Resource Guide

What Is Business Email Compromise?

Some of the most damaging email attacks don't contain malware at all. They look like ordinary business conversations: an invoice, a wire request, a vendor payment change, or a message that appears to come from someone you trust.

The Basics

Business Email Compromise in plain English

Business Email Compromise (BEC) is a form of fraud or social engineering in which criminals impersonate or compromise trusted business identities to convince someone to transfer money, change payment information, disclose sensitive information, or take another unauthorized action.

BEC may involve a compromised real email account, an impersonated or spoofed identity and deceptive domain, or a combination of technical compromise and social engineering. It does not necessarily require malware or ransomware. Sometimes the attacker is simply trying to convince an authorized employee to perform an otherwise legitimate action, just for the wrong reason.

The computer may do exactly what the employee asks it to do. The problem is that the employee was deceived about who was asking.

Comparing Attack Types

BEC vs. phishing: what's the difference?

Phishing is a broader category of deceptive communication. Business Email Compromise typically involves business identity, trust, and financial or sensitive business processes. The categories can overlap.

Generic phishing

A broadly distributed malicious or deceptive message, often sent to many people at once, hoping a small number will click.

Credential phishing

An attempt to steal usernames, passwords, or authentication information, often through a fake sign-in page.

Business Email Compromise

Uses a trusted business identity or relationship to manipulate a business process, such as a payment or a vendor change.

A credential-phishing email can compromise an employee's Microsoft 365 account, which may then be used as part of a BEC attack. The two are related, not mutually exclusive.

Illustrative Examples

What does a BEC attack actually look like?

These are hypothetical, fictional scenarios to show how BEC can unfold. They are not actual Titan clients.

Illustrative Examples, Not Actual Titan Clients

The vendor banking change

A company receives an email that appears to come from a familiar vendor explaining that the vendor has changed banks and asking the business to use new payment instructions for future invoices. Without verifying the request through another trusted channel, an employee updates the vendor's payment information. The next legitimate payment is sent to an account controlled by the criminal.

The executive request

An employee receives what appears to be a message from the owner or an executive requesting an urgent payment. The message creates urgency and discourages normal verification, often citing a confidential situation or a meeting that prevents a phone call.

The compromised email conversation

An attacker obtains access to a legitimate mailbox and observes existing business correspondence. The attacker then inserts fraudulent payment instructions into an existing, familiar conversation, which can be far more convincing than an obvious fake email arriving out of nowhere.

Payroll diversion

Someone impersonating an employee requests that payroll direct-deposit information be changed. HR and payroll processes are therefore part of BEC defense, not only accounts payable.

These examples focus on recognition and prevention. They do not provide instructions for carrying out any of these attacks.

Deceptive Appearance

How can an email look completely legitimate?

Look-alike domains

A domain may visually resemble the legitimate company's domain, with a subtle change such as an extra letter, a swapped character, or a different top-level extension.

Display-name impersonation

The displayed sender name can sometimes create the impression that a message came from someone familiar, even when the underlying email address does not match.

Compromised real accounts

If an actual mailbox has been compromised, messages can originate from a legitimate account, which bypasses many obvious signs of spoofing.

Existing conversation context

An attacker with unauthorized mailbox access may obtain contextual information from prior correspondence that makes fraudulent requests more convincing.

This is why "the email looked real" is not always enough verification for a sensitive financial request.

Cloud Identity

Why Microsoft 365 security matters

Microsoft 365 often contains email, identity, contacts, calendars, SharePoint, OneDrive, Teams, and business documents. The accounts that access it are valuable to an attacker because compromising a real account can bypass many obvious signs of spoofing.

Multifactor authentication
Identity protection
Conditional Access where appropriate
Administrator security
Email security filtering
Suspicious sign-in monitoring
Mailbox rule monitoring where applicable
Legacy authentication controls where applicable
Reviewed user permissions
Prompt account offboarding
Security logging

Enabling one Microsoft security setting does not make BEC impossible. Strong identity protection, MFA, reviewed permissions, and monitoring together reduce the likelihood that a real account can be quietly taken over. Take the Microsoft 365 Security Assessment to see where configuration gaps may exist.

Business Process

The payment verification problem

Technology alone cannot eliminate BEC risk because many attacks target business processes rather than technology. A business should have defined verification procedures for high-risk changes.

Vendor bank-account changes
Wire-transfer requests
ACH changes
Payroll direct-deposit changes
Large or unusual payments
Requests for sensitive employee information

Out-of-band verification

Verify sensitive changes through a separate, previously trusted communication method. For example, if banking instructions arrive by email, verify the change using a known phone number already on record, not contact information supplied in the suspicious message itself.

An email should not be allowed to rewrite your payment process by itself.

Social Engineering

Urgency is a security signal

BEC attacks often create pressure to act quickly and discourage normal verification. Common phrases include:

"I need this immediately.""I'm in a meeting.""Don't call me.""This is confidential.""The vendor needs payment today."

Urgency alone does not prove fraud, because legitimate business is often urgent. The concern is the combination of urgency plus an unusual request plus a request to bypass normal procedure. When those three appear together, slow down and verify.

Recognition

BEC warning signs

Unexpected payment instructions
Bank-account changes
Unusual urgency
A request to bypass normal approval
A sender domain slightly different from normal
Unusual wording or communication style
Unexpected payroll changes
Requests for secrecy
A payment destination that unexpectedly changes
New contact information provided inside the same message requesting the financial change
Authentication or sign-in alerts
Unexpected mailbox rules or forwarding behavior

Do not rely on any single warning sign. Several appearing together is a stronger signal.

