Business email compromise (BEC): What it is and ways to help protect your business from it
Learn how to spot BEC tactics and reduce the risk of potential cybercrimes. Presented by Chase for Business.

- Business email compromise (BEC) is a cybercrime where attackers use email to deceive organizations and convince employees to transfer funds or provide sensitive data.
- BEC can affect businesses of all sizes and potentially result in financial loss and exposure of confidential information.
- Knowing common tactics used in BEC attacks and strengthening your company's cybersecurity can help reduce your risk.
Business email compromise is a rising cyber threat that can disrupt your company's cash flow and operations. Understanding how BEC works, ways to identify suspicious behavior and which steps to take may help you safeguard your organization against this type of threat.
What is business email compromise (BEC)?
Business email compromise (BEC) is a cyberattack in which criminals use deceptive emails to trick employees into transferring funds, data or sensitive details. Unlike broad phishing campaigns that rely on malicious links or attachments, BEC is highly targeted and text-based, which is why it often bypasses standard IT security filters. Attackers frequently research their intended victims, impersonate senior leaders or partners and craft convincing messages to gain trust.
BEC can result in significant harm to businesses. While financial loss is a possible outcome of BEC, attacks may also reveal sensitive company data, interrupt operations and damage your reputation. The consequences can also go beyond immediate financial impact, potentially affecting customer confidence, vendor relationships and your business's future stability.
Almost any business can be targeted. Smaller organizations might lack specialized cybersecurity resources to help prevent BEC, while larger businesses may be targeted due to complex accounts payable structures.
Common BEC tactics and types
Cybercriminals may deploy various techniques for business email compromise, often customizing their approach to the organization or individual target.
Here are a few common types of BEC scams:
- CEO or executive impersonation: Attackers pose as company leaders, sending urgent requests to staff for wire transfers or confidential data. This often happens when the executive is known to be traveling or unavailable to verify the request.
- Vendor email compromise: Cybercriminals gain control of a vendor's actual email account. They may monitor active email threads and step in at the last minute to redirect payments or request alterations to ACH routing instructions.
- Email account compromise: Attackers access a real employee's email inbox and use it to request money or sensitive information from colleagues or partners.
- Attorney impersonation: Criminals pretend to represent your legal team, often seeking immediate payments or private business information about time-sensitive legal matters.
- False invoice scheme: Attackers submit invoices that seem legitimate, tricking staff into paying for goods or services not actually provided. These often arrive right before weekends or holidays when staff are rushed.
These methods depend on exploiting trust and authority. By pretending to be someone familiar or respected, attackers can more easily make their emails appear credible.
Ways to spot BEC
Detecting a business email compromise attempt may require noticing small clues. Certain employees—such as executives, HR professionals, IT staff and new hires unfamiliar with standard processes—may be more frequently targeted.
Common signs of BEC attacks include:
- Unusual requests: Sudden or urgent requests for wire transfers, gift cards or confidential info, especially from high-ranking executives or the legal team.
- Minor changes in email addresses: It can be helpful to pay attention to subtle changes in email addresses, including extra letters, character swaps or slightly altered domains (e.g., @company.com vs @cornpany.com).
- Pressure to respond quickly: Messages stressing urgency or secrecy or those aiming to discourage employees from double-checking requests with others may be a sign of BEC.
- Attempts to avoid standard procedures: These emails may provide directions to overlook typical approval steps, bypass accounting software or communicate outside official channels.
- Unfamiliar language or tone: Email wording that seems odd or inconsistent with the sender's normal communication style can be a sign of BEC.
Ways to protect your business from BEC
Defending your company against business email compromise could involve a mix of technology, procedures and employee education. Consider the following measures:
Verifying requests through alternative means
Confirming fund transfers or changes to vendor payment instructions by phone or in person can help you avoid potential scams. It is generally recommended to use trusted contact information on file, not the phone number provided in the email.
