What Is Business Email Compromise?

Business Email Compromise (BEC) is a category of fraud in which attackers use email — either compromised legitimate accounts or convincing impersonations — to deceive employees into making fraudulent wire transfers, sharing sensitive credentials, or redirecting payroll. BEC does not require malware and often bypasses technical security controls entirely because it exploits human trust rather than software vulnerabilities. The FBI's 2024 Internet Crime Report cited BEC as the most financially damaging cybercrime category, accounting for billions in losses annually.

How BEC Attacks Work

The most effective BEC attacks are patient and deliberate. Attackers may spend weeks monitoring a compromised email account before acting — learning communication styles, identifying key personnel, understanding upcoming transactions, and timing their attack to coincide with a legitimate business process like a real estate closing, acquisition payment, or payroll run.

  • CEO fraud — Impersonating the CEO or another executive to pressure an employee into an urgent wire transfer
  • Vendor impersonation — Pretending to be a known vendor with updated payment instructions
  • Account compromise — Using a legitimately compromised email account to redirect payments or collect credentials from business partners
  • Payroll diversion — Convincing HR to update direct deposit information to an attacker-controlled account

Why Technical Controls Alone Are Not Enough

A BEC attack conducted through a legitimately compromised account passes through email filters, anti-malware systems, and even multi-factor authentication checks for the email itself. The attack vector is trust — the recipient trusts the email because it appears to come from a legitimate source they know. Technical controls reduce risk but cannot eliminate it. Human detection ability is the last line of defense.

How Social Engineering Testing Addresses BEC

Grid32's phishing and vishing assessments include BEC-style scenarios — impersonation of executives, urgency manipulation, and pretexts designed to elicit wire transfers or credential disclosure. These tests measure your employees' ability to recognize and report suspicious requests under realistic conditions. The results directly identify which employees and which processes are most vulnerable, enabling targeted training and process improvements such as out-of-band verification requirements for wire transfers.

Test your human defenses against BEC.

Grid32's social engineering assessments include BEC-style scenarios targeting your financial and administrative staff — the people attackers specifically try to deceive.

Get a Quote →