- According to the FBI, BEC causes over 2.9 billion dollars in annual damage, making it the most financially destructive form of cybercrime worldwide.
- Unlike classic phishing, BEC doesn't aim to install malware but to manipulate business processes — primarily payment instructions and data disclosure.
- The five most common BEC variants are CEO fraud, invoice fraud, account compromise, attorney impersonation, and HR fraud.
- Technical measures (SPF, DKIM, DMARC, email gateway) are necessary but not sufficient. Organizational controls such as dual authorization for payments are the most effective protection.
- In a BEC incident, speed is everything: Within 24 hours of a wire transfer, there is a realistic chance of recovering the funds through the bank.
The invisible threat
Ransomware dominates the headlines. Encrypted systems, ransom demands, days-long outages. The images are dramatic, the coverage intense. But when you look at the raw damage numbers, there's a threat that puts ransomware in the shade: Business Email Compromise, or BEC.
The FBI estimates the global damage from BEC at over 2.9 billion dollars per year — from reported cases in the US alone. The actual figure is considerably higher because many companies don't report BEC attacks out of embarrassment. Germany's federal agencies report a steadily growing number of cases, with individual losses regularly reaching six- and seven-figure amounts.
What makes BEC so dangerous is the combination of two factors: The attacks are technically simple — often nothing more than a well-crafted fake email — and they target the human level: trust, hierarchy, and time pressure. No antivirus scanner flags an email as a threat when it's technically flawless and merely contains a manipulated bank account number.
How BEC attacks work
The anatomy of a BEC attack
A BEC attack typically unfolds in four phases:
Phase 1: Reconnaissance. The attackers research the target company. They use publicly available information: commercial register entries, LinkedIn profiles, the company website, press releases, annual reports. They identify the relevant individuals (executive management, finance department, procurement), their email addresses, communication patterns, and current projects. For targeted attacks, this phase can last weeks or months.
Phase 2: Preparation. The attackers prepare the deception. They register a domain that's confusingly similar to the real one (e.g., company-gmbh.de instead of company.gmbh.de). Or they actually compromise the email account of a relevant person (through phishing, credential stuffing, or vulnerabilities). They create email templates that mimic the communication style of the impersonated person.
Phase 3: Execution. The actual fraudulent email is sent. It appears to come from a trusted person (CEO, supplier, attorney) and contains a plausible call to action: a wire transfer, a change of bank details, or the disclosure of data. The email creates time pressure ("must go out today") and confidentiality ("please keep this discreet").
Phase 4: Monetization. The transferred funds are quickly moved through multiple accounts in different countries to complicate tracing. Within 48 to 72 hours, the money is typically gone for good.
The five most common BEC variants
Variant 1: CEO fraud. The best-known variant. The attackers impersonate the CEO or a board member and instruct an employee in accounting to make an urgent wire transfer. Typical characteristics: large sum, allegedly confidential deal (acquisition, legal dispute), time pressure, instruction not to inform anyone else.
The email comes either from a look-alike domain (ceo@company-grmbh.de instead of ceo@company-gmbh.de) or from the CEO's actually compromised email account. In the second variant, detection is especially difficult because the email is technically authentic.
Variant 2: Invoice fraud. The attackers intercept a real invoice (or create a convincingly fake one) and change the bank details. The recipient transfers the amount believing they're paying the correct supplier. This variant is especially common in international business relationships.
Variant 3: Account compromise. The attackers compromise an employee's email account and use it to send invoices with altered bank details to customers or partners. The advantage for the attackers: the emails come from a genuine, trusted address.
Variant 4: Attorney impersonation. The attackers pose as an external attorney or tax advisor and push for an urgent wire transfer related to an allegedly confidential legal matter. The urgency and authority of the attorney role increase the pressure.
Variant 5: HR fraud (W-2/payroll scam). The attackers impersonate the CEO or HR leadership and ask the HR department to send salary data, tax information, or personal employee data. This data is used for identity theft or further attacks.
