Business Email Compromise (BEC): How the Attack Works and How to Stop It
A BEC email attack carries no malware, no dodgy link and nothing for a scanner to catch. It is a person impersonating someone you trust and asking for a payment or a change of bank details. It is quietly one of the most expensive attacks in cyber crime. Here is exactly how it works, why filtering alone will not stop it, and the layered defence that does.
Most people picture an email attack as a malicious attachment or a link to a fake login page. Business email compromise is neither. There is usually no payload at all. The whole attack is a plausible message, sent to the right person at the right moment, asking them to do something that looks entirely normal. Move a payment. Update a supplier's bank details. Buy some gift cards for the boss. Because there is nothing technically malicious in the email, the tools built to find malicious things have nothing to grab hold of.
BEC is targeted fraud by email. The attacker impersonates a trusted person, an executive, a supplier, a colleague, and persuades someone to send money or data. There is often no malware, which is why it slips past spam filters and built in protection. The defence is not one product. It is a stack of email controls, a payment verification process, and alert people, arranged so that no single failure loses the money.
What a BEC attack actually is
Business email compromise is a form of social engineering. The attacker studies how your organisation communicates, then sends a message that fits the pattern. They know who signs off payments, who talks to which supplier, and how a request from a director usually reads. The email is short, urgent and confident. It asks for a routine business action, not for anything obviously suspicious, and it is aimed at a person who has every reason to comply.
That is what makes it so effective. A phishing campaign is a wide net thrown at thousands of inboxes. BEC is a spear aimed at one desk. The attacker has often watched a real email thread, sometimes from a mailbox they already quietly control, and they time their message to land inside a genuine conversation. To the person reading it, nothing feels wrong.
The main types of BEC
The label covers several closely related frauds. They share a method, impersonation and a believable request, but they target different people and different transactions.
- CEO fraud, or executive impersonation. A message that appears to come from a senior leader, asking finance to make an urgent, confidential payment. It leans on authority and time pressure so the recipient acts before they check. This is the classic BEC attack.
- Supplier and invoice fraud. The attacker poses as a genuine supplier and says their bank details have changed, so please pay the next invoice to a new account. Because there is a real relationship and a real invoice, this is the version that moves the largest sums. It is sometimes called invoice redirection.
- Payroll diversion. A message impersonating an employee asks HR or payroll to update their salary bank details. The next pay run quietly lands in the attacker's account.
- Legal or acquisition pretext. An impersonated lawyer or executive references a sensitive deal or legal matter and pushes for a fast, discreet transfer. The confidentiality is the trick, it discourages the recipient from checking with anyone.
- Account takeover. The most dangerous variant. The attacker is not impersonating a mailbox from the outside, they are inside a real one, having phished the credentials. The fraudulent request comes from the genuine address, in the genuine thread. There is nothing to spot in the sender at all.
Why BEC gets past your filters
Spam filters and the built in protection in Microsoft 365 or Google Workspace are tuned to find malicious content. Bad attachments, known bad links, malware signatures, high volume spam patterns. A well crafted BEC email contains none of that. It is a normal looking message with a normal looking request, so on content alone there is nothing to flag.
The signals that do give it away are subtler. A lookalike domain that swaps one letter. A display name that matches your director while the real address does not. A first time sender asking about a payment. A reply to address that quietly differs from the sender. Baseline filtering catches some of this, but the carefully targeted version, written to your people about a real supplier and a real invoice, is the single hardest class of email attack to stop with filtering alone. And when the attack comes from a genuine, compromised mailbox, there is no impersonation to detect, because the sender really is who they claim to be.
BEC does not spread malware or lock up systems, so it rarely makes headlines the way ransomware does. Yet it is consistently one of the highest value categories of cyber crime reported to the FBI's Internet Crime Complaint Center, running to billions in reported losses year after year. The reason is simple. The attack targets the payment itself, so a single successful message can move a very large sum, and by the time anyone notices, the funds have usually gone.
The layered defence that works
Because BEC blends a technical channel with a human decision, no single control stops it. A resilient posture stacks three kinds of defence so that a failure in one is caught by another.
1. Technical email controls
- Impersonation protection. Dedicated detection for lookalike domains, display name spoofing and unusual payment language, the signals a generic spam filter misses.
- Enforced DMARC, with SPF and DKIM. This stops attackers spoofing your own domain, which protects your suppliers and customers as much as your staff. Enforced is the operative word, present but not enforced does very little.
