Threats & attacks

What is Business Email Compromise?

Business email compromise uses a trusted-looking email to trick staff into moving money or changing bank details. Here is how BEC works, and how to stop it.

Key takeaways
  • Business email compromise (BEC) uses a trusted-looking email to trick staff into paying fraudsters or changing bank details.
  • BEC usually carries no malware and no link, so spam filters and antivirus do not stop it.
  • The FBI reported more than $3 billion in BEC losses in 2025, second only to investment fraud.
  • The average reported BEC loss was about $123,000, and 86% of losses moved by fast, hard-to-reverse wire or ACH payments.
  • Between 2013 and 2023 the FBI recorded about $55.5 billion in exposed BEC losses across 186 countries.
  • Common types include CEO fraud, invoice and vendor fraud, account compromise and payroll or data theft.
  • AI now writes flawless messages and clones voices and faces, so looking for bad grammar is no longer a reliable defence.
  • The single best control is out-of-band verification of any payment or bank-detail change using a contact you already hold.
  • Under Cybersäkerhetslagen and NIS2, a significant incident must be reported to MCF (formerly MSB) within set deadlines, and a mailbox breach may trigger GDPR reporting to IMY.
  • Dual authorisation, MFA and email authentication (SPF, DKIM and DMARC) reduce the risk that a single mistake becomes a loss.

Business Email Compromise Explained

Business email compromise, or BEC, is a targeted fraud in which a criminal uses a spoofed or hijacked email account to pose as someone the victim trusts, such as an executive, a supplier or a lawyer, and ask them to transfer money or change payment details. Most BEC carries no malware and no link.

That trust is what makes it work. The FBI’s Internet Crime Complaint Center recorded more than $3 billion in reported BEC losses in 2025, second only to investment fraud, from 24,768 complaints. The average reported loss was about $123,000.

Because a BEC message often looks like an ordinary request from a real colleague, it slips past spam filters and antivirus. The gap it exploits sits in the payment process, where a person authorises the transfer.

How Business Email Compromise Works

A BEC attack usually runs in four moves. First the criminal does research. Public sources, social media and a company website reveal who approves payments, which suppliers get paid and when a deal is in progress. Good BEC is tailored, so the request lands at a plausible moment.

How Business Email Compromise Works

Next comes access or disguise. The attacker either breaks into a real mailbox using stolen credentials, or registers a look-alike domain and spoofs the display name so the message appears to come from a known sender. A hijacked account is the more dangerous version, since replies stay inside a genuine thread.

Then the manipulation. The message uses authority, urgency and secrecy. A request from the chief executive, a deadline that cannot slip and an instruction to keep the matter confidential all discourage the victim from checking. The pretext is tied to something real, such as an invoice, an acquisition or a payroll update.

Finally the payment. The victim wires money to an account the attacker controls, or quietly updates a supplier’s bank details so future invoices pay the criminal. Generative AI has removed the last easy giveaway. Flawless writing, cloned voices and even live video now make the impersonation convincing, so the old advice to look for bad grammar no longer holds.

Types of BEC Attack

BEC is a family of scams rather than a single trick. Each message is aimed at a chosen target, which makes it a form of spear phishing, and it is sometimes called BEC phishing. The FBI groups the common variations by who the attacker imitates and what they ask for.

  • CEO fraud: The attacker poses as a senior executive and pressures an employee into an urgent transfer, often called fake president fraud or whaling.
  • Invoice and vendor fraud: A supplier’s email is faked or compromised, and the victim is asked to pay a real-looking invoice or send future payments to a new bank account.
  • Account compromise: A real employee’s mailbox is taken over, also called email account compromise, and used to request payments from customers or colleagues.
  • Attorney impersonation: The attacker poses as a lawyer handling a confidential or time-sensitive matter, using pressure and secrecy to force quick action.
  • Data and payroll theft: Rather than money, the request targets staff data, tax forms or payroll details, which are then used for further fraud.

The Business Impact of BEC

The first cost is direct and fast. In 2025 the FBI reported that 86% of BEC losses moved by wire transfer or ACH, methods that clear quickly and are hard to reverse once the money reaches another account. By the time the fraud is noticed, the funds are often gone.

