Business email compromise: how BEC scams work

Inside the impersonation playbook attackers use to redirect payments and invoices — why email filters miss it, and how to shut it down.

SM
Sofia Maretti
Threat Analyst
7 min read

Business email compromise (BEC) is the quiet giant of cybercrime: no malware, no malicious link, just a convincing message that moves money to the wrong account. It consistently causes some of the largest financial losses of any attack type — precisely because it looks so ordinary.

How a BEC scam unfolds

  • Reconnaissance — attackers research executives, finance staff, and suppliers.
  • Impersonation — they spoof or look-alike a trusted person or vendor.
  • The ask — an 'urgent' wire transfer, a changed bank account, or a fake invoice.
  • Pressure — secrecy and time limits to discourage double-checking.

Why filters miss it

There's often nothing for a scanner to catch: no attachment, no link, no known-bad payload — just plain text from a plausible address. That's what makes BEC a human problem first. The defence has to live with the people who handle money and trust, not only in the mail gateway.

How to stop it

  • Verify payment and bank-detail changes out-of-band, every time.
  • Build a no-blame culture where pausing to check is encouraged.
  • Flag external senders and lookalike domains automatically.
  • Simulate BEC scenarios so finance teams recognise the pattern.

BEC succeeds by exploiting trust and urgency. A simple, non-negotiable rule — verify any change to where money goes through a second channel — defeats the vast majority of these attacks.

Security training designed for people. Built for enterprise.

Learn how HookPhish can effortlessly transform your security program and reduce your human cyber-risk.

Fill out the form to schedule a 30-minute chat with a product expert. We'll discuss the challenges you want to solve, walk through HookPhish, and answer any questions.

2026
Top 50
Enterprise
2026
Top 50
Security
2026
Leader
Enterprise
2026
Momentum
Leader
2026
High Performer
Mid-Market
2026
Best Results
Enterprise

Book a personalized demo

Looking to become a partner? Use this form instead.

Select your country from the list.

1/2