defensiva
bec
business-email-compromise
fraude-del-ceo

What Is BEC (Business Email Compromise) and How to Prevent It

What BEC (business email compromise, or CEO fraud) is, how the email wire-transfer scam works, its variants and how to prevent it with SPF, DKIM, DMARC and process controls.

Secra Solutions teamAugust 9, 202612 min read

BEC (business email compromise), also known as CEO fraud, is an email social engineering scam in which an attacker impersonates an executive, a supplier or a trusted partner to trigger a fraudulent wire transfer or the disclosure of sensitive data. It almost never carries malware, which is why it bypasses many filters: it relies on impersonation, urgency and authority. It matters because a single believable request can divert hundreds of thousands of dollars before anyone grows suspicious.

CEO fraud is one of the highest-return categories of cybercrime for attackers, precisely because it does not need to exploit any technical vulnerability. All it takes is a well-written email, a moment of pressure and a payment process that fails to verify who is really on the other end. This article explains what BEC is, how it works step by step, its variants according to the FBI, the technical vectors that make it possible and, above all, how to prevent it by combining email authentication with process controls.

Key takeaways

  • BEC is an email scam that impersonates an executive, supplier or partner to divert money or data, usually without any malware.
  • It leverages three psychological levers (authority, urgency and trust) that make it hard to catch with traditional filters.
  • The FBI describes several variants: CEO fraud, false invoice or vendor email compromise (VEC), attorney impersonation, payroll data theft and payroll diversion.
  • Common vectors are look-alike domains, sender spoofing and genuinely compromised accounts (account takeover).
  • According to the FBI IC3 2025 report, reported BEC losses were around 3.05 billion dollars, with more than 55.5 billion accumulated over the past decade.
  • Effective prevention combines SPF, DKIM and DMARC with out-of-band verification, dual payment approval and phishing-resistant MFA.

What is BEC (business email compromise)

BEC, or business email compromise, is a fraud in which the attacker uses email to pose as a person or entity trusted within a company's financial circuit. The goal is usually one of two things: to get someone with payment authority to send a wire transfer to an attacker-controlled account, or to obtain sensitive information (tax data, payroll, credentials) that is monetized later.

The trait that sets BEC apart from other threats is that it rarely includes a malicious attachment or a link to malware. It is pure social engineering. The attacker studies the organization, identifies who authorizes payments and whose orders are obeyed, and crafts a message that looks legitimate. Because there is no malicious payload to analyze, many antivirus filters and sandboxes have nothing to detect, and the email lands cleanly in the inbox.

Why CEO fraud works so well

CEO fraud exploits well-known human biases. Authority makes an employee hesitate to question an order that appears to come from a superior. Urgency (a confidential deal, a payment due today, an executive traveling with no phone access) shrinks the time available to verify. And trust in a regular supplier makes a change of bank account seem routine. When the three levers combine, even an experienced professional can fall for it.

This is the same psychological terrain that phishing exploits in general, and BEC is in fact a highly targeted variant of it. It helps to first understand what social engineering is in order to recognize how the attacker manipulates the victim's decision before they even hit "reply".

How a BEC attack works step by step

While every campaign varies, most BEC attacks follow a recognizable sequence.

Reconnaissance

The attacker gathers public information about the company: org chart, executive names, suppliers, corporate email addresses and communication patterns. Professional social networks, press releases and the corporate website itself provide almost everything needed. This phase decides who to impersonate and who to target.

Impersonation or compromise

With the target clear, the attacker prepares the channel. They may register a look-alike domain (typosquatting), forge the sender header (spoofing) or, in the most dangerous cases, compromise a real account through targeted phishing or spear phishing. When the email comes from a genuine mailbox, the fraud is almost indistinguishable from legitimate communication.

Request and pressure

The message arrives. It may be an urgent transfer order signed by the "CEO", a supplier invoice with a new account number, or a request from the "attorney" handling a confidential acquisition. The tone conveys haste and discretion to keep the victim from checking with anyone else.

