SardineCon SF/2026

Learn More
Fraud types4 min de leitura

O que é Business email compromise (BEC)?

SUBSCRIBE

Business email compromise is impersonating an executive, vendor, or partner through a spoofed or hacked email to trick staff into redirecting payments, changing bank details, or leaking data. It turns a trusted email into a large, fast loss that is hard to claw back.

What is BEC, in plain English?

Business email compromise is a scam that weaponizes trusted business relationships. The fraudster poses as someone the target already trusts, an executive, a vendor, or a partner, using either a spoofed lookalike email address or a genuinely hacked mailbox. From that position of trust they instruct an employee to send a wire, change a vendor's bank details, or hand over sensitive data.

What makes BEC so effective is that it exploits process and psychology, not technology. There is often no malware and no system breach on the victim's side; there is just a convincing email asking someone to do their normal job in a slightly abnormal way. The request usually carries urgency and secrecy, a deal that must close today, a payment that cannot wait, a matter to keep quiet, which discourages the recipient from pausing to verify.

For fraud and AML teams, BEC is dangerous on both ends. On the sending side, an employee authorizes a legitimate-looking payment. On the receiving side, a bank sees a wire or ACH going to a newly changed account. Because the payment is authorized and moves fast, recovery is difficult, which is why prevention and verification matter far more than after-the-fact investigation.

How a BEC attack unfolds

  1. Recon — Study the target. The attacker learns who pays whom, which vendors exist, and when key executives travel or are hard to reach.
  2. Impersonate — Take a trusted identity. They spoof a lookalike address or hack a real mailbox belonging to a boss, vendor, or partner.
  3. Request — Make the ask. A wire, a bank-detail change, or a data handover is requested, wrapped in urgency and secrecy.
  4. Divert — Funds leave. The payment lands in the fraudster's account and is quickly moved onward through mules before anyone verifies.

Common BEC variants

Variant

The setup

CEO fraud

Impersonates a senior executive pressuring staff into an urgent, off-process payment.

Invoice redirection

Poses as a known vendor and asks to update the bank account on file for future payments.

Payroll diversion

Impersonates an employee requesting a change to their salary deposit details.

Attorney or deal fraud

Poses as a lawyer or partner on a confidential, time-sensitive transaction needing a fast wire.

What it looks like in practice

In practice

An accounts-payable clerk receives an email that appears to be from a long-standing supplier. The supplier says they have switched banks and asks that the next payment go to a new account. The email thread even quotes an earlier genuine message, because the vendor's mailbox was quietly compromised.

The clerk updates the payee and schedules the next invoice payment. On the bank side, a familiar vendor's payment suddenly routes to a brand-new account. The tells were all present: a change to a known vendor's bank details, a request delivered by email only, and no independent confirmation. Because company policy required calling the vendor back on a previously known number before any bank-detail change, the clerk phones the real supplier, learns they never asked to switch banks, and the payment is stopped before it leaves.

Why it matters to operators

BEC produces some of the largest single fraud losses in payments, because the amounts are business-sized and the payments are authorized by a real employee doing their job. There is no anomalous login to catch and often no malware to detect. The defense has to live in process: verifying any payment-detail change through a channel other than the email that requested it.

Concretely, that means calling back on a known number to confirm any change to bank details, requiring two approvers on wires above a threshold, and scoring payee risk so a first-time or newly changed payee triggers extra scrutiny. The most common variants, CEO fraud and invoice redirection, both fail against a simple, enforced rule: never change where money goes based on an email alone.

What to watch

  • New or changed payee. Wires or ACH to a newly added account, or a change to a known vendor's bank details, deserve independent verification.
  • Urgency and secrecy. Requests that push speed and confidentiality are engineered to stop the recipient from checking.
  • Lookalike addresses. Domains and display names that resemble a real executive or vendor but differ by a character or two.
  • Email-only instructions. A payment change that arrives solely by email, with no call or in-person confirmation, is a core red flag.
  • Timing around absences. Requests conveniently timed for when the impersonated executive is traveling or unreachable.

Quick questions

Is BEC a hacking attack?

Sometimes the attacker hacks a real mailbox, but often they simply spoof a lookalike address. Either way the core exploit is trust and process, not a technical breach of the victim company's systems.

How is BEC different from phishing?

Phishing usually casts a wide net to steal credentials or drop malware. BEC is targeted impersonation of a trusted party to trigger a specific payment or data action, often with no malicious link at all.

What is the single best control?

Out-of-band verification: confirming any payment or bank-detail change by calling a known, pre-established number rather than replying to the email. It defeats most BEC because the fraudster does not control that channel.

Why is BEC money so hard to recover?

The payment is authorized and often a wire, which settles fast and is quickly layered through mule accounts. Speed of onward movement leaves a narrow window to claw funds back.

What is CEO fraud's relationship to BEC?

CEO fraud is a specific BEC variant where the impersonated party is a senior executive, using authority and pressure. Invoice redirection is another common variant targeting vendor payments.

Can banks help stop BEC?

Yes. Scoring payee risk, flagging first-time and newly changed payees, and adding friction to large wires give the receiving and sending banks a chance to catch a diverted payment before it settles.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

O que saber junto com Business email compromise (BEC)