Cybersecurity

What Is Business Email Compromise (BEC)?

Learn how business email compromise scams redirect payments, how they differ from phishing, and which controls stop them.

Reviewed October 10, 2026 4 minute read Reviewed by Meta IT Pro
Part of the Cybersecurity Learning Center

Business email compromise is fraud that uses a trusted email identity—an executive, employee, vendor, or client—to trick someone into sending money or sensitive information. It often contains no malware or links, so filters may not catch it.

Key takeaways

What to know before you act

  • BEC is payment and data fraud that exploits trust in an email identity; it often contains no malicious link or attachment.
  • Process controls—callback verification and dual approval—stop BEC more reliably than email filtering alone.
  • If money has been sent, contact your bank and file an IC3 report immediately; speed improves the chance of recovery.

Why it matters

What business leaders should understand

BEC is consistently one of the most costly categories of cybercrime reported to the FBI. A single changed bank account on an invoice can redirect a large payment, and recovery depends on how quickly the bank and law enforcement are contacted.

The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.

How business email compromise works

BEC attackers study how a business pays its bills and who approves what. They then send a message that fits naturally into that process: a vendor announcing new bank details, an executive requesting an urgent wire, an attorney asking to redirect closing funds, or an employee asking payroll to change a direct-deposit account.

The message may come from a look-alike domain, a free email account using a familiar display name, or a real mailbox the attacker has compromised. When a legitimate account is used, the attacker may have read past conversations for weeks and can reply within an existing thread, making the request very convincing.

  • Vendor or invoice fraud: a supplier's bank details are 'updated' before a payment.
  • CEO fraud: an executive appears to request an urgent, confidential transfer or gift cards.
  • Payroll diversion: an employee's direct deposit is redirected.
  • Real estate and legal: closing or settlement funds are sent to a fraudulent account.
  • Data theft: HR or finance staff are asked for W-2s or employee records.

BEC versus ordinary phishing

Phishing usually tries to get someone to click a link, enter a password, or open a file. BEC typically asks a person to take a normal business action—make a payment or send information—based on a false identity. Because there may be nothing technically malicious in the message, the strongest defenses are verification habits built into payment workflows.

Controls that prevent BEC losses

Combine technical safeguards that make impersonation harder with process safeguards that catch it when it happens. The process controls matter most because they work even when the attacker controls a real mailbox.

  • Verify any change to payment details by calling a number already on file, never one in the message.
  • Require two people to approve wires and new payees above a set threshold.
  • Enable MFA on all email accounts and alert on new forwarding or inbox rules.
  • Configure SPF, DKIM, and DMARC to make spoofing your domain harder.
  • Flag external senders and look-alike domains in email.
  • Train finance, HR, and executive assistants on current BEC patterns.

What to do if a fraudulent payment was sent

Call your bank's fraud department immediately and ask them to recall the transfer and contact the receiving bank. File a complaint at ic3.gov with transaction details. Then secure the email account involved: reset the password, revoke sessions, remove malicious rules, and review what the attacker could see. Notify your cyber insurer and preserve evidence for investigators.

Practical action plan

Steps your business can take

01

Require callback verification to a known number before changing any vendor, payroll, or banking details.

02

Use dual approval for wire transfers and payments above a defined threshold.

03

Protect email with MFA, sender authentication, and alerts for new forwarding or inbox rules.

04

Contact your bank immediately and report to IC3 if a fraudulent transfer is suspected.

Recommended next steps

Continue from this article.

These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.

Warning signs

Do not ignore these indicators

  • A vendor or executive asks to change bank details by email
  • Urgent payment requests with instructions to keep the request confidential
  • New mailbox rules that hide or forward messages about invoices or payments

How Meta IT Pro can help

Related services and practical next steps

Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.

Authoritative references

Sources and further reading

These primary sources support the guidance in this article and provide additional technical or consumer information.

Need help with your IT solution?

Get practical guidance from a local IT and cybersecurity team.

Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.