Business Email Compromise (BEC): How B2B Wire Fraud Works and How to Stop It

Business Email Compromise (BEC) is a sophisticated scam targeting companies — not individuals. Attackers impersonate executives, vendors, or business partners to trick employees into wiring money to fraudulent accounts. The FBI reports over $50 billion in total losses since 2013, with BEC now the most financially damaging cybercrime in the United States.

Business Email Compromise, also known as email account compromise (EAC), is a type of phishing attack where criminals gain access to a company's email system or spoof a trusted sender's address to request fraudulent wire transfers, payment redirections, or sensitive data. Unlike many scams that target consumers, BEC targets finance departments, accounts payable teams, and executives at companies of all sizes. According to the FBI's Internet Crime Complaint Center, there were over 21,000 BEC complaints in 2024, with adjusted losses exceeding $2.9 billion. The median loss per incident was $50,000, but losses frequently reach into the millions for larger companies. BEC attacks are increasingly sophisticated, often involving months of reconnaissance before the fraudulent request is made.

Real-world example: A mid-sized manufacturing company received an email that appeared to be from their CEO, sent from an address that was identical except for one character ("@company.co" instead of "@company.com"). The email said the CEO was in a confidential meeting and needed an urgent wire transfer of $250,000 to a new vendor. The finance director, accustomed to receiving such requests from the CEO, processed the payment. The money was sent to a mule account in Hong Kong and was gone within hours. The real CEO was unaware until the next day.

Types of BEC Attacks

CEO Fraud / Executive Impersonation

The most common form. The attacker impersonates a high-level executive — CEO, CFO, or owner — and sends an urgent email to finance or HR requesting a wire transfer, payment to a new vendor, or purchase of gift cards. The email often claims the executive is in a confidential meeting or traveling and unable to discuss by phone. These emails are carefully timed to coincide with known executive travel schedules or busy periods like month-end closing.

Vendor Invoice Fraud

The attacker impersonates a legitimate vendor or supplier, sending fraudulent invoices with updated bank account details. The fake invoice looks nearly identical to the real one, and the payment is directed to the attacker's account. Attackers often gain access to the vendor's email system first, allowing them to monitor real invoice schedules and send their fraudulent invoices at the perfect moment.

Account Compromise

The attacker gains access to a legitimate employee's email account through phishing or credential theft. They monitor email traffic to learn about payment processes, vendor relationships, and approval workflows before sending fraudulent requests from the compromised account itself — making detection extremely difficult.

Lawyer Impersonation

The attacker impersonates an attorney or law firm handling a confidential matter, requesting urgent payment for a settlement, escrow, or legal fee. This variant exploits the authority and confidentiality associated with legal communications to bypass normal verification procedures.

Data Theft

Some BEC attacks target HR departments to obtain employee W-2 forms containing Social Security numbers and tax information, which are then used for identity theft and tax fraud. These attacks often coincide with tax season.

Red Flags and Warning Signs

Urgent and Unusual Payment Requests

Any request for an urgent wire transfer, especially outside normal processes, should trigger verification. BEC attacks thrive on urgency — they want employees to bypass normal procedures. If an executive who never sends direct payment requests suddenly asks for a wire transfer, verify independently.

Slight Changes in Email Addresses

Look for lookalike domains: "company.co" instead of "company.com", "c0mpany.com" with a zero instead of "o", or "company-llc.com" added to the real domain. Also check for spoofed display names — the sender name may say "CEO Jane Smith" but the actual email address is something unrelated.

Changed Bank Account Details

Never accept changed payment instructions via email alone. If a vendor sends a notification that their bank account has changed, verify by calling the vendor's known phone number — not the number in the suspicious email. This is the single most important control for preventing vendor invoice fraud.

Requests to Bypass Normal Procedures

If someone asks you to bypass standard payment approval workflows, that is a red flag. Legitimate urgent requests still go through proper channels. Any attempt to circumvent normal procedures should be treated as suspicious, regardless of the apparent sender.

Unusual Language or Tone

Pay attention to changes in communication style. An executive who normally writes casually but suddenly uses formal language, or a colleague who references projects you do not recognize, may be an impersonator. However, sophisticated BEC attackers study their targets and can replicate tone and style effectively.

How to Protect Your Business

Implement a mandatory payment verification process for all wire transfers and payment changes. Require in-person or phone confirmation using a known phone number — not the number from the email — for any payment request over a threshold amount ($5,000 or $10,000). Use multi-factor authentication on all email accounts, especially for executives and finance staff. Train employees to recognize BEC tactics and to verify unusual requests. Create a culture where it is acceptable to question any payment request, even from the CEO. Use email authentication protocols — SPF, DKIM, and DMARC — to detect and block spoofed emails. Consider using a payment confirmation service or positive pay system with your bank. Establish a response plan: if a fraudulent transfer is detected, contact the receiving bank immediately (the faster you act, the more likely funds can be frozen), contact your bank, notify the FBI's IC3, and preserve all evidence. The Financial Crimes Enforcement Network (FinCEN) has a rapid response process for BEC cases that can help recover funds if initiated within 72 hours.

What should I do if my company is hit by BEC?

Act immediately. Contact the sending bank and request a recall or reversal of the wire transfer. Contact the receiving bank to request a freeze on the funds. File a report with the FBI's Internet Crime Complaint Center at ic3.gov. The FBI's BEC recovery process is time-sensitive — funds can be frozen if you act quickly, especially if the transfer was sent to a domestic account. Contact the Secret Service if the fraud involves a significant amount. Preserve all evidence — emails, headers, transaction records — and do not delete anything. Notify your insurance carrier; many cyber insurance policies cover BEC losses. Conduct a post-incident review to identify how the attack occurred and update your procedures accordingly. Notify affected business partners and clients. Consider hiring a forensic cybersecurity firm to investigate the breach.

Related Resources