Why BEC is so hard to detect
No malware, no suspicious link
Unlike phishing emails that link to a fake login page or contain an attachment with malware, BEC emails arrive without technically suspicious elements. They contain no link, no attachment, no malware. Technically speaking, they are clean emails. An email gateway that checks for suspicious links, attachments, and known malware signatures lets them through.
Social engineering at the highest level
BEC attackers are masters of manipulation. They exploit psychological principles deeply rooted in human psychology:
Authority: The email comes (supposedly) from the CEO. Who questions an instruction from the boss?
Time pressure: "Must be done by 2 PM." Time pressure reduces diligence and suppresses critical questioning.
Confidentiality: "Please keep this strictly confidential, don't inform anyone." This cuts off the reporting channel that would uncover the fraud.
Familiarity: The email mimics the writing style of the impersonated person. If the CEO usually writes briefly and directly, so does the BEC email.
Plausibility: The context fits. If the company is currently preparing an acquisition and the attackers know this from press releases, an allegedly related wire transfer becomes plausible.
AI-powered BEC attacks
The next escalation level is AI-powered BEC attacks. Language models can imitate a person's writing style based on just a few email examples. Deepfake technology can clone a person's voice to convincingly answer phone callbacks. There are documented cases where attackers used deepfake voices of CEOs to confirm wire transfers by phone.
Technical protective measures
Email authentication: SPF, DKIM, DMARC
The three email authentication protocols are the first technical line of defense against BEC:
SPF (Sender Policy Framework): Defines which servers are authorized to send email on behalf of your domain. If an email comes from an unauthorized server, the recipient can mark it as suspicious or reject it.
DKIM (DomainKeys Identified Mail): Cryptographically signs outgoing emails so the recipient can verify that the email actually originated from the stated domain and wasn't tampered with in transit.
DMARC (Domain-based Message Authentication, Reporting and Conformance): Builds on SPF and DKIM and defines what happens to emails that fail the check (nothing, quarantine, reject). DMARC also provides reports on failed authentications.
These three protocols protect your domain from being abused for email spoofing. However, they don't protect against look-alike domains (company-grmbh.de) and not against compromised accounts.
Email gateway and advanced threat protection
Modern email gateways offer features specifically designed for BEC:
- Display name spoofing detection: Detects when the displayed name in an email matches an internal employee but the email comes from an external address.
- Domain impersonation detection: Detects look-alike domains and flags the email.
- Behavioral analysis: Detects unusual communication patterns (e.g., the CEO writes directly to accounting for the first time).
- External warning banner: Adds a prominent notice to emails from external senders, reminding recipients that the email is not internal.
MFA for all email accounts
When an email account is compromised, the attacker gains an authentic communication channel. Multi-factor authentication for all email accounts is therefore one of the most effective measures against the account compromise variant of BEC.
Domain monitoring
Monitor the registration of domains similar to your company domain. Services such as domain monitoring tools or the registration of obvious typo variants (typosquatting protection) can help detect look-alike domains early.
Organizational protective measures
Dual authorization for payments
The single most effective measure against BEC is dual authorization for payment instructions. No wire transfer above a defined threshold (e.g., 5,000 euros) may be approved by a single person. And no change to bank details may be made based on an email.
In practical terms, this means:
- Wire transfers above the threshold require approval by two people.
- Changes to bank details are verified by phone using a known phone number (not the one in the email) with the supplier.
- New payment recipients are set up through a defined verification process, not by email instruction.
Callback verification
For unusual or urgent payment instructions, a callback to the purported sender must occur — using a phone number from an independent source (phone directory, contract documents, CRM), not from the email itself. This procedure sounds simple but is highly effective because it breaks the core deception of the BEC attack.
Clear escalation paths
Employees must know who to contact when a payment instruction seems suspicious — and they must be able to do so without fearing negative consequences. The corporate culture must allow an accountant to question a CEO's instruction without it being interpreted as disloyalty.
