Back to Blog
Threat Intelligence19 min read2024-11-18

Business Email Compromise (BEC): Understanding the $50 Billion Threat

BEC attacks have caused over $50 billion in losses. Learn how these sophisticated scams work and implement defenses to protect your organization.

A

Asfaleia Team

Chief Security Researcher

Business Email Compromise (BEC): Understanding the $50 Billion Threat
Sections

Introduction to Business Email Compromise

Business Email Compromise (BEC) is a sophisticated scam targeting businesses that conduct wire transfers and have suppliers abroad. Criminals compromise legitimate business email accounts through social engineering or computer intrusion to conduct unauthorized fund transfers.

The Scale of the Problem:
$50+ billion in global losses (2013-2022)
$2.7 billion in losses in 2022 alone
19,954 complaints in 2022
Average loss per incident: $125,000
Targets organizations of all sizes
Why BEC is So Effective:
No malware to detect
Exploits trust relationships
Leverages legitimate email accounts
Time-sensitive pressure tactics
Targets employees with payment authority

Types of BEC Attacks

1. CEO Fraud / Executive Impersonation

How It Works:

Attackers impersonate a CEO or senior executive, requesting urgent wire transfers from finance staff.

Example Email:
From: [email protected] (spoofed)
To: [email protected]
Subject: Urgent - Confidential
I need you to process an urgent wire transfer for an acquisition we're working on. This is highly confidential - please don't discuss with anyone else. The amount is $125,000 to the following account...
Please confirm when done.
Sent from my iPhone
Red Flags:
Urgency and secrecy demands
Request to bypass normal procedures
Unusual timing (after hours, holidays)
Mobile signature implying limited communication

2. Invoice Fraud / Vendor Impersonation

How It Works:

Attackers impersonate vendors or suppliers, requesting payment to fraudulent accounts.

Scenarios:
Modified invoices with changed banking details
Fake "account change" notifications
Intercepted email conversations with real vendors
Example:
From: [email protected] (compromised or spoofed)
Subject: Updated Banking Information
Dear Accounts Payable,
Please note our banking information has changed due to an internal restructuring. Effective immediately, please direct all payments to:
Bank: First National Bank
Account: 123456789
Routing: 987654321
Please update your records and use this for our outstanding invoice #4521.
Thank you for your prompt attention.

3. Account Compromise

How It Works:

Attackers gain access to a legitimate employee's email account and use it to request payments or redirect invoices.

Attack Chain:
1Phishing email steals credentials
2Attacker accesses victim's mailbox
3Creates email rules to hide activities
4Sends fraudulent requests from legitimate account
5Intercepts responses to maintain deception
Why It's Dangerous:
Emails come from legitimate accounts
SPF/DKIM/DMARC won't help
Attackers see conversation history
Can intercept warnings

4. Attorney/Legal Impersonation

How It Works:

Attackers pose as lawyers or legal representatives, often during end-of-quarter or deal closings.

Common Pretexts:
M&A transaction closings
Legal settlements
Confidential matters requiring discretion
Time-sensitive legal requirements

5. Data Theft BEC

How It Works:

Instead of money, attackers request sensitive data like W-2s, employee PII, or customer information.

Example:
From: [email protected] (spoofed)
To: [email protected]
Subject: Employee W-2 Request
Hi,
I need copies of all employee W-2 forms for a review we're conducting. Please send them in PDF format at your earliest convenience.
Thanks
Impact:
Tax fraud
Identity theft
Data breach notification requirements
Regulatory fines

BEC Attack Lifecycle

Phase 1: Target Selection

Research Activities:
Company website and press releases
LinkedIn for org structure
SEC filings for financial info
Social media for personal details
News for M&A activity
Ideal Targets:
Companies with international suppliers
Real estate transactions
Law firms
Organizations with loose processes

Phase 2: Reconnaissance

Information Gathered:
Email naming conventions
Executive communication styles
Vendor relationships
Payment procedures
Key personnel
Technical Reconnaissance:
Email security controls (SPF, DKIM, DMARC)
Authentication systems
Out-of-office messages

Phase 3: Account Access/Spoofing

Methods:
Credential phishing
Malware deployment
Domain spoofing (look-alike domains)
Display name spoofing
Reply-to manipulation
Look-alike Domains:
Legitimate: company.com
Spoofed: c0mpany.com (zero instead of o)
Spoofed: cornpany.com (rn looks like m)
Spoofed: company-inc.com (added suffix)
Spoofed: companyy.com (double letter)