- Multi factor authentication. The main defence against account takeover. It limits the damage when a credential is inevitably phished, so a stolen password does not hand over a genuine mailbox.
- Post delivery remediation. The ability to pull a message from every affected inbox after it has been delivered, because the danger of a BEC email is often recognised only after it lands.
2. A payment verification process
This is the control that stops most BEC, and it is not a product. Any change to bank details, and any unusual or urgent payment request, is verified out of band, through a known phone number or in person, never by replying to the email that made the request. If the process is mandatory and applies to everyone including the chief executive, the entire category of attack loses its power, because the fraudulent instruction cannot survive a second, independent check.
3. People who know the pattern
The last layer is a workforce that recognises the shape of these attacks. Not an annual training module that fades in a fortnight, but continuous, relevant awareness of the specific tricks, urgency, authority, confidentiality and secrecy, paired with an easy way to report a suspicious message. That turns your finance and HR teams from the target into the sensor.
Stop asking whether your people will ever stop being fooled. The good attacks are convincing by design, and someone eventually will be. Start asking what has to be true for a fooled click to still not lose the money. If the answer is a mandatory verification step and a mailbox the attacker cannot get into, your layering is working.
Where Mimecast fits
We are a strategic Mimecast partner, and where it fits we recommend it for specific reasons rather than as a default. It sits independently of the mailbox platform, so a compromised Microsoft or Google tenant does not also compromise the security layer in front of it. It is strong on exactly the impersonation and business email compromise classes that baseline filtering finds hardest. It can remove a delivered message from every affected mailbox after the fact, which addresses the account takeover and post delivery problem directly. And it applies one consistent policy across inbound mail, which matters in a mixed or complex estate. Those are the reasons. Where they match your problem, it is a strong fit, and where they do not, we will tell you so. Our guide on whether your built in email security is enough works through that decision in detail.
Before any review, it helps to know roughly where you stand. Our free, interactive Email Security Assessment returns an instant, personalised analysis across the six dimensions of email and collaboration security, from threat protection and authentication to the human layer and incident response. For a focused view of your Mimecast readiness, the Mimecast Assessment does the same. Both are the quickest place to begin.
Worried about your exposure to invoice fraud and BEC?
C4C runs independent email security reviews, checking your impersonation defences, your DMARC enforcement, your payment verification process and your human risk, then recommending what genuinely closes the gaps. Vendor neutral, with no quota to fill.
Prefer email? Reach us directly at hello@c4cgroup.co.uk.
Frequently asked questions
What is business email compromise (BEC)?
Business email compromise is a targeted fraud where an attacker impersonates a trusted party, such as a senior executive, a supplier or a colleague, and tricks an employee into transferring money or changing bank details. It often uses no malware at all, which is why it slips past tools that only look for malicious attachments and links.
How is a BEC attack different from phishing?
Phishing is usually a wide, automated campaign sent to thousands of inboxes, often carrying a malicious link or attachment. BEC is a spear aimed at one person, carrying no payload, just a plausible request timed to fit a real conversation. Phishing tries to harvest a credential or drop malware. BEC goes straight for the payment.
Why do BEC emails get past spam filters and Microsoft 365?
Because there is nothing malicious in the content for a filter to catch. A well crafted BEC email is a normal looking message with a normal looking request. The clues are subtle, a lookalike domain or a spoofed display name, and when the attack comes from a genuine, compromised mailbox there is no impersonation to detect at all, because the sender really is who they claim to be.
What are the main types of BEC attack?
The common types are CEO or executive impersonation, supplier and invoice fraud where bank details are changed, payroll diversion, a legal or acquisition pretext that pushes for a discreet transfer, and account takeover where the attacker sends the request from a real mailbox they have compromised. Supplier and invoice fraud tends to move the largest sums.
How do you stop business email compromise?
With layers. Technical controls for impersonation protection, enforced DMARC and multi factor authentication, a mandatory payment verification process that checks any change of bank details out of band through a known phone number, and continuous human awareness of the pattern. No single control is enough, but together they mean a fooled click does not lose the money.
Does Mimecast stop BEC?
Mimecast is strong against the impersonation and business email compromise classes that baseline filtering finds hardest, it sits independently of the mailbox so a compromised tenant does not compromise it, and it can remove a delivered message from every affected inbox. It is a strong technical layer, but it works best paired with a payment verification process and human awareness, because BEC is ultimately a decision made by a person.