166 terms · 75/46/45
Threat № 028 · class: social eng.

Business Email Compromise

Business email compromise is not an ordinary fake email. The attacker breaks into business correspondence, or imitates it well enough that somebody in the company believes the request comes from the director, from finance, from a supplier, a lawyer or a partner. The aim is usually money, but it can also be a confidential document, a change of payment details, or an opening for the next phase of the attack.

Term

description · examples · notes

Business email compromise is not an ordinary fake email. The attacker breaks into business correspondence, or imitates it well enough that somebody in the company believes the request comes from the director, from finance, from a supplier, a lawyer or a partner. The aim is usually money, but it can also be a confidential document, a change of payment details, or an opening for the next phase of the attack.

Description

BEC is dangerous because it often does not look technically dangerous. No attachment, no malicious link, no obvious malware. The message can be short, polite and businesslike. "Can this go out today?", "The supplier has changed their account", "This stays between us until the deal closes." The attack does not hit the computer; it hits the procedure, the trust, and the habit of settling urgent requests without many questions.

The worst cases arise when an account really is compromised. Then the message does not come from a lookalike domain but from the real account, inside a real conversation, at the right moment. The attacker reads the correspondence, waits for an invoice or an agreement on payment, and changes only what they need: the account number, the payment instruction, or the address the data is sent to. From the outside it all looks like ordinary business, until the money goes to the wrong place.

Examples

  • Finance receives an email that looks like a message from the director: the payment has to go out today, outside the standard procedure, because the deal is confidential and urgent.
  • A supplier's account is compromised. Out of a real conversation comes an invoice with the same amount, the same description, and a changed account number.
  • The attacker registers a domain that differs by one letter and sends a request to change the payment instructions. In a rush and on a phone screen, the difference is easy to miss.

Notes

  • With BEC the most important protection is not another filter but a procedure nobody skips. Every change of account details and every unusual payment has to be confirmed through another channel, on a number or contact known in advance.
  • If a message asks for urgency, confidentiality and a way around the usual approval flow, that is not business efficiency but an alarm.

Mentioned in the news

Composite
Wikipedia

Techniques

carried out with 3

Techniques used to carry it out. Select one to open its page.

Defenses

countered by 6