What Is Business Email Compromise?
Some of the most damaging email attacks don't contain malware at all. They look like ordinary business conversations: an invoice, a wire request, a vendor payment change, or a message that appears to come from someone you trust.
Business Email Compromise in plain English
Business Email Compromise (BEC) is a form of fraud or social engineering in which criminals impersonate or compromise trusted business identities to convince someone to transfer money, change payment information, disclose sensitive information, or take another unauthorized action.
BEC may involve a compromised real email account, an impersonated or spoofed identity and deceptive domain, or a combination of technical compromise and social engineering. It does not necessarily require malware or ransomware. Sometimes the attacker is simply trying to convince an authorized employee to perform an otherwise legitimate action, just for the wrong reason.
The computer may do exactly what the employee asks it to do. The problem is that the employee was deceived about who was asking.
BEC vs. phishing: what's the difference?
Phishing is a broader category of deceptive communication. Business Email Compromise typically involves business identity, trust, and financial or sensitive business processes. The categories can overlap.
Generic phishing
A broadly distributed malicious or deceptive message, often sent to many people at once, hoping a small number will click.
Credential phishing
An attempt to steal usernames, passwords, or authentication information, often through a fake sign-in page.
Business Email Compromise
Uses a trusted business identity or relationship to manipulate a business process, such as a payment or a vendor change.
A credential-phishing email can compromise an employee's Microsoft 365 account, which may then be used as part of a BEC attack. The two are related, not mutually exclusive.
What does a BEC attack actually look like?
These are hypothetical, fictional scenarios to show how BEC can unfold. They are not actual Titan clients.
Illustrative Examples, Not Actual Titan Clients
The vendor banking change
A company receives an email that appears to come from a familiar vendor explaining that the vendor has changed banks and asking the business to use new payment instructions for future invoices. Without verifying the request through another trusted channel, an employee updates the vendor's payment information. The next legitimate payment is sent to an account controlled by the criminal.
The executive request
An employee receives what appears to be a message from the owner or an executive requesting an urgent payment. The message creates urgency and discourages normal verification, often citing a confidential situation or a meeting that prevents a phone call.
The compromised email conversation
An attacker obtains access to a legitimate mailbox and observes existing business correspondence. The attacker then inserts fraudulent payment instructions into an existing, familiar conversation, which can be far more convincing than an obvious fake email arriving out of nowhere.
Payroll diversion
Someone impersonating an employee requests that payroll direct-deposit information be changed. HR and payroll processes are therefore part of BEC defense, not only accounts payable.
These examples focus on recognition and prevention. They do not provide instructions for carrying out any of these attacks.
How can an email look completely legitimate?
Look-alike domains
A domain may visually resemble the legitimate company's domain, with a subtle change such as an extra letter, a swapped character, or a different top-level extension.
Display-name impersonation
The displayed sender name can sometimes create the impression that a message came from someone familiar, even when the underlying email address does not match.
Compromised real accounts
If an actual mailbox has been compromised, messages can originate from a legitimate account, which bypasses many obvious signs of spoofing.
Existing conversation context
An attacker with unauthorized mailbox access may obtain contextual information from prior correspondence that makes fraudulent requests more convincing.
This is why "the email looked real" is not always enough verification for a sensitive financial request.
Why Microsoft 365 security matters
Microsoft 365 often contains email, identity, contacts, calendars, SharePoint, OneDrive, Teams, and business documents. The accounts that access it are valuable to an attacker because compromising a real account can bypass many obvious signs of spoofing.
Enabling one Microsoft security setting does not make BEC impossible. Strong identity protection, MFA, reviewed permissions, and monitoring together reduce the likelihood that a real account can be quietly taken over. Take the Microsoft 365 Security Assessment to see where configuration gaps may exist.
The payment verification problem
Technology alone cannot eliminate BEC risk because many attacks target business processes rather than technology. A business should have defined verification procedures for high-risk changes.
Out-of-band verification
Verify sensitive changes through a separate, previously trusted communication method. For example, if banking instructions arrive by email, verify the change using a known phone number already on record, not contact information supplied in the suspicious message itself.
An email should not be allowed to rewrite your payment process by itself.
Urgency is a security signal
BEC attacks often create pressure to act quickly and discourage normal verification. Common phrases include:
Urgency alone does not prove fraud, because legitimate business is often urgent. The concern is the combination of urgency plus an unusual request plus a request to bypass normal procedure. When those three appear together, slow down and verify.
BEC warning signs
Do not rely on any single warning sign. Several appearing together is a stronger signal.
Would you verify this?
A short educational exercise with fictional business situations. No contact information is required to see the answers.
Scenario 1: A long-term vendor emails saying its banking information changed and asks you to update ACH details. What should you do?
Scenario 2: An email that appears to be from the company owner asks you to process an urgent wire transfer and says not to call because they are in a meeting. What is the safest response?
Scenario 3: An employee emails HR asking to change their direct-deposit information for payroll. What should HR do?
Scenario 4: You receive a Microsoft 365 sign-in alert for an account at an unusual time and location. What should you do?
