Introduction to Business Email Compromise
Business Email Compromise (BEC) is a sophisticated scam targeting businesses that conduct wire transfers and have suppliers abroad. Criminals compromise legitimate business email accounts through social engineering or computer intrusion to conduct unauthorized fund transfers.
The Scale of the Problem:
$50+ billion in global losses (2013-2022)
$2.7 billion in losses in 2022 alone
19,954 complaints in 2022
Average loss per incident: $125,000
Targets organizations of all sizes
Why BEC is So Effective:
No malware to detect
Exploits trust relationships
Leverages legitimate email accounts
Time-sensitive pressure tactics
Targets employees with payment authority
Types of BEC Attacks
1. CEO Fraud / Executive Impersonation
How It Works:
Attackers impersonate a CEO or senior executive, requesting urgent wire transfers from finance staff.
Example Email:
From: [email protected] (spoofed)
To: [email protected]
Subject: Urgent - Confidential
I need you to process an urgent wire transfer for an acquisition we're working on. This is highly confidential - please don't discuss with anyone else. The amount is $125,000 to the following account...
Please confirm when done.
Sent from my iPhone
Red Flags:
Urgency and secrecy demands
Request to bypass normal procedures
Unusual timing (after hours, holidays)
Mobile signature implying limited communication
2. Invoice Fraud / Vendor Impersonation
How It Works:
Attackers impersonate vendors or suppliers, requesting payment to fraudulent accounts.
Scenarios:
Modified invoices with changed banking details
Fake "account change" notifications
Intercepted email conversations with real vendors
Example:
From: [email protected] (compromised or spoofed)
Subject: Updated Banking Information
Dear Accounts Payable,
Please note our banking information has changed due to an internal restructuring. Effective immediately, please direct all payments to:
Bank: First National Bank
Account: 123456789
Routing: 987654321
Please update your records and use this for our outstanding invoice #4521.
Thank you for your prompt attention.
3. Account Compromise
How It Works:
Attackers gain access to a legitimate employee's email account and use it to request payments or redirect invoices.
Attack Chain:
1Phishing email steals credentials
2Attacker accesses victim's mailbox
3Creates email rules to hide activities
4Sends fraudulent requests from legitimate account
5Intercepts responses to maintain deception
Why It's Dangerous:
Emails come from legitimate accounts
SPF/DKIM/DMARC won't help
Attackers see conversation history
Can intercept warnings
4. Attorney/Legal Impersonation
How It Works:
Attackers pose as lawyers or legal representatives, often during end-of-quarter or deal closings.
Common Pretexts:
M&A transaction closings
Legal settlements
Confidential matters requiring discretion
Time-sensitive legal requirements
5. Data Theft BEC
How It Works:
Instead of money, attackers request sensitive data like W-2s, employee PII, or customer information.
Example:
From: [email protected] (spoofed)
To: [email protected]
Subject: Employee W-2 Request
Hi,
I need copies of all employee W-2 forms for a review we're conducting. Please send them in PDF format at your earliest convenience.
