Business Email Compromise is a targeted fraud in which an attacker impersonates a trusted party — a senior executive, a known vendor, an attorney, or a colleague — over email to induce an employee to move money or sensitive data to attacker-controlled destinations. It is the highest-value social-engineering fraud in the modern economy not because it is technically clever but because it weaponizes legitimate business processes. The attacker does not break systems; the attacker breaks judgment.
Two structural forms recur. In impersonation BEC, the message comes from a spoofed or look-alike domain (@company-invoices.com vs. the real @company.com) posing as the CEO, CFO, a supplier, or a lawyer, asking a subordinate to authorize an urgent transfer or update banking details. In account-takeover BEC, the attacker has genuinely compromised a real mailbox and sends the fraudulent request from the authentic account, often after weeks of silent inbox reconnaissance to learn payment cadence and tone, then striking when a real payment is due.
The signature move is the last-minute banking-detail change: an expected payment is redirected by a message claiming “we’ve switched banks — please update our details.” Because the underlying transaction is real, the fraud rides on top of genuine business. There is no malware to detect, the request is plausible, the sender looks right, and the pressure to “just get it done” is manufactured to override the one control that stops it — an independent, out-of-band verification.