Skip to content

Business Email Compromise

Business email compromise (BEC) uses email or an adjacent business communication channel to manipulate an organisation into taking an unauthorised action.

Payments and invoice fraud are common outcomes, but BEC also targets supplier records, payroll information, sensitive documents, account access, approvals, procurement activity, and other business processes. The apparent sender may be an executive, internal function, supplier, contractor, customer, or other trusted business contact.

Attackers use lookalike domains, spoofed display names, compromised mailboxes, altered documents, existing conversation history, and cross-channel follow-up to place a fraudulent request inside ordinary work. Routine business activity gives the request its legitimacy context.

Trust, delegation, and time-sensitive workflows widen the exposure. A brief, professionally written message works when the requested action resembles normal administration and lands at a moment where delay carries an apparent operational cost.

BEC appears in payment, payroll, supplier, procurement, legal, HR, project, and document-handling workflows. Delivery may begin through email and continue through collaboration platforms, messaging applications, or phone contact. What distinguishes it from broader phishing is that the fraudulent request resembles ordinary administration within one of these processes, so a credible message can introduce an unauthorised change to money, access, records, or approval authority without ever looking out of place.

Common patterns include:

  • changes to supplier, employee, or customer records
  • altered invoices or payment instructions
  • payroll redirection
  • urgent purchases or approvals
  • release of sensitive business information
  • executive, legal, HR, finance, or procurement impersonation
  • messages sent from a compromised mailbox
  • new requests introduced into an established business thread
  • movement to a newly supplied email address, phone number, or personal account

BEC indicators are often concentrated in the requested business action and the path used to authorise it. Professional wording, authentic thread history, or a real sending account may coexist with an unauthorised request.

IndicatorWhat to look for
Unexpected change requestPayment details, payroll information, supplier records, contact details, delivery instructions, account ownership, or other business records are changed without an established trigger.
Unusual business actionAn emergency purchase, document release, sensitive data transfer, account change, or approval falls outside the normal pattern for the workflow.
Process pressureSpeed, confidentiality, or special handling is used to reduce normal checks or review.
Identity mismatchSender address, reply-to address, display name, writing style, role, timing, or communication channel differs from established patterns for the claimed sender.
Channel shiftThe interaction moves to a new email address, phone number, personal account, messaging application, or other contact path.
Record inconsistencyInvoice details, purchase orders, supplier information, payroll records, contract details, document references, or account information conflict with existing records.
Thread continuity changeAn established conversation introduces a new request, attachment, payment path, contact detail, or timing pattern without a corresponding business reason.
Authority used to suppress challengeSeniority, legal sensitivity, customer pressure, or supplier importance is relied on to discourage review.
Verification avoidanceCallback checks or secondary confirmation are discouraged, or the contact path supplied in the request is presented as the verification path.