Business Email Compromise: Why It's Still the Top Attack
Executive Summary
Business Email Compromise is not a new threat, but it remains the most financially damaging form of cybercrime targeting businesses today. According to the FBI's 2025 Internet Crime Complaint Center report, BEC accounted for $3.05 billion in reported losses across nearly 25,000 complaints in a single year. For business leaders who assume their team is too savvy to fall for a scam email, the attack methods have evolved well past anything that looks like a scam.
Why Business Email Compromise Is Still the Dominant Threat
Security headlines cycle through ransomware, AI-powered attacks, and nation-state intrusions. BEC rarely generates the same dramatic coverage, but it consistently produces the largest dollar losses of any cybercrime category. The FBI has tracked it since 2015, and cumulative losses have now crossed $17 billion.
What makes BEC so persistent is that it does not rely on breaking through technical defenses. It relies on breaking through human judgment. An attacker does not need to crack your firewall if they can convince your accounts payable coordinator that the CFO approved an urgent wire transfer. Endpoint protection and antivirus software offer no protection against a well-crafted email that looks exactly like one from a trusted colleague or vendor.
The threat has also grown more precise. In 2025, attackers increasingly used AI-generated content to make fraudulent emails nearly indistinguishable from genuine business correspondence. Roughly 74% of organizations reported facing BEC attempts in the past year, and attacks now target employees well beyond finance, including operations, HR, procurement, and administrative staff.
How BEC Attacks Actually Work
The mechanics of a BEC attack are less dramatic than they sound, which is exactly what makes them effective. Most follow one of a few patterns.
Email account takeover. An attacker gains access to a legitimate email account, often through a phishing link or a credential purchased from a prior breach. Rather than acting immediately, they observe. They read emails, learn the organization's financial processes, identify upcoming wire transfers, and study how executives communicate. In one 2025 case involving a mid-Atlantic law firm, an attacker spent 11 days inside a managing partner's email inbox, learning the details of an active real estate closing, before sending a fraudulent escrow disbursement instruction to the bookkeeper. The firm lost $2.3 million in a single transfer.
Executive impersonation. Attackers spoof or compromise an executive's email address and send urgent instructions directly to someone with payment authority. The message typically creates pressure: a deal depends on it, a deadline is imminent, a client relationship is at risk. The urgency is designed to short-circuit normal verification habits.
Vendor email compromise. This variant grew 67% in 2025 and is now the most financially damaging form of BEC. An attacker compromises a supplier's real email account, or registers a nearly identical domain, and inserts themselves into existing billing threads. They update payment instructions to redirect funds to an account they control. Because the thread is legitimate and the relationship is established, the fraud often goes undetected until the real vendor follows up on a missing payment.
For a closer look at how BEC differs from standard phishing attacks and why that distinction matters for your defenses, see Business Email Compromise vs. Phishing: What Leaders Need to Know Right Now.
Business Impact
The average BEC attack involving a wire transfer cost victims $293,000 in 2025. That figure makes it one of the most expensive single incidents a business can experience, and it does not account for the follow-on costs: forensic investigation, legal review, customer notification, regulatory inquiries, and the internal time spent untangling what happened and closing the gap that allowed it.
Wire fraud is the most visible outcome, but BEC causes other types of damage that are harder to quantify. Payroll diversion attacks redirect employee direct deposits to attacker-controlled accounts. W-2 fraud extracts sensitive employee tax data that can be used for identity theft. Vendor payment fraud strains business relationships when legitimate invoices go unpaid. And when an executive's email account is compromised, everything in that inbox, years of business correspondence, contracts, client information, and strategic planning documents, is potentially exposed.
Recovery is rarely simple. The FBI's Internet Crime Complaint Center Financial Fraud Kill Chain program can sometimes intercept wire transfers if reported within 72 hours, but most victims do not realize the fraud has occurred within that window. Once funds are moved internationally, recovery rates drop sharply.
What Companies Can Do
BEC is a human-layer threat, so the response has to include a human-layer component. Technical controls alone are not enough, but they set the foundation.
Start with email authentication. DMARC, DKIM, and SPF records help prevent spoofing of your domain by outside parties. These are not optional. If your domain lacks proper email authentication records, attackers can send email that appears to come from your own addresses. Many organizations have never verified that these records are correctly configured and enforced.
Next, apply multi-factor authentication to every business email account without exception. An attacker who obtains a credential through phishing or a data breach cannot access the account without also defeating the second factor. This is the single highest-impact technical control for reducing account takeover risk. If you have questions about whether MFA is actually protecting your accounts or creating new exposures, see When MFA Becomes the Vulnerability.
