Business Email Compromise (BEC)
Definition
A fraud in which an attacker impersonates a trusted executive, finance counterpart, or supplier over email to authorise fraudulent wire transfers or redirect payments. BEC attacks frequently follow a period of silent email account access in which the attacker studies payment workflows before striking.
- Also known as
- CEO fraud, wire transfer fraud
- Precursor
- Often follows silent email account compromise
- Goal
- Fraudulent wire transfer or redirected payment
- Investigative focus
- Email headers, login logs, and payment workflow timeline
Common questions
Why do BEC attackers spend time inside an email account before acting?+
The silent access period lets the attacker study real invoicing patterns, vendor relationships and the language a genuine executive or supplier uses, so the eventual fraudulent request blends in with normal correspondence and is harder for staff to spot.
What evidence typically distinguishes BEC from a spoofed external email?+
True account compromise leaves login and mailbox-rule artifacts, such as unfamiliar IP addresses, new forwarding rules, or read-then-deleted messages, inside the victim's own account, whereas a spoofed email leaves no trace inside the impersonated party's mailbox at all.
Related terms
- Advance-Fee Fraud
- A scheme in which the victim is promised a large future payment in exchange for an upfront fee. Variants include the classic...
- Blockchain Analytics
- The use of tools such as Chainalysis, Elliptic, or CipherTrace to trace cryptocurrency fund flows across a public ledger. Because most public...
- Card-Not-Present (CNP) Fraud
- Fraudulent use of payment card data in a transaction where the physical card is absent, typically an online or telephone purchase. The...
- Money Mule
- A person who receives fraudulently obtained funds into their bank account and transfers them onward, taking a commission. Mules may be witting...
- Phishing
- A mass deception attack delivered by email, SMS (smishing), or voice call (vishing) in which the attacker impersonates a trusted entity to...