Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is business email compromise?

Business email compromise — BEC — is the misuse or impersonation of trusted business communications to redirect money, information or account changes.

The important thing is that the trusted business process is being exploited. The email account itself may or may not actually be compromised.

BEC can work in several ways

Common patterns include:

  • genuine mailbox takeover;
  • lookalike domain;
  • spoofed sender;
  • display-name impersonation;
  • false invoice;
  • changed bank details;
  • payroll diversion;
  • supplier impersonation;
  • phone follow-up.

A convincing attack may combine several of these.

The genuine mailbox question matters

Suppose a supplier email asks for new bank details.

If it genuinely came from the supplier's mailbox, the investigation needs account/session evidence.

If it came from a lookalike domain, the investigation needs domain, hosting and sending evidence.

If the address was spoofed, the delivery/authentication evidence may show that.

Trusted relationshipSupplier / finance processVictim expects legitimate communication.
Impersonation routeCompromised mailbox or fake senderSeveral technical methods are possible.
InstructionChange payment detailsBusiness process is redirected.
OutcomePayment / data / account changeFinancial and account records show consequence.

Preserve both communication and business records

Useful evidence may include:

  • native messages and headers;
  • message trace;
  • mailbox audit;
  • forwarding rules;
  • authentication/session records;
  • payment instructions;
  • approval records;
  • verification calls;
  • financial records.

The business workflow can be just as important as the email itself.

Keep the identities separate

The apparent sender, mailbox owner, domain registrant, payment beneficiary and offender may all be different people.

That is why BEC should be treated as a connected sequence rather than a single “hacked email” event.

The practical point is: BEC exploits trust in a business process. Work out which communication route was used, how the process was bypassed and where the money or information actually went.

Reference: CIM-038Cyber Incidents & Offender Methods