Define clear escalation paths: If a payment instruction appears unusual, it is escalated to the supervisor or the CISO (Information Security Officer). The payment is held until legitimacy is confirmed. Better to delay a legitimate payment by one day than to fail to stop a fraudulent one.
Awareness training with BEC focus
General phishing training is not enough because BEC works differently than classic phishing. Training must address the specific characteristics of BEC:
- What does a BEC email look like? (Show a concrete example)
- What psychological tricks are used?
- What is dual authorization and why does it apply without exception?
- How does callback verification work?
- What to do if you suspect something?
Particularly effective are simulated BEC attacks. Send a convincingly realistic BEC email to the accounting department and check whether the defined process is followed. The results show whether the training is working and serve as a basis for improvements.
When it happens: Incident response for BEC
The first 24 hours
When a BEC attack is detected, speed is critical. Especially if a wire transfer has already been made, the first 24 hours offer the best chance of recovering the funds.
Contact the bank immediately. Call your bank's fraud department and request a recall of the wire transfer. For SEPA transfers within the EEA, a recall within a few hours is often still possible. For international transfers, it becomes more difficult, but the attempt must be made immediately.
Report the incident internally. Inform the CISO (Information Security Officer), executive management, and the affected department. Preserve the fraudulent email with complete headers as evidence.
File a criminal complaint. File a complaint with the police, ideally with the Central Cybercrime Contact Point of the relevant state criminal investigation office. The criminal complaint is a prerequisite for international legal assistance and potentially also for cyber insurance.
Check the communication chain. If the BEC email came from a compromised internal account, the account must be locked immediately and the password changed. Check whether further emails were sent from this account and whether other accounts are also compromised.
Follow-up
After the acute phase comes the review:
- Root cause analysis: How did the attack get through? Was it due to missing email authentication, a compromised account, lack of awareness, or a missing dual authorization process?
- Process improvement: What controls need to be introduced or strengthened?
- Training: Targeted follow-up training for the affected department and general awareness-raising across the company.
- Documentation: Document the incident, track measures, record lessons learned. In ISMS Lite, BEC incidents can be recorded as security events and directly linked to corrective measures and risk assessment.
BEC in the ISMS
Risk assessment
BEC belongs in every risk assessment that covers information security. The likelihood of occurrence is high (BEC attempts are ubiquitous), and the potential damage is significant (six-figure amounts and more). The risk assessment should treat the different BEC variants as separate scenarios because the protective measures differ.
Relevant controls from ISO 27001 Annex A
Several controls from ISO 27001 Annex A address BEC directly or indirectly:
- A.6.3 (Awareness, education, and training): Training program with BEC-specific content.
- A.5.14 (Information transfer): Regulations for secure information exchange, including verification of payment instructions.
- A.8.15 (Logging): Logging of email activities for detecting compromised accounts.
- A.5.24 (Information security incident management planning and preparation): Incident response process that covers BEC as a scenario.
Metrics
Track BEC-relevant metrics to measure the effectiveness of your protective measures:
- Number of detected and blocked BEC attempts (email gateway statistics)
- Number of reported suspicious emails (employee reporting willingness)
- Results of BEC simulations (proportion of employees who respond correctly)
- Implementation rate of dual authorization for payments
BEC is not a threat that can be solved with a single tool or a single measure. It requires a combination of technical controls, robust business processes, and trained employees. The good news: Every single measure noticeably reduces the risk, and the most effective measures — dual authorization and callback verification — are neither expensive nor technically complex.
Further reading
- Recognizing and reporting phishing: Practical guide for employees and IT
- Email security: Properly configuring SPF, DKIM, and DMARC
- Social engineering in organizations: Attack patterns and defense strategies
- Detecting and reporting security incidents: The right process
- Building and sustaining a security awareness program
