Business Email Compromise Explained
Business email compromise, or BEC, is a targeted fraud in which a criminal uses a spoofed or hijacked email account to pose as someone the victim trusts, such as an executive, a supplier or a lawyer, and ask them to transfer money or change payment details. Most BEC carries no malware and no link.
That trust is what makes it work. The FBI’s Internet Crime Complaint Center recorded more than $3 billion in reported BEC losses in 2025, second only to investment fraud, from 24,768 complaints. The average reported loss was about $123,000.
Because a BEC message often looks like an ordinary request from a real colleague, it slips past spam filters and antivirus. The gap it exploits sits in the payment process, where a person authorises the transfer.
How Business Email Compromise Works
A BEC attack usually runs in four moves. First the criminal does research. Public sources, social media and a company website reveal who approves payments, which suppliers get paid and when a deal is in progress. Good BEC is tailored, so the request lands at a plausible moment.

Next comes access or disguise. The attacker either breaks into a real mailbox using stolen credentials, or registers a look-alike domain and spoofs the display name so the message appears to come from a known sender. A hijacked account is the more dangerous version, since replies stay inside a genuine thread.
Then the manipulation. The message uses authority, urgency and secrecy. A request from the chief executive, a deadline that cannot slip and an instruction to keep the matter confidential all discourage the victim from checking. The pretext is tied to something real, such as an invoice, an acquisition or a payroll update.
Finally the payment. The victim wires money to an account the attacker controls, or quietly updates a supplier’s bank details so future invoices pay the criminal. Generative AI has removed the last easy giveaway. Flawless writing, cloned voices and even live video now make the impersonation convincing, so the old advice to look for bad grammar no longer holds.
Types of BEC Attack
BEC is a family of scams rather than a single trick. Each message is aimed at a chosen target, which makes it a form of spear phishing, and it is sometimes called BEC phishing. The FBI groups the common variations by who the attacker imitates and what they ask for.
- CEO fraud: The attacker poses as a senior executive and pressures an employee into an urgent transfer, often called fake president fraud or whaling.
- Invoice and vendor fraud: A supplier’s email is faked or compromised, and the victim is asked to pay a real-looking invoice or send future payments to a new bank account.
- Account compromise: A real employee’s mailbox is taken over, also called email account compromise, and used to request payments from customers or colleagues.
- Attorney impersonation: The attacker poses as a lawyer handling a confidential or time-sensitive matter, using pressure and secrecy to force quick action.
- Data and payroll theft: Rather than money, the request targets staff data, tax forms or payroll details, which are then used for further fraud.
The Business Impact of BEC
The first cost is direct and fast. In 2025 the FBI reported that 86% of BEC losses moved by wire transfer or ACH, methods that clear quickly and are hard to reverse once the money reaches another account. By the time the fraud is noticed, the funds are often gone.
A compromised mailbox carries a second cost. It usually holds personal data, so the incident can be a reportable data breach even when no money is lost. That brings regulatory duties, which the next section covers.
Other variants divert salary payments or harvest staff data for later attacks. Beyond the loss itself sit the recovery costs, the audit, the legal exposure and the damage to supplier and customer trust. For a smaller firm, a single large transfer can threaten the whole business.
Business Email Compromise Examples
BEC is not theoretical. These three cases, spanning a decade, show the scam evolving from fake invoices to live deepfakes.

Facebook and Google
Between 2013 and 2015 a Lithuanian man, Evaldas Rimasauskas, defrauded Facebook and Google of more than $120 million. He registered a company impersonating Quanta Computer, a Taiwanese hardware maker both firms genuinely used, then sent fake invoices, forged contracts and letters bearing false corporate seals.
Facebook lost about $99 million and Google about $23 million, though both recovered most or all of the money. Rimasauskas pleaded guilty in 2019 and was sentenced to five years, per the US Department of Justice. A simple check of the new bank details with a known contact at the real supplier would have exposed the fraud.