A compromised mailbox carries a second cost. It usually holds personal data, so the incident can be a reportable data breach even when no money is lost. That brings regulatory duties, which the next section covers.

Other variants divert salary payments or harvest staff data for later attacks. Beyond the loss itself sit the recovery costs, the audit, the legal exposure and the damage to supplier and customer trust. For a smaller firm, a single large transfer can threaten the whole business.

Business Email Compromise Examples

BEC is not theoretical. These three cases, spanning a decade, show the scam evolving from fake invoices to live deepfakes.

Business Email Compromise Examples

Facebook and Google

Between 2013 and 2015 a Lithuanian man, Evaldas Rimasauskas, defrauded Facebook and Google of more than $120 million. He registered a company impersonating Quanta Computer, a Taiwanese hardware maker both firms genuinely used, then sent fake invoices, forged contracts and letters bearing false corporate seals.

Facebook lost about $99 million and Google about $23 million, though both recovered most or all of the money. Rimasauskas pleaded guilty in 2019 and was sentenced to five years, per the US Department of Justice. A simple check of the new bank details with a known contact at the real supplier would have exposed the fraud.

FACC

In January 2016 an email impersonating the chief executive of FACC, an Austrian aerospace parts maker, asked a finance employee to wire funds for a fake acquisition. About €50 million was wired out before anyone noticed. FACC managed to freeze
roughly €10.9 million, leaving a net loss of about €42 million.

The consequences reached the top. FACC’s board dismissed both the chief executive and the finance chief over the incident, a reminder that payment fraud is now a governance issue. Dual authorisation and a mandatory second-channel check for any large or unusual transfer would have removed the single point of failure.

Arup

The newest case shows where BEC is heading. In January 2024 a finance employee at the Hong Kong office of the engineering firm Arup received an email, apparently from the chief financial officer in the UK, about a confidential transaction. The employee was suspicious and asked for a video call.

On the call the chief financial officer and several colleagues looked and sounded normal. Every one of them was an AI-generated deepfake built from public footage. Reassured, the employee made 15 transfers totalling about $25 million. Hong Kong police confirmed the fraud, and the money was not recovered.

No Arup system was breached. The attackers bypassed technology and targeted a person directly. Verification failed because the video call was arranged by the attacker, so it was never independent. A callback to the executive on a previously known number would have broken the illusion.

Business Email Compromise and Compliance

For many Swedish organisations, BEC is now a compliance matter as well as a financial one. Cybersäkerhetslagen (SFS 2025:1506), in force since 15 January 2026, transposes the EU NIS2 Directive into Swedish law. Under NIS2 Article 20 the board approves and oversees security measures and can be held personally accountable, which is why the FACC dismissals matter.

NIS2 Article 21 requires incident handling and security awareness training, both central to stopping BEC, and Article 23 sets the reporting obligations. A significant incident must be reported to MCF (formerly MSB) and the relevant sector authority on a set cascade, an early warning within 24 hours, a full notification within 72 hours and a final report within one month.

A BEC that compromises a mailbox is usually a personal-data breach, which must be reported to IMY within 72 hours under GDPR Article 33. Financial firms face a parallel duty under DORA Article 17, supervised by Finansinspektionen. The reporting clock starts fast, so an incident plan matters.

How to Spot a BEC Email

Most BEC shares a recognisable shape. Learning the pattern helps, as long as it is backed by process and not treated as the only defence.

  • A change to payment or bank details, especially at short notice.
  • Pressure to act quickly, often with a deadline or a threat of consequences.
  • A request for secrecy, such as keeping the transaction between you and the sender.
  • A look-alike domain or a display name that does not match the real email address.
  • A request that skips the normal approval process or moves to a personal email or phone.

There is a limit to spotting. AI now writes clean, well-formatted messages and clones voices and faces, so the classic tells of poor grammar and awkward phrasing are disappearing. Treat every one of these signs as a prompt to verify, and never as proof either way.

How to Defend Against BEC

The most effective defence against BEC is a payment process that does not rely on any single person spotting a fake. Verification should be a fixed step, not a judgement call made under pressure.

People: Train staff who handle payments to read authority and urgency as manipulation, and build a culture where checking a request is expected and never penalised. eBuilder’s security awareness training focuses on the payment-fraud scenarios that matter.

