Knowledge Base
Engineer Login
Back to Knowledge Base

Responding to a Business Email Compromise (BEC) Attack

Security & antivirus BEC email compromise fraud incident response By Kerry · Updated 03/05/26 07:53 AM
Business Email Compromise (BEC) attacks impersonate executives or vendors via email to trick employees into transferring money or changing payment details. BEC causes billions in losses annually and targets finance staff specifically. Prompt response is critical. If you discover a BEC attack in progress (e.g., a fraudulent wire transfer was requested): immediately contact your bank — transfers can sometimes be recalled if reported within hours. Preserve all emails without deleting them. Identify how the attacker gained access (compromised mailbox, display name spoofing, domain lookalike) by reviewing sign-in logs. Prevention: implement DMARC/DKIM/SPF to block domain spoofing. Set up a mail flow rule to tag emails from external senders with a visual banner ('External Email: Verify before acting'). Train finance staff to always verify payment changes via a phone call to a known number — never by replying to the email requesting the change. Require dual approval for wire transfers above a threshold. Enable sign-in alerts for executive mailboxes.