Phase 4: Execution

Attack Elements:
Urgency and pressure
Authority exploitation
Confidentiality demands
Procedure bypass requests
Emotional manipulation

Phase 5: Money Movement

Laundering Methods:
Wire to foreign accounts
Cryptocurrency conversion
Money mules
Shell companies
Quick withdrawal before detection

Prevention Strategies

Email Security Controls

Technical Measures:
SPF (Sender Policy Framework):
v=spf1 include:_spf.google.com include:mail.company.com -all
DKIM (DomainKeys Identified Mail):
Sign outbound emails
Verify inbound signatures
Alert on failures
DMARC (Domain-based Message Authentication):
v=DMARC1; p=reject; rua=mailto:[email protected]
Advanced Email Security:
Anti-spoofing filters
Display name protection
Look-alike domain detection
Machine learning analysis
URL sandboxing

Process Controls

Wire Transfer Procedures:
1Dual Approval
All transfers above threshold require two approvers
Approvers must be from different departments
2Verbal Verification
Call known phone number (not from email)
Verify all banking changes
Document verification
3Waiting Period
24-48 hour delay for new account payments
Mandatory delay for banking changes
Time for verification
4Payment Limits
Transaction limits by role
Daily/monthly limits
Exception approval process
Vendor Management:
1Verified Contact List
Pre-established contacts for vendors
Phone numbers from contracts, not emails
Update process with verification
2Banking Change Procedures
Written request on letterhead
Multi-channel verification
Waiting period before changes
3Regular Reconciliation
Match payments to invoices
Verify deliveries
Audit payment patterns

Employee Training

Training Focus Areas:
BEC attack recognition
Email header analysis
Verification procedures
Reporting suspicious emails
Real-world examples
Red Flag Training:
Urgency demands
Secrecy requirements
Procedure bypass requests
Unusual timing
Grammar/style changes
New or changed payment details
Simulations:
BEC simulation exercises
Tabletop scenarios
Process testing
Response drills

Technical Detection

Email Analysis:
Header anomaly detection
Reply-to field monitoring
Domain age checking
Sender reputation scoring
Behavioral Analysis:
Unusual payment patterns
New vendor additions
Banking change requests
Large transaction alerts
Account Security:
Impossible travel detection
New device alerts
Email rule monitoring
Forwarding rule alerts

Incident Response

Immediate Actions (First 24 Hours)

1Contact Financial Institution
Request wire recall
Freeze receiving account if possible
Document all communications
2Preserve Evidence
Do not delete emails
Document timeline
Preserve headers and logs
Screenshot everything
3Report to Authorities
FBI IC3 complaint
Local law enforcement
Financial regulatory body
4Internal Notification
Legal counsel
Executive leadership
Insurance carrier
PR/Communications

Recovery Efforts

Wire Recall Process:
Contact bank immediately
Provide all transaction details
Request intermediary bank holds
Work with receiving bank country
Success Factors:
Speed of detection (within 24-48 hours)
Clear documentation
Law enforcement involvement
Bank cooperation
Recovery Statistics:
29% of funds recovered on average
Higher success within 24 hours
International transfers harder to recover
Cryptocurrency nearly impossible

Metrics and KPIs

Prevention Metrics

SPF/DKIM/DMARC implementation
Training completion rates
Simulation exercise results
Process compliance audits

Detection Metrics

Time to detect BEC attempts
False positive rates
User reporting rates
Security tool effectiveness

Response Metrics

Time to report to bank
Recovery rate
Investigation closure time
Lessons learned implementation

Conclusion

BEC attacks are among the most financially damaging cyber threats, relying on human trust rather than technical exploits. Defense requires a combination of technical controls, robust procedures, and comprehensive employee training.

Key Takeaways:
Verify all payment changes through known contacts
Implement multi-factor approval for wire transfers
Never bypass verification procedures for urgency
Train employees to recognize BEC tactics
Report suspicious emails immediately
Time is critical for fund recovery

Asfaleia-Tech offers BEC assessments, email security implementation, and employee training programs. Contact us to protect your organization from BEC attacks.

Tags

#BEC#Email Security#Wire Fraud#Social Engineering#Financial Crime

Downloadable-style takeaway

Use this as a working assessment checklist.

Pull the headings into your next security review, assign owners, and mark each section as ready, partial, or missing.

A

Written by

Asfaleia Team

Chief Security Researcher

Written by the Asfaleia Tech Security Team, combining field experience across offensive testing, detection engineering, incident readiness, and compliance evidence.

Ready to Strengthen Your Security?

Let's discuss how Asfaleia-Tech can help protect your organization.