Business Email Compromise (BEC)
1. Overview
Business Email Compromise (BEC) is a targeted scam where attackers spoof or hijack corporate email accounts to deceive employees, partners, or clients into transferring funds or disclosing sensitive information.
2. How the Scam Works
- Information Gathering
- Reconnaissance: collecting names, roles, vendors, and payment habits.
- Spoofing or Account Compromise
- Impersonating or hacking a legitimate email account.
- Fraudulent Request
- Sending payment instructions, changing bank details, or requesting sensitive information.
- Payment or Disclosure
- Victims execute wire transfers or disclose data, believing they are acting on legitimate instructions.
3. Key Red Flags
- Sudden changes to payment instructions.
- Urgent or high-pressure requests outside normal procedures.
- Email addresses that are similar but slightly altered (typosquatting).
- Requests for sensitive information via unencrypted email.
- Missing verification with the usual point of contact.
4. Prevention
- Implement multi-factor validation processes for wire transfers.
- Train staff to verify any financial request through a separate channel (phone, in person).
- Use two-factor authentication (2FA) for corporate email accounts.
- Enable DMARC/DKIM/SPF protection to reduce email spoofing.
- Limit publicly accessible sensitive information.
5. Response Steps
- Suspend compromised accounts and revoke access.
- Immediately contact the bank and attempt to cancel or freeze transfers.
- Gather evidence (email headers, copies, logs) for investigation.
- Notify the security team and compliance officers.
- Report the incident to the relevant authorities.
6. Summary
BEC targets financial processes and organizational trust. Robust procedural controls, training, and technical protections significantly reduce the risk.