Interactive Exercise

Would you verify this?

A short educational exercise with fictional business situations. No contact information is required to see the answers.

Scenario 1: A long-term vendor emails saying its banking information changed and asks you to update ACH details. What should you do?

Scenario 2: An email that appears to be from the company owner asks you to process an urgent wire transfer and says not to call because they are in a meeting. What is the safest response?

Scenario 3: An employee emails HR asking to change their direct-deposit information for payroll. What should HR do?

Scenario 4: You receive a Microsoft 365 sign-in alert for an account at an unusual time and location. What should you do?

Scenario 5: An existing email thread with a vendor suddenly includes new payment instructions. What should you do?

Scenario 6: An unexpected invoice arrives from a sender you recognize but with slightly different bank details than usual. What should you do?

Email Authentication

SPF, DKIM and DMARC: where do they fit?

SPF - Sender Policy Framework

Helps identify which systems are authorized to send email for a domain.

DKIM - DomainKeys Identified Mail

Adds cryptographic authentication to help verify that a message was authorized and was not altered in transit.

DMARC - Domain-based Message Authentication, Reporting & Conformance

Builds on SPF and DKIM and allows domain owners to establish handling and reporting policies for authentication failures.

These technologies can help reduce certain forms of domain spoofing but do not eliminate BEC, particularly when a legitimate mailbox is compromised or a deceptive look-alike domain is used. Email authentication is one layer, not a complete BEC defense.

Account Compromise

What if the attacker has the real mailbox?

When a legitimate account is compromised, the situation becomes an identity and security incident, not simply a spam problem. Potential defensive and response considerations include:

Securing the affected identity
Reviewing active sessions
Investigating suspicious sign-ins
Reviewing forwarding and mailbox rules
Reviewing other potentially affected accounts
Preserving relevant logs and evidence
Determining whether sensitive information was accessed
Following the organization's incident-response procedures

This guidance is high-level. It does not provide instructions for bypassing authentication or maintaining unauthorized mailbox access.

Incident Response

What should we do if money was sent?

Time can matter significantly in financial fraud response. If money was sent to the wrong account, promptly contact:

The business's financial institution
The organization's IT or security provider
Appropriate internal leadership
Legal and cyber-insurance resources where applicable
Law enforcement and reporting resources as appropriate

Recovery is not guaranteed, and this is not legal advice. Involve legal and insurance resources promptly.

Combined Defense

Technology controls + business controls

Technology Controls

  • MFA
  • Identity monitoring
  • Email security filtering
  • Endpoint security
  • Microsoft 365 security configuration
  • Logging and alerting
  • SPF, DKIM and DMARC
  • Secure administrator practices

Business Controls

  • Payment verification
  • Dual approval where appropriate
  • Vendor-change verification
  • Payroll-change verification
  • Employee awareness
  • A defined escalation process
  • Incident-response procedures

BEC defense works best when cybersecurity controls and financial and business procedures reinforce each other.

Interactive Self-Check

BEC readiness check

Answer honestly. No contact information is required to see your result.

Is MFA required for Microsoft 365?

Are suspicious sign-ins monitored?

Are vendor banking changes independently verified?

Are payroll changes independently verified?

Are large or unusual payments subject to additional approval?

Are SPF, DKIM and DMARC configured appropriately?

Do employees know how to report suspicious email?

Are former employee accounts promptly disabled?

Does someone review security alerts?

Does the business have an incident-response process?

Answer all 10 questions to see your readiness summary.

Why This Matters

A statistic worth knowing

Business email compromise remains one of the highest-loss cybercrime categories reported to the FBI.

The FBI's Internet Crime Complaint Center reported that BEC caused approximately $2.9 billion in adjusted losses in its 2023 reporting year, making it one of the costliest cybercrime categories tracked by IC3. These figures reflect reported losses nationwide and are not specific to the Treasure Coast.

Source: FBI / IC3, 2023
About Titan

How Titan helps reduce BEC risk

Titan IT Management helps small and midsized businesses strengthen Microsoft 365 security, email security, identity protection, MFA, endpoint security, security monitoring, employee security awareness, and the cybersecurity processes that BEC targets. We serve businesses throughout Florida's Treasure Coast, including Stuart, Port St. Lucie, Jensen Beach, and Fort Pierce.

We do not claim to prevent every BEC incident, because no honest provider can. What we do is reduce the likelihood of compromise, detect suspicious activity earlier, and help build the business processes that make a fraudulent email far less likely to succeed.

Research & Sources

Sources & further reading

Every statistic on this page is traceable to these sources. Where a number could not be reliably verified, it was left out.

FBI / IC3

Internet Crime Report (2023)

The FBI's annual Internet Crime Complaint Center report, documenting business email compromise, ransomware, and other cybercrime trends reported to IC3. BEC accounted for approximately $2.9 billion in adjusted losses in the 2023 reporting year.

View source

CISA

Business Email Compromise (2024)

CISA guidance on business email compromise, including prevention recommendations, warning signs, and reporting resources for organizations.

View source

NIST

Cybersecurity Framework (2024)

The NIST Cybersecurity Framework, widely used to organize cybersecurity activities across identify, protect, detect, respond, and recover, including email and identity security.

View source

Microsoft

Microsoft Cybersecurity Policy (2024)

Microsoft guidance on email security, identity protection, and defending against business email compromise within Microsoft 365 environments.

View source

Understand how BEC works so you can interrupt it.

Business Email Compromise is serious, but it is not mysterious. Titan helps businesses across the Treasure Coast strengthen email security, Microsoft 365 identity protection, and the payment-verification processes that BEC relies on, without fear-based marketing.