Business Email Compromise (BEC)

Defend corporate entities against domain spoofing, social engineering, and unauthorized corporate wire transfers.

Business Email Compromise (BEC)

Business Email Compromise is a form of cyber-enabled fraud where criminals impersonate executives, employees, suppliers, or trusted partners to manipulate financial transactions.

Common methods include:

  • Fake payment instructions.
  • Supplier impersonation.
  • Executive impersonation.
  • Requests to change bank account details.

Protection measures:

  • Verify payment requests through separate communication channels.
  • Confirm changes to supplier information.
  • Implement strong email security practices.

Train employees to identify suspicious communications.

Modus Operandi

BEC represents an elite tier of corporate cybercrime targeting accounting, payroll, and supply chain managers. Perpetrators infiltrate corporate infrastructure or mimic high-level executives to redirect legitimate commercial payments to fraudulent accounts.
The scheme typical progresses through four core stages:
  1. Target Surveillance: Fraudulent actors spend weeks tracking company personnel, vendor invoices, and executive travel patterns.
  2. Domain Exploitation: Cybercriminals register domains that visually look like a company’s partner or executive email.
  3. Deceptive Instruction: The spoofed address sends an urgent request to alter bank routing details for a major pending vendor payment.
  4. Capital Siphoning: The accounting team processes the invoice normally, unknowingly sending corporate capital directly to fraud networks.

Key Red Flags

  • Sudden Changes in Routing Details: Last-minute updates to established bank details or payment channels provided via email.
  • Executive Bypasses: Instructions allegedly from executives to push payments through while bypassing normal review workflows.
  • Altered Email Domains: Minor typographical variations in sending addresses designed to deceive readers.
  • Extreme Confidentiality: Demands to handle payment changes strictly via isolated channels without verbal confirmation.

Protection Protocols

  • Enforce Out-of-Band Verification: Confirm any modification to banking arrangements via a known alternative phone number.
  • Dual-Authorization Policies: Mandate that all financial movements above a specific amount require sign-offs from two separate managers.
  • Deploy DMARC Protocols: Implement advanced email filtering mechanisms across the enterprise to automatically catch domain spoofing.
error: Security Alert