Scenario 5: An existing email thread with a vendor suddenly includes new payment instructions. What should you do?
Scenario 6: An unexpected invoice arrives from a sender you recognize but with slightly different bank details than usual. What should you do?
SPF, DKIM and DMARC: where do they fit?
SPF - Sender Policy Framework
Helps identify which systems are authorized to send email for a domain.
DKIM - DomainKeys Identified Mail
Adds cryptographic authentication to help verify that a message was authorized and was not altered in transit.
DMARC - Domain-based Message Authentication, Reporting & Conformance
Builds on SPF and DKIM and allows domain owners to establish handling and reporting policies for authentication failures.
These technologies can help reduce certain forms of domain spoofing but do not eliminate BEC, particularly when a legitimate mailbox is compromised or a deceptive look-alike domain is used. Email authentication is one layer, not a complete BEC defense.
What if the attacker has the real mailbox?
When a legitimate account is compromised, the situation becomes an identity and security incident, not simply a spam problem. Potential defensive and response considerations include:
This guidance is high-level. It does not provide instructions for bypassing authentication or maintaining unauthorized mailbox access.
What should we do if money was sent?
Time can matter significantly in financial fraud response. If money was sent to the wrong account, promptly contact:
Recovery is not guaranteed, and this is not legal advice. Involve legal and insurance resources promptly.
Technology controls + business controls
Technology Controls
- MFA
- Identity monitoring
- Email security filtering
- Endpoint security
- Microsoft 365 security configuration
- Logging and alerting
- SPF, DKIM and DMARC
- Secure administrator practices
Business Controls
- Payment verification
- Dual approval where appropriate
- Vendor-change verification
- Payroll-change verification
- Employee awareness
- A defined escalation process
- Incident-response procedures
BEC defense works best when cybersecurity controls and financial and business procedures reinforce each other.
BEC readiness check
Answer honestly. No contact information is required to see your result.
Is MFA required for Microsoft 365?
Are suspicious sign-ins monitored?
Are vendor banking changes independently verified?
Are payroll changes independently verified?
Are large or unusual payments subject to additional approval?
Are SPF, DKIM and DMARC configured appropriately?
Do employees know how to report suspicious email?
Are former employee accounts promptly disabled?
Does someone review security alerts?
Does the business have an incident-response process?
Answer all 10 questions to see your readiness summary.
A statistic worth knowing
Business email compromise remains one of the highest-loss cybercrime categories reported to the FBI.
The FBI's Internet Crime Complaint Center reported that BEC caused approximately $2.9 billion in adjusted losses in its 2023 reporting year, making it one of the costliest cybercrime categories tracked by IC3. These figures reflect reported losses nationwide and are not specific to the Treasure Coast.
Source: FBI / IC3, 2023Keep exploring
Microsoft 365 Security Assessment
A free self-assessment scoring your Microsoft 365 security posture.
ExploreCybersecurity Services
Email security, identity protection, MFA, endpoint security, and monitoring.
ExploreHow Small Businesses Get Hit With Ransomware
How ransomware attacks begin and progress, and how layered defenses interrupt them.
ExploreCybersecurity Risk Report
Verified national data translated into practical guidance for Treasure Coast businesses.
ExploreWhat Happens During an IT Assessment?
A transparent look at what a professional assessment reviews.
ExploreCase Studies
Anonymized client stories, including security and recovery engagements.
ExploreHow Titan helps reduce BEC risk
Titan IT Management helps small and midsized businesses strengthen Microsoft 365 security, email security, identity protection, MFA, endpoint security, security monitoring, employee security awareness, and the cybersecurity processes that BEC targets. We serve businesses throughout Florida's Treasure Coast, including Stuart, Port St. Lucie, Jensen Beach, and Fort Pierce.
We do not claim to prevent every BEC incident, because no honest provider can. What we do is reduce the likelihood of compromise, detect suspicious activity earlier, and help build the business processes that make a fraudulent email far less likely to succeed.
Sources & further reading
Every statistic on this page is traceable to these sources. Where a number could not be reliably verified, it was left out.
FBI / IC3
Internet Crime Report (2023)
The FBI's annual Internet Crime Complaint Center report, documenting business email compromise, ransomware, and other cybercrime trends reported to IC3. BEC accounted for approximately $2.9 billion in adjusted losses in the 2023 reporting year.
View sourceCISA
Business Email Compromise (2024)
CISA guidance on business email compromise, including prevention recommendations, warning signs, and reporting resources for organizations.
View sourceNIST
Cybersecurity Framework (2024)
The NIST Cybersecurity Framework, widely used to organize cybersecurity activities across identify, protect, detect, respond, and recover, including email and identity security.
View sourceMicrosoft
Microsoft Cybersecurity Policy (2024)
Microsoft guidance on email security, identity protection, and defending against business email compromise within Microsoft 365 environments.
View sourceUnderstand how BEC works so you can interrupt it.
Business Email Compromise is serious, but it is not mysterious. Titan helps businesses across the Treasure Coast strengthen email security, Microsoft 365 identity protection, and the payment-verification processes that BEC relies on, without fear-based marketing.
