Business email compromise is measured in individual incidents, each one built around a single target and a single payment, and each one capable of doing more damage in one afternoon than a thousand blocked phishing emails ever could. 

Any organization that has moved money by wire transfer or changed a supplier’s bank details in the past should treat this as a live financial risk and report suspected incidents to its national fraud reporting center, the FBI’s IC3 in the United States, Action Fraud in the UK, and equivalents elsewhere.

The controls that actually stop business email compromise

Because business email compromise bypasses the technical red flags phishing training relies on, the controls that stop it look different too. Awareness helps, but the defenses that actually hold up are procedural and technical, not a matter of employees reading emails more carefully.

Dual authorization

Dual authorization on any payment above a set threshold has to be mandatory, not a courtesy extended when someone remembers to ask. A single person’s approval should never be enough to move a meaningful sum of money, regardless of how senior or urgent the request appears.

Callback verification

Callback verification closes the loop that email alone can’t. Any request to change bank details or release a payment should be confirmed by phone, using a number already on file, never one supplied in the email itself, since a number provided by the attacker simply connects the target back to the attacker.

Review payment approval procedures

Regular reviews of payment approval procedures also help reduce business email compromise risk over time. As businesses grow, temporary exceptions and informal shortcuts often become part of everyday operations without anyone questioning whether they are still appropriate. Reviewing who can authorize payments, how bank detail changes are approved, and which transactions require additional verification helps ensure financial controls continue to match the organization’s current level of risk. Even well-designed procedures lose effectiveness if they are not revisited as the business evolves.

Email authentication

Technical email authentication is a key component of email security and matters here in a way it doesn’t for most phishing, because business email compromise frequently relies on spoofing an organization’s own domain to impersonate its executives. 

DMARC, working alongside SPF and DKIM, tells receiving mail servers what to do with messages that fail to authenticate against your domain, which makes it significantly harder for an attacker to send an email that appears to come from your own CEO.

Open security culture

None of this works without a cultural norm underneath it: It is always acceptable to pause and verify a request, regardless of who appears to be asking. Employees who fear looking obstructive or distrustful toward a senior figure are exactly the ones a business email compromise attempt is designed to catch, and that fear only goes away when leadership makes it clear, repeatedly, that questioning an unusual request is expected, not disloyal.

How to spot the warning signs of a business email compromise attempt

Business email compromise rarely announces itself through obvious technical warning signs. The email may come from a familiar address, reference a real project, and use language that matches previous conversations. That is why the context around the request often matters more than the email itself.

Several patterns appear repeatedly across business email compromise investigations. A request that bypasses normal approval procedures should always raise questions. So should unexpected instructions to keep a payment confidential, changes to a supplier’s bank details shortly before an invoice is due, or requests that arrive while a senior executive is traveling and difficult to reach. Attackers deliberately choose situations where employees are less likely to verify the request through another channel.

Small changes in communication style can also provide clues. An executive who normally delegates financial approvals may suddenly ask for a payment personally. A supplier who usually communicates through an account manager may send banking instructions from a different contact. None of these signs proves an attack on its own, but they should prompt additional verification before money moves or account details change.

The safest approach is to treat unusual financial requests as business process exceptions rather than situations that require urgent decisions. A short phone call using a trusted number, or confirmation through an established internal communication channel, can prevent a loss that would otherwise take weeks or months to recover.

How do credentials make business email compromise easier? 

Not every business email compromise attempt relies on a spoofed lookalike domain. Sometimes, it starts with a genuinely compromised email account, one where the attacker simply logged in using a password that had already been exposed somewhere else. 

Once inside, they don’t need to fake anything. They can read old threads, match tone and formatting exactly, and send the fraudulent request from an address that passes every authentication check, because it really is the sender’s own account.

This is where password hygiene and business email compromise prevention overlap directly. Proton’s Data Breach Observatory tracks how often business credentials surface in criminal datasets long before anyone inside the affected company notices, and account compromise is exactly the outcome that data enables. 

A secure business email, unique passwords on every account, combined with multi-factor authentication (MFA), means a password leaked from one breach can’t be reused to walk into a mailbox and launch a business email compromise attempt from the inside.

A business password manager like Proton Pass for Business makes this standard realistic to maintain across an entire organization, rather than something that depends on individual employees remembering not to reuse a password. When credentials are generated and stored properly, vulnerabilities to data breaches and account takeovers are significantly reduced.

Protect your business accounts from compromise with a secure business password manager.