Business Email Compromise
Business email compromise (BEC) uses email or an adjacent business communication channel to manipulate an organisation into taking an unauthorised action.
Payments and invoice fraud are common outcomes, but BEC also targets supplier records, payroll information, sensitive documents, account access, approvals, procurement activity, and other business processes. The apparent sender may be an executive, internal function, supplier, contractor, customer, or other trusted business contact.
Attackers use lookalike domains, spoofed display names, compromised mailboxes, altered documents, existing conversation history, and cross-channel follow-up to place a fraudulent request inside ordinary work. Routine business activity gives the request its legitimacy context.
Trust, delegation, and time-sensitive workflows widen the exposure. A brief, professionally written message works when the requested action resembles normal administration and lands at a moment where delay carries an apparent operational cost.
How it appears
Section titled “How it appears”BEC appears in payment, payroll, supplier, procurement, legal, HR, project, and document-handling workflows. Delivery may begin through email and continue through collaboration platforms, messaging applications, or phone contact. What distinguishes it from broader phishing is that the fraudulent request resembles ordinary administration within one of these processes, so a credible message can introduce an unauthorised change to money, access, records, or approval authority without ever looking out of place.
Common patterns include:
- changes to supplier, employee, or customer records
- altered invoices or payment instructions
- payroll redirection
- urgent purchases or approvals
- release of sensitive business information
- executive, legal, HR, finance, or procurement impersonation
- messages sent from a compromised mailbox
- new requests introduced into an established business thread
- movement to a newly supplied email address, phone number, or personal account
Indicators
Section titled “Indicators”BEC indicators are often concentrated in the requested business action and the path used to authorise it. Professional wording, authentic thread history, or a real sending account may coexist with an unauthorised request.
| Indicator | What to look for |
|---|---|
| Unexpected change request | Payment details, payroll information, supplier records, contact details, delivery instructions, account ownership, or other business records are changed without an established trigger. |
| Unusual business action | An emergency purchase, document release, sensitive data transfer, account change, or approval falls outside the normal pattern for the workflow. |
| Process pressure | Speed, confidentiality, or special handling is used to reduce normal checks or review. |
| Identity mismatch | Sender address, reply-to address, display name, writing style, role, timing, or communication channel differs from established patterns for the claimed sender. |
| Channel shift | The interaction moves to a new email address, phone number, personal account, messaging application, or other contact path. |
| Record inconsistency | Invoice details, purchase orders, supplier information, payroll records, contract details, document references, or account information conflict with existing records. |
| Thread continuity change | An established conversation introduces a new request, attachment, payment path, contact detail, or timing pattern without a corresponding business reason. |
| Authority used to suppress challenge | Seniority, legal sensitivity, customer pressure, or supplier importance is relied on to discourage review. |
| Verification avoidance | Callback checks or secondary confirmation are discouraged, or the contact path supplied in the request is presented as the verification path. |