What is business email compromise?
Business email compromise (BEC) is a fraud pattern in which an attacker uses convincing business communications to induce an unauthorized action, often a transfer of money. An attacker may compromise a genuine mailbox, impersonate an executive, pose as a supplier or insert new bank details into an existing payment conversation.
BEC does not always require malware, an attachment or a lookalike domain. A message sent from a compromised legitimate mailbox may pass email authentication checks. The central question is whether the instruction was genuinely authorized, not simply whether the message passed a technical check.
Immediate response after a suspected transfer
Contact the sending bank immediately through a verified channel and ask about its fraud response and recall procedures. Notify the responsible security team and report through appropriate law-enforcement channels. Speed matters, but no recovery can be guaranteed.
Stop additional payments and verify instructions through a previously known telephone number. Preserve the original email and transaction evidence. Account containment and log collection should be coordinated with authorized administrators.
Evidence to preserve
Collect original email files, full headers, the relevant thread, invoices and payment-confirmation records. Where authorized, preserve sign-in logs, forwarding rules, delegated access and security changes. Forwarded text and screenshots alone can omit crucial context.
Compare the visible From, Reply-To, envelope sender and signing domain. Domain lookups can provide infrastructure context, but cannot identify a sender or prove account compromise by themselves.
- Record message receipt and payment times separately.
- Save original .eml files, attachments and message identifiers.
- Keep genuine and altered invoices for comparison.
- Document independently verified supplier contact and approval decisions.
- Preserve authorized mailbox logs before retention periods expire.
How to prevent business email compromise
Use multi-factor authentication, careful account administration, staff awareness and independently verified payment-detail changes. SPF, DKIM and DMARC address some domain-spoofing risks but cannot stop every fraudulent instruction from a genuine compromised account.
Report observations, source artifacts and limitations together. Do not publish victim information, bank account details or confidential links in a public case summary.
