I’m sure most people reading this blog have received an email from a Nigerian Prince or Banker asking for help moving several million dollars, but today’s cybercriminals are far more advanced. Business email compromise (BEC) is a cyberattack in which criminals use email to impersonate a trusted person or take control of a legitimate account. The objective may be to redirect a payment, steal sensitive information, obtain login credentials or persuade somebody within a business to take an action they would not normally take.
What makes BEC particularly challenging is that the suspicious email may not always come from an obviously fake address. If an attacker gains access to a genuine mailbox, messages appear to come from somebody the recipient already knows and trusts. Also, if they have access to the mailbox, they can review previous email exchanges and mimic the language used.
Understanding that distinction can help businesses look beyond obvious spam and phishing emails and consider how people, processes and technology work together to reduce the risk.
Business email compromise is a targeted type of phishing that uses business relationships and trusted identities to make fraudulent requests appear legitimate.
For example, an attacker might impersonate a Managing Director and ask Finance to make an urgent payment. In another scenario, an attacker could compromise a supplier’s genuine email account and use it to send altered payment instructions to its customers.
BEC attacks can be effective because they often exploit normal business behaviour.
Employees routinely receive requests from directors, colleagues, suppliers and customers. Invoices are paid, bank details change, documents are shared and people are sometimes asked to act quickly.
An attacker may attempt to make a fraudulent request look like another ordinary business interaction.
There is no single method used in every BEC attack.
Two important approaches are email impersonation and email account compromise.
With impersonation, an attacker attempts to make an email look as though it has come from somebody tries to make an email look like it came from someone the recipient trusts. This might involve a similar-looking domain, a misleading display name or another form of email spoofing.
Account compromise can be more difficult for a recipient to identify.
If an attacker obtains access to a genuine business mailbox, they may be able to send messages from the real account. Depending on the circumstances and access obtained, they may also review previous correspondence and use that information to make subsequent messages more convincing.
This is why recognising BEC cannot depend solely on checking whether a sender’s name looks familiar.
Although the techniques vary, several scenarios are particularly relevant to businesses.
An attacker may impersonate a senior member of the organisation and contact an employee who has authority to make payments, purchase with authority to make payments, purchase goods, or disclose information.
The request might appear urgent or confidential:
Urgency can discourage the recipient from verifying the request through another channel.
Businesses can reduce this risk by having clear verification procedures for unusual or sensitive requests, particularly those involving money, credentials or confidential information.
An organisation may receive what appears to be a genuine message from a supplier stating that its bank details have changed.
Sometimes the sender may be impersonating the supplier. In other cases, a genuine supplier account may have been compromised.
This makes verification especially important.
A request to change payment details should not be trusted automatically simply because it appears in a familiar email conversation.
Businesses should consider confirming significant financial changes through a known, separate communication method using contact information they already trust.
A compromised employee mailbox can create risks beyond the individual account.
Depending on the access available, an attacker may be able to view correspondence, identify business relationships or send messages that appear to come from the employee.
This could potentially expose colleagues, customers or suppliers to further fraudulent approaches.
Strong account security therefore forms an important part of wider business cyber security rather than being treated purely as an email problem.
Phishing remains a common way attackers try to obtain account credentials.
A message might direct an employee to a convincing-looking login page or encourage them to open a malicious attachment.
QR-code phishing — sometimes referred to as quishing — provides another variation. Instead of asking somebody to click a conventional link, an email may encourage the recipient to scan a QR code with a mobile device.
The technique may change, but the underlying principle is similar: persuade somebody to trust a request and take an action that benefits the attacker.
Traditional phishing emails can sometimes contain obvious warning signs such as poor spelling, unexpected attachments or unusual sender addresses.
BEC can be more subtle.
An attacker may research an organisation before making contact. Publicly available information can help identify employees, senior management, suppliers or business activities.
A compromised mailbox can potentially provide even richer context.
This means a malicious request could:
The question therefore shouldn’t simply be:
“Do we recognise the sender?”
Businesses should also consider:
“Does this request make sense, and have we independently verified anything unusual or sensitive?”
The consequences depend on the account, its permissions, and the nature of the compromise.
Potential activity can include:
This is one reason security visibility matters.
Preventing every malicious action is an important objective, but businesses should also consider whether they would identify unusual activity if preventative controls were bypassed.
Understanding how to improve cyber security visibility can help organisations think about what they can actually see across their environment and where potential blind spots may exist.
No single warning sign proves that an email account has been compromised.
However, employees should be encouraged to question unexpected or unusual behaviour, particularly when several warning signs appear together.
These may include:
A request can also be suspicious even when the email address itself appears legitimate.
When something doesn’t feel right, employees should have a clear way to report it.
Business email compromise is not solely a technology problem.
A stronger approach combines technical protection with account security, employee awareness and appropriate business processes.
Multi-factor authentication adds an extra layer of protection to business accounts, while appropriate email-security controls can help identify and block some malicious messages.
Access should also reflect what each employee genuinely requires.
Former employees should not retain active accounts, unused accounts should be reviewed, and privileged access should be restricted appropriately.
Our cybersecurity checklist for small businesses covers wider practical controls businesses can review across users, systems, cloud services and security processes.
Employees should know what to do when they receive an unusual financial or sensitive request.
For example, organisations can establish procedures for independently verifying:
Verification should use a trusted method rather than simply replying to the potentially compromised email.
Employees do not need to become cybersecurity specialists.
They do need to understand the types of requests that should make them stop and check.
Training can help staff recognise suspicious behaviour, while clear internal reporting procedures make it easier to raise a concern without delaying unnecessarily.
Accounts and permissions should change as employees join the organisation, move between roles or leave.
Regular access reviews can help identify inactive accounts, unnecessary privileges and administrative access that is no longer required.
Even well-designed preventative controls may not stop every incident.
Businesses should therefore consider how they detect, investigate, and escalate suspicious activity.
The aim is not simply to ask:
“Can we stop this?”
It is also:
“If something unusual happens, would we know?”
If an employee suspects an email account has been compromised, they should report the concern quickly through the organisation’s established IT or security process.
The appropriate response depends on what happened, but may involve securing affected accounts, reviewing suspicious activity, and determining whether other people or organisations have been contacted.
If a fraudulent payment may have been made, contact the relevant bank or financial provider promptly using trusted official contact details.
Businesses should also preserve relevant information and follow their established incident-response procedures.
Where appropriate, incidents may need to be reported to relevant authorities or other affected parties.
The important point is to avoid continuing to trust the potentially compromised communication channel while the situation is being investigated.
Business email compromise demonstrates why cyber security cannot rely on a single control.
Email protection, account security, multi-factor authentication, employee awareness, appropriate access, payment-verification processes, monitoring, and incident response can all help reduce risk.
The right combination depends on the organisation, its systems, and how its employees work.
Qual Limited can help businesses review their existing cyber security arrangements, identify potential gaps and determine where additional controls or protection may be appropriate.
Talk to Qual about reviewing your email and cyber security arrangements.
We’ll be in touch within the next 24 hours (Mon-Fri)
Request a quick call back for a no-obligation chat. With over 30 years of practical experience, our UK-based experts are ready to help. Guaranteed no pushy sales, just a friendly call to understand your challenges and explore some potential solutions.
Are you looking to connect with a dedicated account manager who can tailor IT solutions to meet your business needs?
Are you looking to connect with a dedicated account manager who can tailor IT solutions to meet your business needs?