Process: Verify every new or changed bank detail through an independent channel, using a phone number you already hold and not one supplied in the request. Require dual authorisation for payments above a set threshold, and give staff a clear, no-blame way to pause a suspicious transfer.

Technology: Turn on multi-factor authentication for every mailbox to make account takeover harder. Deploy email authentication, meaning SPF, DKIM and DMARC at an enforcement policy, to block spoofing of your own domain. Monitor for the inbox rules attackers create to hide their replies, a job that suits managed detection and response.

Finally, plan for the day BEC fraud succeeds. Know how to contact your bank immediately to attempt a recall, and report the incident to the police and to the regulators where required. The FBI notes that speed is decisive, since a fast recall is often the only way to get funds back.

Myths & Facts

Myth

BEC is just spam that our email filter will catch.

Only large corporations are targeted by BEC.

You can always spot a scam email by its bad grammar.

If the email comes from my boss’s real address, it must be genuine.

BEC only matters if money is actually lost.

Our bank will simply reverse a fraudulent transfer.

Fact

BEC often contains no malicious link or attachment, so it bypasses spam filters and antivirus. It relies on a believable request to a real person, which is why payment verification matters more than filtering.

The FBI reports BEC against small local businesses as well as large firms. Smaller organisations are attractive because they often lack dual authorisation and formal payment checks, and a single loss can be severe.

Generative AI now produces flawless, well-formatted messages and can clone voices and video. The old giveaways have largely gone, so the reliable test is verification through a separate channel rather than a careful read of the message.

Attackers hijack real mailboxes through stolen passwords, so a message from a genuine address can still be fraudulent. Multi-factor authentication and a verification step for payment requests both reduce this risk.

A compromised mailbox is usually a personal-data breach in its own right, which can trigger a 72-hour reporting duty to IMY under GDPR even when no funds move. The compliance exposure is real either way.

BEC payments usually move by wire or ACH, which clear quickly and are hard to recall. Recovery depends on contacting the bank within hours, and in many cases the money is never returned.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario simulation

  1. A long-standing supplier emails to say their bank has changed, and asks you to send this month’s payment to a new account. The address and signature look correct.

    What do you do?

    • Update the details and pay, since the email looks genuine.
    • Call the supplier on a number you already hold to confirm the change.
    • Reply to the email asking them to confirm the new account.
  2. You receive an urgent email from your chief executive asking you to wire a large sum for a confidential acquisition, and to tell no one until it closes.

    What is the safest response?

    • Act quickly and keep it confidential, as instructed.
    • Verify on a known number and follow the dual-authorisation process.
    • Forward the email to a colleague and ask if it looks real.
  3. After a suspicious payment email, you join a video call where your CFO and two colleagues appear and repeat the request. They look and sound normal.

    What should you do before paying?

    • Pay, because seeing them on video confirms the request.
    • End the call and confirm through a separate channel you control.
    • Ask the people on the call to prove who they are.
  4. An hour after paying an invoice, you realise the bank details were fraudulent and the supplier never sent the request.

    What is the right first step?

    • Wait to see if the supplier notices before raising it.
    • Contact your bank immediately to attempt a recall, then report it.
    • Delete the email so the mistake is not discovered.

Knowledge test

  1. Why do most BEC emails get past spam filters and antivirus?

    • They use advanced encryption
    • They usually contain no malicious link or attachment
    • They are sent from government servers
    • They are too short to scan

    BEC relies on a believable request rather than malware, so there is often no link or file for security tools to catch.

  2. According to the FBI, roughly how much did BEC cost in reported losses in 2025?

    • More than $300 million
    • More than $3 billion
    • More than $30 billion
    • More than $300 billion

    The FBI’s Internet Crime Complaint Center reported more than $3 billion in BEC losses in 2025, second only to investment fraud.

  3. What is the single most effective control against BEC?

    • Out-of-band verification of payment and bank-detail changes
    • A stronger spam filter
    • Longer email passwords
    • Blocking all external email

    Confirming any payment or bank-detail change through a separate, trusted channel stops the fraud even when the email looks genuine.