FACC
In January 2016 an email impersonating the chief executive of FACC, an Austrian aerospace parts maker, asked a finance employee to wire funds for a fake acquisition. About €50 million was wired out before anyone noticed. FACC managed to freeze
roughly €10.9 million, leaving a net loss of about €42 million.
The consequences reached the top. FACC’s board dismissed both the chief executive and the finance chief over the incident, a reminder that payment fraud is now a governance issue. Dual authorisation and a mandatory second-channel check for any large or unusual transfer would have removed the single point of failure.
Arup
The newest case shows where BEC is heading. In January 2024 a finance employee at the Hong Kong office of the engineering firm Arup received an email, apparently from the chief financial officer in the UK, about a confidential transaction. The employee was suspicious and asked for a video call.
On the call the chief financial officer and several colleagues looked and sounded normal. Every one of them was an AI-generated deepfake built from public footage. Reassured, the employee made 15 transfers totalling about $25 million. Hong Kong police confirmed the fraud, and the money was not recovered.
No Arup system was breached. The attackers bypassed technology and targeted a person directly. Verification failed because the video call was arranged by the attacker, so it was never independent. A callback to the executive on a previously known number would have broken the illusion.
Business Email Compromise and Compliance
For many Swedish organisations, BEC is now a compliance matter as well as a financial one. Cybersäkerhetslagen (SFS 2025:1506), in force since 15 January 2026, transposes the EU NIS2 Directive into Swedish law. Under NIS2 Article 20 the board approves and oversees security measures and can be held personally accountable, which is why the FACC dismissals matter.
NIS2 Article 21 requires incident handling and security awareness training, both central to stopping BEC, and Article 23 sets the reporting obligations. A significant incident must be reported to MCF (formerly MSB) and the relevant sector authority on a set cascade, an early warning within 24 hours, a full notification within 72 hours and a final report within one month.
A BEC that compromises a mailbox is usually a personal-data breach, which must be reported to IMY within 72 hours under GDPR Article 33. Financial firms face a parallel duty under DORA Article 17, supervised by Finansinspektionen. The reporting clock starts fast, so an incident plan matters.
How to Spot a BEC Email
Most BEC shares a recognisable shape. Learning the pattern helps, as long as it is backed by process and not treated as the only defence.
- A change to payment or bank details, especially at short notice.
- Pressure to act quickly, often with a deadline or a threat of consequences.
- A request for secrecy, such as keeping the transaction between you and the sender.
- A look-alike domain or a display name that does not match the real email address.
- A request that skips the normal approval process or moves to a personal email or phone.
There is a limit to spotting. AI now writes clean, well-formatted messages and clones voices and faces, so the classic tells of poor grammar and awkward phrasing are disappearing. Treat every one of these signs as a prompt to verify, and never as proof either way.
How to Defend Against BEC
The most effective defence against BEC is a payment process that does not rely on any single person spotting a fake. Verification should be a fixed step, not a judgement call made under pressure.
People: Train staff who handle payments to read authority and urgency as manipulation, and build a culture where checking a request is expected and never penalised. eBuilder’s security awareness training focuses on the payment-fraud scenarios that matter.
Process: Verify every new or changed bank detail through an independent channel, using a phone number you already hold and not one supplied in the request. Require dual authorisation for payments above a set threshold, and give staff a clear, no-blame way to pause a suspicious transfer.
Technology: Turn on multi-factor authentication for every mailbox to make account takeover harder. Deploy email authentication, meaning SPF, DKIM and DMARC at an enforcement policy, to block spoofing of your own domain. Monitor for the inbox rules attackers create to hide their replies, a job that suits managed detection and response.
Finally, plan for the day BEC fraud succeeds. Know how to contact your bank immediately to attempt a recall, and report the incident to the police and to the regulators where required. The FBI notes that speed is decisive, since a fast recall is often the only way to get funds back.