Business Email Compromise: CEO Fraud and Vendor Invoice Scams

Business email compromise (BEC) attacks cost organizations over $2.9 billion in 2024. The FBI reports that BEC has surpassed ransomware as the most financially damaging cybercrime, with an average loss of $120,000 per incident.

Business email compromise is a sophisticated form of phishing that targets employees with access to company finances. Attackers spend weeks or months researching their targets, studying internal communication patterns, and crafting convincing emails. They spoof or compromise email accounts of executives, vendors, or business partners to authorize fraudulent wire transfers, change vendor payment details, or request the purchase of gift cards. The attack relies on social engineering rather than technical hacking — the emails appear legitimate, using proper internal language, signatures, and even context from previous communications.

The FBI categorizes BEC into five types: CEO fraud (impersonating the CEO or executive to request a wire transfer), account compromise (hacking an employee's email and requesting payments to fraudulent accounts), fake invoice schemes (impersonating a vendor and providing new banking details), attorney impersonation (posing as a lawyer handling confidential matters), and data theft (requesting W-2 information or other employee data). The rise of AI-generated deepfake audio has added a sixth category — attackers now use voice cloning to call employees while impersonating executives, confirming fraudulent payment instructions by phone.

How BEC Attacks Work

A typical BEC attack begins with reconnaissance — the attacker identifies key personnel in the finance department, studies the organizational structure, and monitors social media for travel announcements or other absences. They register a domain that looks nearly identical to the company's real domain (e.g., using cornpany.com instead of company.com) or spoof the display name in the email header. The attacker sends an email from what appears to be the CEO's account to a finance employee, requesting an urgent wire transfer to a new vendor, often citing a confidential acquisition or time-sensitive deal that cannot be discussed publicly. The email creates urgency, authority, and secrecy — three psychological triggers that bypass normal verification procedures. Once the money is wired, it moves through multiple accounts across different countries within hours, making recovery extremely difficult.

Prevention Measures

Implement mandatory verification procedures for all wire transfer requests, especially those involving changes to vendor payment details. Require in-person or verbal confirmation using previously known phone numbers — not numbers provided in the suspicious email. Use multi-factor authentication for all email accounts. Implement DMARC, DKIM, and SPF email authentication protocols to detect domain spoofing. Train employees to spot BEC red flags: urgent requests for wire transfers, changes to vendor payment instructions, requests to maintain confidentiality, and unusual language from known contacts. Establish a company policy that no wire transfer can be authorized solely by email. Create a culture where employees feel comfortable double-checking financial requests, even from executives. If your company handles large wire transfers, consider using positive pay and transaction confirmation services with your bank.

FAQs

How do BEC attackers choose their targets?

Attackers target any employee with access to company finances — not just executives. They research organizations through LinkedIn, company websites, and news releases to identify finance personnel and executive structures. Small and medium businesses are frequent targets because they often have fewer security controls.

Can a company recover money lost to BEC?

Immediate action is critical. Contact your bank and law enforcement within hours — the FBI's IC3 has a Rapid Response Protocol that can freeze funds if notified quickly enough. However, recovery rates decline rapidly after 24 hours. Many companies enhance cyber insurance to cover social engineering fraud.

Is BEC only about wire transfers?

No. BEC attacks also target employee W-2 information (used for tax identity fraud), request gift card purchases, change direct deposit information to reroute payroll, and ask for credentials or sensitive data. Any request involving money or sensitive data from an email should be verified through a secondary channel.