Thanks
Impact:
Tax fraud
Identity theft
Data breach notification requirements
Regulatory fines
BEC Attack Lifecycle
Phase 1: Target Selection
Research Activities:
Company website and press releases
LinkedIn for org structure
SEC filings for financial info
Social media for personal details
News for M&A activity
Ideal Targets:
Companies with international suppliers
Real estate transactions
Law firms
Organizations with loose processes
Phase 2: Reconnaissance
Information Gathered:
Email naming conventions
Executive communication styles
Vendor relationships
Payment procedures
Key personnel
Technical Reconnaissance:
Email security controls (SPF, DKIM, DMARC)
Authentication systems
Out-of-office messages
Phase 3: Account Access/Spoofing
Methods:
Credential phishing
Malware deployment
Domain spoofing (look-alike domains)
Display name spoofing
Reply-to manipulation
Look-alike Domains:
Legitimate: company.com
Spoofed: c0mpany.com (zero instead of o)
Spoofed: cornpany.com (rn looks like m)
Spoofed: company-inc.com (added suffix)
Spoofed: companyy.com (double letter)
Phase 4: Execution
Attack Elements:
Urgency and pressure
Authority exploitation
Confidentiality demands
Procedure bypass requests
Emotional manipulation
Phase 5: Money Movement
Laundering Methods:
Wire to foreign accounts
Cryptocurrency conversion
Money mules
Shell companies
Quick withdrawal before detection
Prevention Strategies
Email Security Controls
Technical Measures:
SPF (Sender Policy Framework):
v=spf1 include:_spf.google.com include:mail.company.com -all
DKIM (DomainKeys Identified Mail):
Sign outbound emails
Verify inbound signatures
Alert on failures
DMARC (Domain-based Message Authentication):
v=DMARC1; p=reject; rua=mailto:[email protected]
Advanced Email Security:
Anti-spoofing filters
Display name protection
Look-alike domain detection
Machine learning analysis
URL sandboxing
Process Controls
Wire Transfer Procedures:
1Dual Approval
All transfers above threshold require two approvers
Approvers must be from different departments
2Verbal Verification
Call known phone number (not from email)
Verify all banking changes
Document verification
3Waiting Period
24-48 hour delay for new account payments
Mandatory delay for banking changes
Time for verification
4Payment Limits
Transaction limits by role
Daily/monthly limits
Exception approval process
Vendor Management:
1Verified Contact List
Pre-established contacts for vendors
Phone numbers from contracts, not emails
Update process with verification
2Banking Change Procedures
Written request on letterhead
Multi-channel verification
Waiting period before changes
3Regular Reconciliation
Match payments to invoices
Verify deliveries
Audit payment patterns
Employee Training
Training Focus Areas:
BEC attack recognition
Email header analysis
Verification procedures
Reporting suspicious emails
Real-world examples
Red Flag Training:
Urgency demands
Secrecy requirements
Procedure bypass requests
Unusual timing
Grammar/style changes
New or changed payment details
Simulations:
BEC simulation exercises
Tabletop scenarios
Process testing
Response drills
Technical Detection
Email Analysis:
Header anomaly detection
Reply-to field monitoring
Domain age checking
Sender reputation scoring
Behavioral Analysis:
Unusual payment patterns
New vendor additions
Banking change requests
Large transaction alerts
Account Security:
Impossible travel detection
New device alerts
Email rule monitoring
Forwarding rule alerts
Incident Response
Immediate Actions (First 24 Hours)
1Contact Financial Institution
Request wire recall
Freeze receiving account if possible
Document all communications
2Preserve Evidence
Do not delete emails
Document timeline
Preserve headers and logs
Screenshot everything
3Report to Authorities
FBI IC3 complaint
Local law enforcement
Financial regulatory body
4Internal Notification
Legal counsel
Executive leadership
Insurance carrier
PR/Communications
Recovery Efforts
Wire Recall Process:
Contact bank immediately
Provide all transaction details
Request intermediary bank holds
Work with receiving bank country
Success Factors:
Speed of detection (within 24-48 hours)
Clear documentation
Law enforcement involvement
Bank cooperation
Recovery Statistics:
29% of funds recovered on average
Higher success within 24 hours
International transfers harder to recover
Cryptocurrency nearly impossible
Metrics and KPIs
Prevention Metrics
SPF/DKIM/DMARC implementation
Training completion rates
Simulation exercise results
Process compliance audits
Detection Metrics
Time to detect BEC attempts
False positive rates
User reporting rates
Security tool effectiveness
Response Metrics
Time to report to bank
Recovery rate
Investigation closure time
Lessons learned implementation
Conclusion
BEC attacks are among the most financially damaging cyber threats, relying on human trust rather than technical exploits. Defense requires a combination of technical controls, robust procedures, and comprehensive employee training.
Key Takeaways:
Verify all payment changes through known contacts
Implement multi-factor approval for wire transfers
Never bypass verification procedures for urgency
Train employees to recognize BEC tactics
Report suspicious emails immediately
Time is critical for fund recovery
Asfaleia-Tech offers BEC assessments, email security implementation, and employee training programs. Contact us to protect your organization from BEC attacks.