Establish payment verification procedures that cannot be bypassed by email instruction alone. Any request to change payment account information, initiate an out-of-cycle wire, or redirect payroll should require a secondary verification step, a phone call to a known number, or an in-person confirmation. This sounds simple, but organizations that have not formally established this requirement often have no consistent practice in place.
Train your team on BEC specifically, not just phishing generally. Employees who can recognize a phishing link may still fall for a well-researched executive impersonation. Training should include examples of what BEC messages look like, what pressure tactics attackers use, and a clear process for escalating suspicious payment requests.
How a Managed IT Provider Helps
Most businesses do not have the internal security resources to monitor for the early indicators of an email account compromise, configure email authentication protocols correctly, or run ongoing security awareness training with updated content. A managed IT provider fills those gaps systematically.
On the technical side, a managed provider can audit your existing email authentication configuration, deploy advanced email filtering that catches lookalike domains and suspicious sender behavior, and implement security monitoring that flags unusual inbox rule changes or login activity from unexpected locations. Those inbox rule changes, where attackers set email to auto-delete or redirect specific message types, are one of the most consistent early signs of an account takeover, and they go undetected without active monitoring.
On the human side, a managed IT partner can deliver role-specific security awareness training that addresses BEC directly, test employee responses through simulated attack scenarios, and help your leadership team establish the verification procedures that make it harder for attackers to succeed even if they get a foothold in your email environment.
When a BEC incident does occur, a managed provider with incident response capabilities can move quickly to contain the breach, preserve forensic evidence, and support the FBI reporting process that gives the best chance of fund recovery.
Best Practices
Configure and enforce DMARC on your domain. Set the policy to reject or quarantine rather than monitor only. Leaving it in monitor mode provides reporting but no actual protection against spoofing.
Require MFA on all email accounts. This is the most direct control against account takeover, which underlies most of the most damaging BEC variants.
Create a written payment verification policy. Document what triggers a secondary verification requirement and what the verification process is. Make sure every employee who handles payments or payroll knows it.
Implement a process for verifying changes to vendor payment details. Any request to update account numbers, routing numbers, or payment methods should require a callback to a verified contact number, not a number provided in the requesting email.
Monitor for suspicious inbox rules. Attackers commonly set rules to hide their activity. Automated monitoring that alerts on new inbox rules created by someone other than the account holder can surface account takeovers early.
Report immediately. If you suspect a BEC-related wire transfer, report to the FBI's IC3 and your financial institution within hours. The sooner the Financial Fraud Kill Chain is activated, the better the odds of recovering funds.
FAQ
What is the difference between BEC and regular phishing?
Phishing typically targets a broad audience with a generic message designed to capture credentials or deliver malware. Business Email Compromise is targeted, researched, and focused on initiating fraudulent financial transactions rather than on deploying malicious software. BEC attackers often spend days or weeks studying a target organization before sending a single message, which is why the fraud can be so convincing. The two threats share some underlying methods, but BEC is more sophisticated, more targeted, and typically results in higher individual losses.
Can BEC happen even if we have strong spam filters?
Yes. Spam filters are designed to catch mass-distribution junk email, malware attachments, and known malicious links. BEC attacks often contain none of those elements. A message sent from a legitimately compromised account, or from a carefully spoofed address that passes authentication checks, may arrive cleanly in an inbox. BEC succeeds at the human layer, which spam filters do not evaluate.
How do attackers know enough about our business to sound credible?
Attackers research targets using publicly available information, including company websites, LinkedIn profiles, press releases, and regulatory filings. They also use data from prior breaches to obtain credentials and gain access to email accounts directly. Once inside, they can read months or years of business correspondence, learning financial processes, vendor relationships, contract terms, and communication styles. The resulting fraud attempts reflect that specific knowledge, which is why they bypass scrutiny that would catch a generic scam.
What should we do immediately if we think a BEC attack has succeeded?
Contact your bank immediately and request a wire recall or a SWIFT gpi Tracker trace if the transfer has already been sent. Then report the incident to the FBI's Internet Crime Complaint Center at ic3.gov. The FBI's Financial Fraud Kill Chain program works with financial institutions to intercept transfers, but speed is critical. After containing the immediate financial exposure, preserve all relevant email communications and access logs, change compromised credentials, and engage your IT team or managed provider to assess the full scope of the breach. Document everything throughout the process for potential law enforcement and insurance purposes.
For more on how managed IT helps prevent breaches, read what Core Managed CEO Jon Wright shared in the Triangle Business Journal here.
Business email compromise is one of the most preventable and most costly threats your organization faces. Core Managed works with businesses across Indianapolis, Raleigh, and Atlanta to build the technical controls and team training that stop these attacks before they cost you. If you want to review your current email security posture, give us a call at 888-890-2673 or contact us here to schedule a conversation.