What is business email compromise?¶
Business email compromise is the misuse or impersonation of business email to manipulate payments, information, account changes or other trusted processes.
Avoid the dangerous assumption¶
The dangerous assumption is that business email compromise always means the victim’s mailbox was technically hacked.
It may involve:
- a compromised internal mailbox
- a compromised supplier or customer mailbox
- a lookalike domain
- a spoofed sender address
- an impersonated display name
- telephone follow-up
- altered bank details
- fraudulent invoices
- requests to change payment or payroll information.
The incident may be primarily social engineering, account takeover or a combination of both.
Investigators should identify which account or identity was trusted and why the request succeeded.
Preserve the original messages, headers, mailbox audit records, forwarding rules, authentication records, payment instructions and communications used to verify or approve the change.
Ask whether the offender had access to genuine correspondence. Knowledge of invoice amounts, project details or normal language may indicate mailbox access, but the information could also have come from another source.
Do not assume that a message appearing within an existing thread proves the account was compromised. Thread content can be copied or imitated. Equally, a genuine mailbox may have been used to send or modify messages.
Separate the financial event from the email event. The message may have influenced a transfer, while banking and organisational records show how the payment was authorised and where it went.
The apparent sender, account holder, domain registrant and offender may all be different.
Operational takeaway¶
Treat business email compromise as a combined trust, communication and account problem, and preserve both the email evidence and the payment or process records it influenced.