Execution and laundering

If the victim executes the transfer, the money is moved quickly through intermediary accounts, often overseas, to make recovery difficult. In data-theft cases, the information is later used for tax fraud or to prepare follow-up attacks.

BEC variants according to the FBI

The FBI classifies business email compromise into several variants, all sharing the same impersonation root but with different objectives.

CEO fraud

The attacker impersonates a senior executive and orders a finance employee to make an urgent transfer. This is the variant that gives the fraud its popular name.

False invoice or vendor email compromise (VEC)

Known as vendor email compromise (VEC), it consists of posing as a regular supplier to send an apparently legitimate invoice with a modified account number. It often relies on the prior compromise of the supplier's account, which lets the attacker reply within real threads.

Attorney impersonation

The attacker poses as a law firm or legal advisor handling a sensitive, confidential matter, appealing to discretion to discourage verification.

Payroll data theft

Instead of money, the target is employees' personal and tax data, used for identity fraud or fraudulent tax filings.

Payroll diversion

The attacker poses as an employee and asks HR to change the bank account where their salary is deposited, redirecting the payment to an account under their control.

Technical vectors behind BEC

Behind the social engineering there is always a technical mechanism that lends the email credibility. Knowing them helps decide which defense to apply.

Look-alike domains (typosquatting)

The attacker registers a domain almost identical to the legitimate one, changing a letter, adding a hyphen or using a different extension. At a glance, secra-es.com or secna.es can pass for authentic. This vector requires no compromise; it simply bets that the victim will not look at the address closely.

Sender spoofing

When a domain does not publish correct authentication records, it is possible to forge the "From" field so the email appears to come from the legitimate domain. This is where SPF, DKIM and DMARC come in, as we cover in the prevention section.

Genuinely compromised accounts (account takeover)

The hardest case to detect. The attacker controls a genuine mailbox, almost always after stealing credentials via phishing or adversary-in-the-middle techniques. Modern campaigns use proxies that intercept the session to bypass the second factor, as we explain in AiTM phishing and session hijacking to bypass MFA. With the account taken over, the attacker reads prior emails, learns the victim's style and replies within legitimate threads, making the fraud nearly undetectable to the recipient.

It also pays to watch emerging threats that reinforce the credibility of the deception, such as synthetic voice or video. Understanding what a deepfake is and its threats to businesses helps anticipate the evolution of CEO fraud toward channels beyond email.

What BEC costs: FBI IC3 2025 report data

The economic impact of BEC is among the highest across all cybercrime. According to the FBI IC3 2025 report, roughly 24,768 complaints related to business email compromise were recorded, with reported losses close to 3.05 billion dollars, a figure up from 2024. The average loss per incident stood at around 137,000 dollars, which illustrates why a single case can be devastating for an organization.

For perspective, the same report puts accumulated BEC losses at more than 55.5 billion dollars over the past decade. Meanwhile, SpiderLabs observed a 15% increase in the volume of BEC emails during 2025, a sign that the threat is not only persisting but intensifying. These figures should be read as reported losses: the real volume is very likely higher, since many incidents go unreported.

How to prevent BEC

Effective defense against BEC combines two complementary layers: technical email authentication to make impersonation harder, and process controls so that no transfer depends on a single email.

Email authentication: SPF, DKIM and DMARC

The first line is to publish and correctly maintain the three email authentication standards. SPF defines which servers may send on behalf of your domain, DKIM cryptographically signs messages, and DMARC states what to do when an email fails verification. A DMARC policy with p=reject causes spoofed emails from your domain to be rejected before they reach the recipient, closing off direct spoofing. We recommend reviewing in detail how they are configured in our guide on SPF, DKIM and DMARC for email authentication.

Bear in mind that authentication protects against forgery of your own domain, but not against look-alike domains or compromised accounts. It is therefore a necessary condition, not a sufficient one.

