Business email compromise (BEC) is one of the most financially damaging forms of social engineering targeting organizations today. Unlike malware or ransomware, BEC attacks require no technical exploits and often rely on deceptive emails. A convincing email, a sense of urgency and the right impersonation may influence employees into sharing sensitive information or authorizing financial transactions.

Key Takeaways
  • BEC is a social engineering attack that manipulates people through trust, which makes it one of the most financially damaging threats businesses face today.
  • Attackers impersonate executives, vendors and legal counsel to redirect payments or steal sensitive data.
  • Traditional email security tools often miss BEC attacks because they typically contain no malicious links, attachments, or code.
  • AI and deepfake technology are now being used to clone voices and generate fake video, extending BEC beyond email into voice and video channels.
  • A layered defense combining employee training, strict payment controls and identity verification technology offers the strongest protection against BEC.

The growing impact of these attacks is reflected in the rapid expansion of the BEC security market. The global BEC market is expected to reach $5.41 billion by 2030, growing at a CAGR of 21.6% as organizations invest in stronger detection and prevention capabilities due to rising risks.


What Is Business Email Compromise (BEC)?

Business email compromise is a targeted social engineering attack in which a threat actor manipulates someone inside an organization, typically through email, into approving fraudulent payments or sharing sensitive business information.

Unlike phishing campaigns that cast a wide net, a BEC attack is deliberate and highly personalized. Attackers often research an organization before launching an attack. They identify key decision-makers, employees who handle vendor payments, etc., and who are likely to act quickly on an executive’s request.

BEC attacks are particularly dangerous because they do not contain malware, malicious links, or dangerous attachments that traditional email security filters might catch. Emails used in a BEC attack typically contain nothing but text, which makes them indistinguishable from routine business communication.


How Does a Business Email Compromise Attack Work?

The BEC attack process explains how the attacks unfold in a series of calculated steps designed to exploit trust and urgency within organizations.

Reconnaissance
Research target org & hierarchy
Impersonation
Spoof or hijack trusted email
Trust-Building
Insert into existing thread
Fraudulent Request
Urgent wire or data request
Funds Stolen
Redirected to attacker account
  • Reconnaissance: The attacker researches the target organization, studying LinkedIn profiles, company websites and vendor relationships to identify who controls payments and the hierarchy.
  • Impersonation: Armed with that information, they either spoof a trusted email address or hijack a real account through credential theft, making the message appear legitimate.
  • Trust-Building: Some BEC attacks take place in the middle of an already-existing email thread, inserting the attacker into an ongoing conversation to add credibility before the fraudulent request is made.
  • Fraudulent Request and Theft: The attacker sends an urgent request, typically a wire transfer, a change in vendor banking details or payroll data. If the receiver agrees, the funds are redirected to an account owned by the attacker.

For example, an accounts payable employee receives what looks like a message from their CFO, asking for an urgent $47,000 wire to a new vendor. The name, tone, and email details all appear legitimate, and hence, the wire transfer is processed. However, it is later discovered that the CFO never sent the email.


Types of BEC Email Scam

In BEC fraud attackers use several variations depending on who they are targeting and what they want to extract.

CEO Fraud

Attackers impersonate a senior executive and send urgent payment requests to finance employees, often referencing a real vendor or project to appear credible.

Example: “I need a wire of $35,000 sent today. Do not discuss it with anyone.”

Fake Invoice Scam

The attacker poses as a familiar vendor and sends a professional-looking invoice, but with their own bank details swapped in. Because the email carries no malware or suspicious links, it passes right through most email security tools.

Example: A supplier emails the accounts team saying their bank details have changed and asks for future payments to go to a new account.

Account Compromise

The attacker breaks into a real email account using stolen login credentials. Because the message comes from a legitimate address, it is less likely to raise suspicion.

Example: A vendor’s compromised account is used to ask a client to update their payment details before the next invoice is due.

Attorney Impersonation

The attacker pretends to be a lawyer involved in a sensitive business matter, such as a merger or legal settlement. They create urgency and confidentiality to prevent the target from verification.

Example: “I’m legal counsel overseeing the acquisition. Please arrange the escrow transfer before the close of business. This is strictly confidential.”

Data Theft

Some BEC frauds focus on stealing sensitive organization or employee data. Typically, HR and payroll teams are their frequent targets.

Example: An attacker posing as the CEO emails HR requesting a full list of employee W-2 forms for identity fraud or resale on the dark web.

