Business email compromise (BEC) is a scam where a criminal impersonates a trusted contact, such as your CEO, a supplier or a solicitor, by email. The goal is to trick a member of staff into sending money or sensitive data to an account the criminal controls. There’s no malware and no dodgy attachment, just a convincing message, sent at the right moment, to the right person, asking for something that sounds entirely routine.

That’s what makes business email compromise dangerous. A well-run BEC scam looks exactly like the finance emails your team handles every day. The FBI’s Internet Crime Complaint Center logged 24,768 BEC complaints in its 2025 report. Reported losses hit $3.05 billion, an average of roughly $123,000 per incident. And 86% of that money moved by wire transfer or ACH, which is hard to claw back once it’s gone.
Table of Contents
How does a business email compromise attack actually work?
Most BEC attacks follow a pattern. The attacker doesn’t need to breach your network at all, they just need patience and a convincing story.
- Research. The attacker studies your company website, LinkedIn and press coverage to learn names, job titles, suppliers and who signs off payments.
- Access or spoofing. They either register a lookalike domain, spoof a real address, or gain access to a genuine mailbox through a prior phishing attack.
- The approach. A message arrives that sounds routine: an invoice, a bank detail change, an urgent request from “the CEO” while they’re travelling.
- Pressure. The email creates urgency and discourages the recipient from checking, “I’m in a meeting, please action this now.”
- The payout. Funds go to an account the criminal controls, often moved on again within hours.
According to Cisco’s security research, this makes BEC a type of phishing attack that tricks employees into transferring funds to fraudulent accounts, but one that skips the malicious link or attachment a spam filter would normally catch.
What are the main types of BEC scams?
BEC isn’t one trick, it’s a family of them, each aimed at a different part of the business:
- CEO fraud. An attacker impersonates a senior executive and pressures a finance team member into an urgent, confidential wire transfer.
- Invoice or vendor fraud. The criminal poses as a genuine supplier, sending a fake invoice or a “new” bank account for an existing one.
- Vendor email compromise. Instead of spoofing a supplier, the attacker actually breaks into a real supplier’s mailbox and rides an existing, legitimate payment thread.
- Payroll diversion. A message to HR or payroll, apparently from an employee, asks to change bank details for the next salary run.
- Data theft. Rather than money, the target is sensitive records, often HR or tax data, requested under the guise of an internal audit.
These categories come from Cisco’s breakdown of BEC attack types, and the through-line is the same in each: the request looks and reads like something your business genuinely does every week.
Why is business email compromise so hard to catch?
Traditional email security tools are built to spot malware, bad links and known-bad senders. Business email compromise has none of that. The message is plain text, sent from an account that looks legitimate, or genuinely is. It asks for something a human would normally just do, so spam filters have little to work with.
Attackers also lean on timing. Ask for a payment change the day before a director leaves for a conference. Or time it to a genuine, ongoing invoice negotiation. Either way, there’s no natural pause for anyone to question it. That’s before generative AI is factored in: UK finance and treasury leaders surveyed by Trustpair in 2025 said AI is making BEC messages read more convincingly and copy a real executive’s tone more closely than ever.
How common is business email compromise for UK businesses?
BEC volumes are climbing, not falling. LevelBlue’s SpiderLabs recorded a 15% rise in BEC email volume in 2025 versus 2024. Monthly interception counts now run into the thousands. In the same Trustpair survey, 93% of UK finance and treasury professionals said their organisation had been targeted by fraud attempts in the past year, with AI-assisted BEC named as a growing driver.
This isn’t a threat limited to large enterprises. Smaller businesses are often softer targets: fewer verification checks, a smaller finance team, and a culture where a “from the boss” email gets actioned quickly out of respect, not carelessness.
How can a business defend against BEC?
The National Cyber Security Centre sets out the defences that actually move the needle, and none of them require exotic technology:
- Multi-factor authentication (MFA) on every email account, so a stolen password alone isn’t enough to get in. Our own look at a recent MFA-bypassing phishing kit shows why MFA needs to be paired with monitoring, not treated as a silver bullet.
- DMARC, SPF and DKIM configured on your domain, so spoofed emails claiming to be from your own company are rejected before they land in a colleague’s inbox.
- Out-of-band verification for any payment or bank detail change, a phone call to a known number, not the one in the email, before money moves.
- A blame-free reporting culture, so staff who spot something odd flag it fast instead of quietly ignoring it.
- A rehearsed incident response plan, so if a payment does go out wrongly, the bank and Action Fraud are called within the first hour, when recovery is still realistically possible.
Technical controls stop some of this. The rest comes down to whether your staff would actually notice, and that’s something you can test rather than guess at. A scoped social engineering assessment or red team assessment puts your real processes, not just your inboxes, under the same pressure a genuine business email compromise attempt would apply. It shows you exactly where a request would have gone through unchecked. If that sounds useful, Aardwolf Security’s testers can scope an engagement around your finance workflows; you can get in touch to talk through what that would look like.
Business email compromise FAQ
Is business email compromise the same as phishing?
It’s a form of phishing, but a narrower one. General phishing casts a wide net with links or attachments. BEC is targeted, text-only social engineering aimed at a specific person with the authority to move money or data, which is exactly why social engineering defences matter as much as technical filters.
Can BEC happen without any hacking at all?
Yes. Many BEC attacks use a spoofed or lookalike domain rather than a genuinely compromised account, so no system is ever broken into. That’s part of why it slips past tools built to detect intrusions.
What should staff do if they suspect a BEC email?
Don’t reply to it, don’t forward it, and don’t action the request. Verify with the sender through a separate, known channel, a phone call, not a reply to the same email thread, then report it to IT or security so others can be warned.
Is cyber insurance enough to cover BEC losses?
Some policies cover it, but many carve out social engineering fraud or set tight sub-limits and strict conditions, such as proof that verification steps were followed. Check the wording before assuming a policy will pay out in full.
How quickly should a suspected BEC payment be reported?
Immediately. Call your bank’s fraud line and report to Action Fraud within the first hour if at all possible; banks can sometimes freeze a fraudulent transfer before it clears onward, but the window closes fast.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.