Business email compromise
Also known as BEC, CEO fraud
Fraud carried out through a real or convincingly spoofed business mailbox, usually to redirect a payment.
BEC costs businesses more than ransomware in reported losses, and it rarely involves malware at all. The attacker gets into a mailbox, reads quietly for weeks to learn how the business talks about money, then inserts themselves into a live invoice thread with new bank details.
Because the message comes from a genuine account and continues a genuine conversation, email filtering has almost nothing to catch. Detection comes from watching for the tells inside the tenant, such as new inbox rules that hide replies, sign-ins from unexpected locations, and mail forwarding quietly enabled.
Where this comes up
Business email compromise sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.
Measure this on your own domain
Our free email authentication checker reads this record for any domain over public DNS, grades what it finds, and gives you the exact record to publish if it is wrong. No sign-up.
Check your domain →