Vendor Email Compromise

The attacker gains access to a supplier’s email account or creates a look-alike domain that resembles theirs. Then they join an active payment conversation and request a change in bank account details. Since the email appears to come from a trusted vendor, it may not be questioned.

Example: A trusted vendor’s account is used to send the accounts payable team updated banking details just before a large payment is scheduled.


Key Indicators of BEC Attack

BEC attacks are designed to look ordinary. Recognizing the signs of a BEC attack can make the difference between stopping the fraud in time and unknowingly transferring funds.

  • Look-Alike Domains: The sender’s email address may look legitimate at first, but a closer look may show a swapped letter, an added hyphen, or a slightly different domain extension. These small details are easy to miss in a busy inbox.
  • Unexpected Payment Requests: If a payment request shows up outside the normal billing cycle, involves an unfamiliar account, or feels out of place given your usual process, pause before acting on it.
  • Sudden Bank Account Changes: Vendors generally do not change their banking details over email without a phone call or some kind of formal confirmation. A standalone email requesting a payment redirect is worth verifying independently.
  • Bypassed Approval Workflows: Watch for messages that claim approvals have already been given and ask you to skip the usual steps. Scammers rely on employees being reluctant to question authority.
  • Secrecy Requests: A legitimate manager or executive will not ask you to hide a financial transaction from your team. When an email asks you to keep something confidential, it should be treated as a warning sign.
  • Unusual Urgency: Rushed requests are designed to limit careful review. If the pressure to act immediately is stronger than the explanation for why, treat it as suspicious.
  • Changed Writing Style: People have consistent communication habits. If an email from a known colleague or executive reads differently than usual, whether in tone, phrasing, or level of detail, it may not actually be from them.
  • Unverifiable Voice or Video Approvals: Attackers now use AI tools to clone voices and generate convincing videos. If someone seems to authorize a payment via a call or video but cannot be contacted to confirm, it should not be acted upon.

Identify manipulated audio, video, and images in real time.Diopter’s deepfake detection tool flags synthetic media before it influences a business decision.

Get the verdict in 60 seconds →

Why Traditional Email Security Often Misses BEC

BEC detection challenges arise because these attacks often lack traditional warning signs. BEC emails usually contain no malware, malicious links, or suspicious attachments that email security filters are designed to detect. Instead, they rely on plain text messages, allowing them to blend easily into normal business communication and making detection significantly more difficult.

  • No malicious payload: A BEC email usually contains only a few lines of plain text, with no malware or attachments for antivirus solutions or secure email gateways to detect.
  • Legitimate account use: When an attacker uses a compromised real email account, the message passes SPF, DKIM, and DMARC checks. From a technical standpoint, the email looks completely valid.
  • Low send volume: Unlike mass phishing campaigns, BEC attacks target one or two people at a time. Traditional secure email gateways struggle to detect well-constructed BEC campaigns because of their low volume, lack of obviously malicious content, and a seemingly legitimate source.
  • Social engineering over code: BEC relies on human psychology, not technical exploits. The threat lives in the context and intent of the message, not in any file or link.
  • AI-generated communication: Attackers now use AI tools to generate emails that closely mimic a target’s writing style, tone and vocabulary, making them even harder to distinguish from genuine messages. In 2025, businesses reported losses of over $30 million to BEC scams involving AI frauds.

Business Impact of BEC Attacks

Business email fraud carries consequences that extend well beyond the wire transfer.

The FBI IC3 2025 Annual Report found $3.04 billion in losses from 24,768 complaints, which makes BEC the second most expensive US cybercrime.

  • Financial loss: Wire transfers and fraudulent payments are often irreversible. One successful BEC attack may drain millions of dollars in a matter of minutes, with little chance of full recovery.
  • Operational disruption: After an attack is discovered, normal business operations stall. Finance teams are locked down, vendor relationships are paused and IT teams spend days or weeks investigating what happened and how.
  • Reputational damage: Clients, partners and vendors who are involved in the fraud, even indirectly, lose confidence in the organization. Rebuilding that trust takes far longer than recovering the funds.
  • Compliance and legal exposure: Organizations in regulated industries face scrutiny from regulators if a BEC attack results in a data breach or a failure in financial controls. This may lead to audits, penalties and reporting.
  • Recovery costs: Forensic investigations, legal fees, staff overtime, and potential cyber insurance claims all add up quickly after a BEC incident, compounding the original financial loss.