  4. Why is looking for bad grammar no longer a reliable way to spot BEC?

    • Spell-checkers are now standard
    • Criminals hire professional writers
    • AI can generate flawless text and clone voices and video
    • Grammar was never a clue

    Generative AI produces clean, well-formatted messages and convincing voice and video, removing the language clues people once relied on.

  5. Under Cybersäkerhetslagen and NIS2, who can be held personally accountable for security measures?

    • Only the IT department
    • The management body, or board
    • External auditors
    • The email provider

    NIS2 Article 20 makes the board responsible for approving and overseeing security measures, which is why payment fraud is a governance issue.

  6. Why are BEC payments often impossible to recover?

    • They are paid in cash
    • Banks refuse to help
    • They are sent abroad by law
    • They move by wire or ACH, which clear quickly and are hard to reverse

    In 2025 the FBI reported that 86% of BEC losses moved by wire or ACH, fast methods that are difficult to recall once cleared.

Take it with you

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Every BEC attack ends with a person deciding to act. Technology narrows the gap, but the final safeguard is a trained employee who pauses to verify an unusual payment request. That is a skill, and it fades without practice.

Regular, scenario-based training keeps payment fraud recognisable and makes verification the normal response instead of an awkward exception. eBuilder’s security awareness training is built around the payment and impersonation scenarios that cause real losses, so your team meets the tactics in a safe setting before a criminal tries them for real.

Frequently Asked Questions

What is business email compromise in simple terms?

Business email compromise is a fraud in which a criminal poses as someone you trust, such as an executive or a supplier, and uses email to trick you into transferring money or changing payment details. It usually involves no malware, which is why it defeats standard email security.

Is BEC the same as phishing?

BEC is a targeted form of email fraud, while phishing is usually a bulk attack sent to many people at once. BEC is researched and personalised, often impersonating a specific colleague or supplier, and it frequently carries no link or attachment, unlike typical phishing emails.

What are the main types of BEC attack?

The main types are CEO fraud, invoice and vendor fraud, account compromise, attorney impersonation and data or payroll theft. They differ by who the attacker imitates and what they request, but all rely on a believable message that pressures a person into acting before they verify it.

How much money does BEC cost businesses?

The FBI’s Internet Crime Complaint Center reported more than $3 billion in BEC losses in 2025, making it the second-costliest cybercrime after investment fraud. Between 2013 and 2023 it recorded about $55.5 billion in exposed losses worldwide. These figures cover only cases reported to the FBI, so the real total is higher.

What are the warning signs of a BEC email?

The clearest warning signs are a sudden change to bank or payment details, pressure to act urgently, a request for secrecy and a sender address or domain that does not quite match. Any request that skips the normal approval process should be verified through a separate, trusted channel before you act.

Can BEC be stopped by a spam filter or antivirus?

Not reliably. Because BEC messages often contain no malicious link, attachment or code, they pass through spam filters and antivirus that look for those signals. Stopping BEC depends far more on payment process controls, staff verification and email authentication than on any single filtering tool.

What is the single best way to prevent BEC?

The single most effective control is out-of-band verification. Before paying a new or changed bank detail, confirm it by calling the supplier or executive on a number you already hold rather than one supplied in the email. Pair this with dual authorisation for larger payments so no one person can release funds alone.

How do deepfakes and AI change BEC?

AI makes BEC far more convincing. It generates flawless text in any language, clones a known voice from a short sample and can fake live video, as in the 2024 Arup case where a deepfake video call led to a $25 million loss. This removes the language and quality clues people once relied on.

What should I do if we have already paid a fraudulent invoice?

Act within hours, because speed decides whether funds can be recovered. Contact your bank immediately to request a recall of the payment and preserve all emails and evidence. Report the incident to the police, and notify the relevant regulator if personal data was exposed.

Do we have to report a BEC incident to the authorities in Sweden?

Often, yes. If your organisation falls under Cybersäkerhetslagen and NIS2, a significant incident must be reported to MCF (formerly MSB) and your sector authority, with an early warning within 24 hours. A mailbox breach that exposes personal data also requires notifying IMY within 72 hours under GDPR.

Get a 30-Minute Security Briefing. No Pitch Deck.

Talk to a Sweden-based analyst. We'll review your posture, map your NIS2 gaps, and give you a clear picture of where you stand, in plain language.

Book a Free Briefing
No commitment Sweden-based analyst

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.