Business Email Compromise (BEC) — What It Is and How to Protect Against It
Security / Antivirus
BEC
email fraud
wire transfer
CEO fraud
social engineering
By Kerry · Updated 03/04/26 10:48 PM
Business Email Compromise (BEC) is one of the costliest cyber crimes targeting small businesses. Understanding it is your first line of defense.
What is BEC?
BEC is a scam where an attacker impersonates a trusted person — your boss, a vendor, or a client — via email to trick you into transferring money, sending sensitive data, or changing payment details.
Common BEC scenarios:
1. CEO Fraud: You receive an email that appears to be from your owner or manager asking you to urgently wire money or buy gift cards. The email looks real but is spoofed or sent from a lookalike address (e.g.
[email protected] instead of battlecreekit.com).
2. Vendor Impersonation: A supplier sends an email saying their bank account has changed — please send future payments to the new account. The email may come from a hacked or spoofed vendor email.
3. Payroll Redirect: HR or payroll receives an email from an "employee" asking to change their direct deposit account before payday.
4. Invoice Fraud: A fake invoice arrives from what looks like a legitimate vendor, with payment details controlled by the attacker.
Red flags to watch for:
- Urgency or pressure ("do this today," "don't tell anyone yet")
- Request to bypass normal approval processes
- Payment to a new or changed bank account
- Slightly wrong email address (very close to a real one)
- Grammar or tone that seems off for the person it claims to be from
- Requests for gift cards as payment
How to protect your business:
1. Verify by phone — for any payment request or bank account change, call the requestor using a number you already have on file (not one provided in the email). This single step stops most BEC attacks.
2. Set up a two-person approval rule for wire transfers or payments over a threshold
3. Enable email authentication (SPF, DKIM, DMARC) — contact us to check your email domain setup
4. Enable MFA on all Microsoft 365 accounts — even if credentials are stolen, attackers can't send email from your account
5. Train all staff — anyone who handles payments or data should know what BEC looks like
If you receive a suspicious request: do not act on it until you've verified verbally. Then forward it to us so we can investigate.
If you've already sent a payment: contact your bank immediately — some wire transfers can be recalled within hours.