Real-World Cases of Business Email Compromise Attempt

BEC scams do not only target large enterprises. The following cases show how the attack pattern plays out across different industries and organization sizes, and what made each one succeed.

Case study

Ubiquiti Networks — $46.7 million

In one of the most well-known BEC frauds, Ubiquiti Networks lost $46.7 million after attackers impersonated a trusted vendor and sent fraudulent payment requests to the finance department. The emails appeared legitimate and referenced real internal processes, which is why they were not questioned.

Case study

Toyota Subsidiary — $37 million

Automobile giant Toyota’s subsidiary lost $37 million when a third party posing as a business partner emailed the finance team requesting funds be transferred to a specific account. The attack worked because the request appeared authentic, using legitimate-looking communication details.

Case study

Facebook & Google — $121 million combined

Technology corporations Facebook and Google were defrauded of over $121 million by an attacker who posed as a legitimate hardware vendor and submitted fake invoices over an extended period. The scheme succeeded because the invoices closely matched the companies’ existing payment processes.

What these BEC scam examples share is a common attack pattern: research a real relationship, impersonate a trusted party, make a request that fits the context and introduce just enough urgency to discourage a second look.

See how Diopter strengthens identity and payment verification in real time.Explore how signals are analysed to flag suspicious transactions and help security teams take confident, immediate action.

Learn more →

BEC vs EAC (Email Account Compromise) vs Phishing

These three threats are often mistaken for one another but they operate differently and require different responses. The table below breaks down the key distinctions.

BEC EAC Phishing
Objective Financial fraud or data theft via impersonation Gain persistent access to a real email account Steal credentials, install malware, or harvest data
Attack Method Email spoofing, domain impersonation, or compromised accounts Credential theft, MFA bypass, session hijacking Mass fake emails, malicious links, or harmful attachments
Account Access Required Not always; spoofed identity often sufficient Yes, attacker takes over a real account No; attacker sends from their own fraudulent account
Typical Target Executives, finance teams, HR, and accounts payable Individuals with high-value email access Broad groups; anyone in an organization
Malware Use Rarely Rarely Common
Financial Fraud Focus High High, often a precursor to BEC Moderate
Detection Difficulty High; no malicious payload to flag High; traffic comes from a legitimate account Moderate; filters can catch links and attachments
Deepfake Risk High and growing Moderate Low

Phishing attacks are often broader in scope, targeting dozens or hundreds of accounts at once, while a BEC attack is highly targeted with a specific end goal in mind. EAC sits in between: it is frequently a stepping stone that gives attackers the legitimate account access they need to launch a more convincing BEC email.


How AI and Deepfakes Are Changing Business Email Compromise

The mechanics of a BEC attack have always relied on convincing impersonation. AI has made it significantly easier and harder to detect.

  • AI-written messages: Attackers now use large language models to generate BEC emails that closely mimic a target’s writing style, vocabulary, and tone. These messages are well-structured, contextually accurate, and virtually free of the grammatical errors that once helped employees spot fraud.
  • Voice cloning scams: Deepfake audio tools can replicate a known executive’s voice from as little as a few seconds of public audio. Attackers use these cloned voices to place calls or send voice notes that appear to authorize wire transfers. The employee hears a familiar voice and complies.
  • Synthetic video in executive impersonation: AI-generated video is now being used in live video calls to impersonate senior leaders. By replicating a person’s appearance, facial expressions and mannerisms, attackers can make fraudulent requests appear more credible.
  • Multi-channel fraud: Modern deepfake BEC attacks rarely rely on email alone. Attackers send a fake BEC email and then follow up with a voice call or video message to make the request stronger and make people forget to check through a different route.

Modern BEC defense now includes deepfake detection tools, out-of-band verification protocols and behavioral anomaly monitoring. They can flag requests that deviate from established patterns, even when the sender appears legitimate.


Building a Layered Defence Against BEC

No single control stops a determined BEC attack. The most effective approach combines awareness, process discipline and the right technology working together.

People

Your employees are both the primary target and the first line of defence. Regular security awareness training should cover how to recognize a BEC email, what social engineering looks like in practice and what to do when a request feels off.

Training should go beyond theory: use realistic scenarios, simulated BEC attempts and short refreshers that keep vigilance high. Staff handling payments or sensitive data should receive more frequent and role-specific training, since they are the most likely targets of executive impersonation and vendor payment fraud.

