Business Email Compromise: What It Is and How to Protect Your Business

Photo of Brian Largent

Brian Largent

CEO, ArcLight Group

June 29, 2026 5 min read
Share:
Business Email Compromise: What It Is and How to Protect Your Business

If there’s one cyber threat that keeps coming up in client conversations right now, it’s Business Email Compromise (BEC). And for good reason. BEC attacks racked up close to $3 billion in losses in 2023, and that number keeps climbing. Whether you run a small business or a larger operation, this is a threat you need to understand.

What Is Business Email Compromise?

BEC is a type of cybercrime where attackers manipulate or take over email accounts to commit fraud. Usually that means wire fraud or credential theft. These aren’t the obvious spam emails of years past. Today’s BEC attacks are targeted, well-researched, and harder to spot than ever.

Attackers are also using generative AI to write emails that mimic the tone, language, and style of people you trust. A colleague. A vendor. Your CEO. That’s what makes them dangerous.

How a BEC Attack Unfolds

There are two flavors of BEC attempts: passive and active.

Passive attempts

These are the simpler ones, but they still work.

  1. You get an email that convinces you to click a link and enter your username and password. If MFA is on, they then prompt you for the MFA code too.
  2. Someone calls you directly, claiming to be from your IT provider, your EMR or ERP or CRM vendor, Microsoft, Google, or another trusted name. They spin a story and ask for your login, or request remote access to “fix something.”
  3. Once they have your credentials, scripts run immediately to log into your email, probe internal systems, and look for what they can grab.
  4. If you let them onto your computer, things get a lot worse very fast. That’s a topic for another article.

Active attempts

These read more like a spy novel.

  1. The attacker studies your organization: names, roles, relationships, and communication patterns.
  2. Using adversary-in-the-middle (AiTM) techniques, they position themselves to harvest credentials and gather intelligence.
  3. Account takeover. Through phishing, social engineering, or software vulnerabilities, they get into a legitimate email account.
  4. They pose as someone you trust: your CFO, a supplier, your attorney.
  5. The ask. A convincing email goes out requesting a wire transfer, sensitive data, or credentials. Almost always with urgency baked in.

The goal is always the same. Get your people to act without stopping to question the request.

How to Spot a BEC Attack

Even with good defenses in place, the occasional BEC email will get through. Knowing what to look for is your first line of defense.

  • Spelling or grammar that’s off. Legitimate contacts don’t typically misspell their own company name.
  • Strange requests. Anything asking you to move the conversation to a personal phone number or messaging app, share credentials, or buy gift cards should set off alarms.
  • Artificial urgency. Phrases like “urgent” or “needs to happen right now” are pressure tactics.
  • Generic greetings or vague references. Attackers usually don’t know your internal lingo or specific working relationships.
  • Lookalike email addresses. A swapped letter or an added hyphen is easy to miss at a glance.

If something feels off, trust that instinct. Don’t reply to the suspicious email. Reach out to the supposed sender through a separate channel you already know is legitimate.

The Most Common Types of BEC Attacks

BEC isn’t one thing. Here are the variations we see most often.

Invoice fraud. Attackers compromise a vendor’s email account and send updated payment details that redirect funds to their own accounts.

CEO fraud. Someone posing as an executive asks a staff member for an urgent wire transfer or gift card purchase.

Payroll diversion. Attackers impersonate HR or an employee to reroute paychecks.

Voice cloning. AI-generated audio mimics a leader’s voice to lend credibility to a fraudulent request.

Email spoofing. Near-identical email addresses used to impersonate someone you trust.

Attorney impersonation. Attackers pose as legal counsel to pull sensitive information.

Account compromise scams. Fake “your account has been compromised” alerts that push you to click a phishing link.

Real Cases, Real Money

It’s easy to dismiss BEC as something that happens to other businesses. These cases tell a different story.

  • Facebook and Google lost more than $100 million to a scammer impersonating a hardware supplier.
  • Toyota Boshoku Corporation was defrauded out of more than $37 million through fake wire transfer requests.
  • Children’s Healthcare of Atlanta lost $3.6 million to an attacker posing as a construction company’s CFO.
  • Grand Rapids Public Schools had $2.8 million redirected when attackers impersonated their health insurer.

Once the money is gone, recovering it is extremely difficult. Often impossible.

What You Can Do

Because BEC attacks exploit human behavior, your defenses need a human focus too. Here’s where to start.

Security awareness training. Regular, current training helps your team recognize BEC tactics before they fall for them. Simulated phishing exercises keep people alert to evolving threats like deepfakes and fake CAPTCHA attacks.

Multi-factor authentication. MFA makes it significantly harder for attackers to take over an account even when credentials are stolen. It isn’t bulletproof, but it raises the bar considerably.

Identity threat detection and response (ITDR). ITDR tools monitor for behavioral anomalies. Suspicious inbox rules, unusual login locations, impossible travel patterns. The kind of signals that suggest an account takeover is in progress.

Secure payment processes. Don’t process invoices and payments through email. A dedicated portal with proper authentication makes it much harder for attackers to redirect funds. And verify any change in payment instructions by phone, using a number you already have on file.

Final Thoughts

Business email compromise is one of the fastest-growing threats facing businesses today, and it isn’t slowing down. The good news: with the right awareness, processes, and tools in place, it’s a manageable risk.

If you’d like to talk through your email security posture or how to tighten it up, give us a call. We’re happy to help.

ArcLight Group

(918) 270-6600

arclightgroup.com

Photo of Brian Largent
About the Author

Brian Largent

Father to five, husband to one, founder, CEO, and all around swell fella (or so I'm told)

Ready to harden your environment?

Get the 27-point assessment we run on every new client

Two hours. One real engineer. A written report telling you exactly where your gaps are — whether or not you ever hire us.

No hard sell. No obligation. Month-to-month after — cancel anytime.