What is business email compromise?¶
Business email compromise — BEC — is the misuse or impersonation of trusted business communications to redirect money, information or account changes.
The important thing is that the trusted business process is being exploited. The email account itself may or may not actually be compromised.
BEC can work in several ways¶
Common patterns include:
- genuine mailbox takeover;
- lookalike domain;
- spoofed sender;
- display-name impersonation;
- false invoice;
- changed bank details;
- payroll diversion;
- supplier impersonation;
- phone follow-up.
A convincing attack may combine several of these.
The genuine mailbox question matters¶
Suppose a supplier email asks for new bank details.
If it genuinely came from the supplier's mailbox, the investigation needs account/session evidence.
If it came from a lookalike domain, the investigation needs domain, hosting and sending evidence.
If the address was spoofed, the delivery/authentication evidence may show that.
Preserve both communication and business records¶
Useful evidence may include:
- native messages and headers;
- message trace;
- mailbox audit;
- forwarding rules;
- authentication/session records;
- payment instructions;
- approval records;
- verification calls;
- financial records.
The business workflow can be just as important as the email itself.
Keep the identities separate¶
The apparent sender, mailbox owner, domain registrant, payment beneficiary and offender may all be different people.
That is why BEC should be treated as a connected sequence rather than a single “hacked email” event.
The practical point is: BEC exploits trust in a business process. Work out which communication route was used, how the process was bypassed and where the money or information actually went.