Process

Strong financial controls can help prevent fraud even if a suspicious email reaches an employee. Require approval from at least two people for wire transfers and payment changes above a set amount.

Make it clear that changes to suppliers’ bank accounts must be confirmed by a known phone number, not by the email chain that asks for the change. Make sure that you have to call backs before you can handle any high-value or unusual deals. These steps do not slow business down significantly, but they close the gaps that BEC scams depend on.

Technology

Email authentication protocols, including SPF, DKIM and DMARC, are foundational controls that help prevent domain spoofing and unauthorized email impersonation. Multi-factor authentication on all email accounts makes it significantly harder for attackers to take over real accounts for use in BEC campaigns.

Beyond these basics, AI-powered monitoring tools can detect anomalies in email behavior, such as unusual send patterns, sudden changes in communication style or requests that fall outside normal business workflows and flag them before a fraudulent transaction is completed.


How Diopter Helps Detect Modern BEC Attacks

A BEC attack rarely stays within a single channel. An attacker may start with a spoofed BEC email, follow up with a cloned voice call and close with a deepfake video to push through a fraudulent approval. By the time the request reaches someone who can authorize it, multiple layers of impersonation have already been applied.

This is where Diopter fits into a layered defense strategy. Email authentication and staff training are two examples of front-end applications that handle impersonation. Diopter focuses on the channels where impersonation is most difficult to detect, such as live voice calls and video meetings.

On every critical call, Diopter covers four areas:

  • Identity and payment verification: Confirming who is on the call and whether payment instructions are legitimate.
  • Conversational manipulation detection: Flagging social engineering patterns such as urgency, authority pressure and isolation tactics.
  • Deepfake detection: Scoring audio and video for signs of synthetic or cloned media in real time.
  • Policy alignment: Flagging requests that bypass normal approval workflows or established verification steps.

For teams managing vendor payments, executive approvals, or IT help desk access, Diopter adds a critical verification layer that traditional BEC cybersecurity controls may lack.

Conclusion

Business email compromise remains one of the most financially damaging threats facing organizations today, not because it is technically complex, but because it is built entirely around trust.

As AI-enabled impersonation and deepfake BEC extend the attack surface beyond email into voice and video channels, traditional security controls are no longer sufficient on their own. The best way for businesses to lower their risk is to use a multi-layered approach that includes training employees, strict process controls and using technology.

At Diopter, we help organizations strengthen this last layer of defense by focusing on the behavioral and contextual signals behind BEC attacks. By adding real-time identity and intent verification into existing workflows, Diopter helps security teams reduce the risk of fraudulent transactions.

Stop BEC before it reaches your approvers.

Diopter scores live calls and video in real time, flagging deepfakes and social engineering patterns before a transaction is authorized.

See how it works →

FAQs

What should you do if your business experiences a BEC attack?
Immediately halt any pending transactions, notify your bank to attempt a recall, report the incident to the FBI IC3, and involve your IT or security team to identify how the BEC attack occurred and whether any accounts were compromised.
Can small businesses become victims of BEC?
Absolutely. Small businesses are actually among the most targeted. They are easier to trick because they often have fewer security controls, smaller teams handling multiple responsibilities, and less formal verification processes for financial transactions.
Can deepfake technology be used in BEC attacks?
Yes, and it is becoming more common. Attackers now pair a spoofed BEC email with an AI-generated voice call or video to make the request feel even more legitimate. When an employee hears a familiar voice or sees a recognizable face, they are far less likely to question it.
Can AI detect Business Email Compromise in real time?
Yes. AI-powered tools can analyze communication patterns, flag social engineering language and detect synthetic media during live calls. This makes real-time detection of a BEC attack possible even when the email itself contains no obvious red flags.
What is vendor email compromise?
It is a type of BEC fraud where attackers take over or imitate a supplier’s email account to redirect payments to themselves. Since the message appears to come from someone the business already knows and works with, it rarely raises suspicion until the money is gone.
How can MSPs help clients prevent BEC?
MSPs are well-positioned to build strong defenses for their clients. This includes setting up email authentication, rolling out multi-factor authentication, running security awareness training and deploying tools that catch suspicious BEC email activity. They can also help put clear payment verification policies in place, so employees know exactly what steps to follow before authorizing any transfer.
DAI
Diopter AI Team
Threat Intelligence

The Diopter AI Team publishes research and analysis on deepfake fraud, synthetic media detection, and AI-enabled social engineering. The team works directly with security, fraud, and IT organizations to map real-world attack arcs.