Business email compromise is a scam where someone impersonates a trusted contact, usually an executive, vendor, or client, through a hijacked or spoofed email account, to trick your business into sending money or changing payment details. You might be saying, “Tony, this isn’t new, we’ve seen these phishing attempts for years now. We’re smarter than that”
And you might be right. But even still, it accounts for billions of dollars of losses annually, meaning it’s still one of the most important security measures that businesses can take in 2026 and beyond. In fact, the FBI’s Internet Crime Complaint Center recorded $3.05 billion in BEC losses in 2025 alone, across nearly 24,800 complaints, making it the second costliest crime type the agency tracks.
Business email compromise, or BEC, is a scam where an attacker impersonates someone your business trusts (an executive, a vendor, or a client) through a compromised or spoofed email account, to trick an employee into sending money or changing payment details. Unlike a lot of cybercrime, it doesn’t need malware, a virus, or a hacked network to work.
It’s different from generic phishing in one important way. Phishing usually casts a wide net looking for anyone who’ll click a bad link. BEC is targeted. The attacker studies your business first: who signs off on wire transfers, which vendors you work with, how your executives write emails. Then they use that research to make one specific request look completely normal.
BEC is one of the two costliest categories of cybercrime the FBI tracks, behind only investment fraud. In 2025, the FBI’s Internet Crime Complaint Center logged 24,768 BEC complaints totaling just over $3.05 billion in reported losses, an average of roughly $123,000 per incident.
BEC losses have stayed in the top two crime categories for multiple years running, and total cybercrime losses reported to the IC3 climbed 26% from 2024 to 2025, reaching nearly $20.9 billion across all categories. Small and mid-sized businesses make up a large share of these cases because smaller businesses tend to have fewer checks in place around wire transfers and vendor payment changes.
A BEC scam usually follows the same basic pattern, no matter which specific angle the attacker uses:
The specific tactic changes, but it usually falls into one of three categories.
|
Tactic |
How It Works |
Red Flag
|
|---|---|---|
|
Executive impersonation |
An email that looks like it’s from a company leader asks for an urgent, confidential wire transfer |
Urgency, secrecy, and a request to skip normal approval steps |
|
Vendor invoice fraud |
A real invoice arrives with quietly changed bank account details |
Any payment detail change that doesn’t come with a phone call to confirm |
|
Payroll diversion |
An employee’s direct deposit gets rerouted to an attacker’s account |
A direct deposit change request that didn’t go through HR directly |
86% of the money lost to BEC in 2025 moved through wire transfer or ACH, the same payment rails your business uses every day for legitimate transactions. That’s exactly why it works. Nothing about the payment itself looks unusual until the money is already gone.
Standard security tools don’t catch BEC because there’s usually nothing malicious to detect. No virus gets installed. No malicious link gets clicked. Antivirus software and spam filters are built to flag dangerous attachments and known bad links, and a well-written BEC email often contains neither.
This is a social engineering ploy wearing a technical disguise. Credential theft is one common way an attacker gets into a real email account in the first place, since a compromised inbox is far more convincing than a spoofed one. Once they’re in, they can study real email threads, jump into an existing conversation, and send a request that looks exactly like it belongs there. That’s why identity security and email account protection matter here as much as any spam filter.
Stopping BEC comes down to habits more than software, though the right technical controls help enforce those habits.
BEC is a people problem that technology can help guard against, but it can’t solve alone. If your current setup doesn’t include real verification steps for payment changes, we’ll help you build them.
What is business email compromise?
Business email compromise is a scam where an attacker impersonates a trusted contact, such as an executive or vendor, through a hijacked or spoofed email account to trick a business into sending money or changing payment details.
How does BEC differ from regular phishing?
Regular phishing casts a wide net hoping anyone clicks a bad link. BEC is targeted and researched, built around a specific business’s real vendors, executives, and communication patterns, and it often skips malware entirely.
Can BEC happen even with antivirus and spam filters in place?
Yes. Most BEC emails don’t contain malware or malicious links, so standard security tools have nothing to flag. It relies on convincing writing and a legitimate-looking request, not a technical exploit.
What should I do if I suspect a BEC attempt at my business?
Don’t send the payment or confirm the change over email. Call the person or vendor directly using a number you already have on file, not one listed in the suspicious message, and report the attempt to your IT team right away.