For example, if a long-standing supplier emails a sudden request to update their ACH routing details, you may want to call your established contact at that company using a phone number from a previous, verified invoice. Relying solely on the contact details in the new email may be risky, as attackers might update email signatures to route verification calls to themselves.
Implementing dual control
You may want to require multiple authorizations for financial transactions or account changes. Having a second person review and approve wire transfers can add an important layer of operational security.
In practice, this often looks like a "maker-checker" system where one employee initiates a payment, and a manager or executive must separately approve it in the banking portal. This separation of duties can help catch fraudulent requests that might slip past a single busy employee.
Adopting multi-factor authentication (MFA)
MFA can strengthen security, which may make it more difficult for attackers to access email accounts even if passwords are stolen. By requiring a second form of verification—such as a code from an authenticator app or a physical security token—you can help block unauthorized access. If an attacker manages to guess or steal an employee's password, MFA can serve as a critical barrier to prevent them from logging in and launching an internal BEC attack.
Limiting publicly available information
Consider minimizing the details about employees, roles and internal processes shared on your company's website or social media. Cybercriminals might scour professional networking sites to understand your organizational chart and identify who handles accounts payable. They may also look for public posts about executives traveling or attending conferences, using that absence as an opportunity to send a fake urgent request to employees.
Training employees regularly
You may want to offer consistent training on BEC scams, phishing and social engineering, stressing vigilance with email requests. Education is often most effective when it is ongoing rather than a once-a-year event. Consider running simulated phishing exercises to help staff practice identifying suspicious emails in a safe environment. Training can help employees feel empowered to pause and question unusual requests, even when those requests appear to come from the CEO.
Utilizing advanced email security tools
Consider implementing email filtering, anti-phishing solutions and monitoring systems to identify and block suspicious emails. Modern email security platforms can often detect anomalies, such as a sender address that is one letter off from your actual domain. Additionally, configuring email authentication protocols like DMARC, SPF and DKIM can help verify that incoming messages truly originate from the claimed sender, which may reduce the number of spoofed emails reaching your employees' inboxes.
What to do if BEC happens
If you think your company has experienced business email compromise, swift action may help contain the impact. Consider taking the following actions:
- Contacting your bank immediately: It can be helpful to get in touch with your financial institution right away if funds were transferred or account details stolen. You may want to initiate a wire recall or freeze affected accounts.
- Notifying your IT and security team: Consider informing your internal or external IT resources immediately when suspicious activity is discovered so they can secure the network.
- Resetting compromised passwords: You may want to change passwords for affected accounts and related systems as soon as possible.
- Reporting the incident: Consider reporting to law enforcement, such as the FBI's Internet Crime Complaint Center (IC3)Opens overlay, or other relevant authorities.
- Keeping evidence: It can be helpful to preserve emails, payment records and any relevant communications for investigation purposes.
Frequently asked questions
Why are BEC attacks hard to identify?
These attacks are personalized and appear legitimate, meaning they can often get past standard email security defenses because they rely on human manipulation rather than malicious software.
How do attackers choose their targets?
Attackers often target those with access to company finances or sensitive data, such as executives, accounting or HR staff, but any employee may become a target.
How do attackers know so much about my business and vendors?
Cybercriminals often gather information from publicly available sources like your company website, social media and professional networking sites. They may also compromise a single email account and read through months of historical invoices and communications to learn about your vendor relationships and payment schedules.
Can BEC attacks be prevented?
While there's no way to prevent all attacks, strong security practices, ongoing employee education and multi-factor authentication can help lower your risk.
Does cyber insurance cover BEC losses?
Coverage can vary significantly depending on your specific policy. Many standard policies may cover traditional network breaches but might exclude social engineering scams where an employee voluntarily sends money. It can be helpful to review your policy language with your insurance provider to understand your specific coverage.
How can a banking partner help prevent or mitigate BEC?
Banks may offer treasury management tools like dual control workflows and transaction alerts to help catch fraudulent payments before they leave your business bank account. If an incident occurs, they may also be able to assist with rapid response efforts such as initiating a wire recall to try to recover funds.