Out-of-band verification

The golden rule against wire-transfer fraud: any change of bank account or unusual payment must be verified through a channel other than the email that originated the request. A call to the supplier's known number (not the one that appears in the suspicious email) defeats the vast majority of BEC attacks. Out-of-band verification is probably the single most cost-effective control on this list.

Dual payment approval

Requiring that no transfer above a certain threshold be executed without approval from two people dramatically reduces risk. Even if an attacker deceives one employee, they must also deceive a second, which multiplies the chances that someone spots the anomaly.

External email tagging and look-alike domain detection

Configuring the email system to visibly tag messages arriving from outside the organization helps employees avoid mistaking a look-alike domain for an internal one. In parallel, monitoring the registration of domains similar to yours lets you detect campaign preparations before they materialize.

Phishing-resistant MFA

To prevent account compromise (the most dangerous vector), any second factor is not enough. AiTM campaigns bypass SMS or app codes. What is needed is phishing-resistant MFA, based on standards such as FIDO2 or physical security keys, which binds authentication to the real domain and cannot be replayed through a malicious proxy.

Training and awareness

Technology reduces the attack surface, but the final link is the person. Regular training that teaches how to recognize the signs of CEO fraud, together with drills, keeps everyone's guard up. As a complement, review our guides on how to avoid phishing and the different types of phishing to strengthen your team's security culture. BEC is not the only fraud family that leans on email and the web: techniques such as malvertising and SEO poisoning show that awareness must span every channel.

Frequently asked questions

What is the difference between BEC and regular phishing?

Phishing is a broad term for any email deception, often mass-scale and with malicious links or attachments. BEC is a highly targeted, malware-free variant that impersonates a specific trusted person (an executive or supplier) to trigger a transfer or the disclosure of data. BEC bets on credibility and an existing relationship, not on volume.

Why does BEC bypass email filters?

Because it usually includes neither malware nor malicious links to analyze. It is plain text requesting an apparently legitimate action. Signature-based filters or sandboxes find nothing suspicious, so the email reaches the inbox. Defense must focus on authentication, context and process, not just content detection.

Are SPF, DKIM and DMARC enough to stop BEC?

Not on their own. They protect against direct spoofing of your domain, which is an important vector, but they do not stop look-alike domains or genuinely compromised accounts. They are essential as a foundation, but must be combined with out-of-band verification, dual payment approval and phishing-resistant MFA.

What is VEC or vendor email compromise?

It is the BEC variant in which the attacker impersonates a regular supplier, often after compromising their email account, to send an apparently legitimate invoice with a modified account number. Because they reply within real threads, it is especially hard to detect without out-of-band verification.

How do I verify a supplier's bank account change?

Never by replying to the email requesting the change. Contact the supplier through a different, previously known channel, such as their usual phone number, and confirm the new account number with an identified person. This single step defuses most false-invoice fraud.

Does CEO fraud only affect large companies?

No. Although the FBI IC3 2025 figures reflect multimillion-dollar losses, BEC affects organizations of any size, including small businesses, local governments and nonprofits. Any entity that makes transfers and has a payment circuit is a potential target, and smaller ones often have fewer controls.

Get in touch with Secra

Secra is an offensive cybersecurity company with its own CVE research program (CVE-2025-40652 in CoverManager and CVE-2023-3512 in Setelsa ConacWin CB, both published in the NVD and INCIBE-CERT). We assess how a real attacker would attempt to impersonate your organization and put your email controls and payment processes to the test before the adversary does. If you want to strengthen your defense against CEO fraud, get in contact with our team.

About the author

Secra Solutions team

Ethical hackers with OSCP, OSEP, OSWE, CRTO, CRTL and CARTE certifications, 7+ years of experience in offensive cybersecurity, and authors of CVE-2025-40652 and CVE-2023-3512.

Share article