Business Email Compromise (BEC)
Business Email Compromise (BEC) is a sophisticated form of email fraud where attackers impersonate executives, trusted vendors, or partners to trick employees into performing financial transactions or sharing sensitive information.
Types of BEC Fraud
- CEO Fraud: Attackers impersonate a high-ranking executive, such as the CEO, to request urgent payments or sensitive actions.
- Vendor or Supplier Fraud: Attackers pose as a regular vendor, sending fake invoices or changing payment details to divert funds.
- Account Compromise: Attackers compromise an employee's email to request unauthorized actions from colleagues.
- Attorney Impersonation: Scammers pose as attorneys handling “confidential legal matters,” requiring immediate payment.
- Payroll Diversion: Attackers impersonate employees, requesting to update direct deposit information to redirect payroll funds.
Examples of BEC Emails
- An email from a “CEO” instructing an employee to wire funds immediately to a new account.
- A fake vendor email requesting payment to a “new bank account” due to supposed banking changes.
- An email from “HR” asking to update an employee’s direct deposit information, diverting payroll funds.
How It Works
Attackers often spoof email addresses or compromise real accounts to make fraudulent requests appear genuine. These emails typically use urgent language to pressure employees into bypassing standard verification processes. Common tactics include subtle misspellings, lookalike domains, and requests for changes in payment methods.
Red Flags to Watch Out For
- Urgency and Pressure: Requests that feel rushed or demand immediate action.
- Unusual Requests: Changes to payment details or sensitive information requests that don’t align with typical communication.
- Subtle Misspellings or Domain Changes: Look out for slight alterations in email addresses or domain names (e.g., "company.co" instead of "company.com").
How to Avoid BEC
- Verify requests for financial transactions or sensitive information, especially if they seem urgent or unusual.
- Implement multi-factor authentication (MFA) for all business email accounts.
- Educate employees on BEC tactics, red flags, and encourage caution when handling unexpected requests.
- Use email security protocols like DMARC to prevent email spoofing.
Real-World Examples of BEC Fraud
- Retail Chain Scam: A large retailer was defrauded of over $100,000 when attackers impersonated a supplier, providing altered payment details. The accounts team updated payment information, routing future payments to the scammer.
- Small Business CEO Impersonation: A small business lost $50,000 when the CFO received a fraudulent email from a “CEO” requesting an immediate wire transfer to finalize a "partnership."
- Payroll Scam: A fraudster impersonated an employee to update direct deposit details with HR, rerouting payroll funds to their account before the mistake was detected.