S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T14.10
CATEGORY Social Engineering
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Business Email Compromise

Digital Lure · CEO / Vendor-Email Fraud · Very High
High Alert
How It WorksSEC 01

Business Email Compromise is a targeted fraud in which an attacker impersonates a trusted party — a senior executive, a known vendor, an attorney, or a colleague — over email to induce an employee to move money or sensitive data to attacker-controlled destinations. It is the highest-value social-engineering fraud in the modern economy not because it is technically clever but because it weaponizes legitimate business processes. The attacker does not break systems; the attacker breaks judgment.

Two structural forms recur. In impersonation BEC, the message comes from a spoofed or look-alike domain (@company-invoices.com vs. the real @company.com) posing as the CEO, CFO, a supplier, or a lawyer, asking a subordinate to authorize an urgent transfer or update banking details. In account-takeover BEC, the attacker has genuinely compromised a real mailbox and sends the fraudulent request from the authentic account, often after weeks of silent inbox reconnaissance to learn payment cadence and tone, then striking when a real payment is due.

The signature move is the last-minute banking-detail change: an expected payment is redirected by a message claiming “we’ve switched banks — please update our details.” Because the underlying transaction is real, the fraud rides on top of genuine business. There is no malware to detect, the request is plausible, the sender looks right, and the pressure to “just get it done” is manufactured to override the one control that stops it — an independent, out-of-band verification.

Warning SignsSEC 02
  • Manufactured urgency. "Today," "before I land," "the deal is at risk" — pressure to act before verifying.
  • A last-minute banking change. Any "we switched banks — update our details," especially on an expected payment.
  • Secrecy framing. "Keep this between us," "don't loop in the team" — severing you from the colleagues who would sanity-check it.
  • A look-alike or subtly wrong sender domain , or a reply-to that differs from the display name.
  • Deviation from the normal process — a skipped approver, a new payee, an unusual amount or country.
  • Pressure not to call , or a supplied "new" number for verification.
Frequently Paired WithSEC 03
  • Fake Invoices · T14.12
    The document-centric sibling BEC delivers
  • Phishing · T14.3
    Credential-theft precursor to account takeover
  • Vishing · T14.4
    Voice channel in callback-defeating variants
  • Trust Exploitation · T14.21
    BEC is a trust-transfer attack
How the Attack UnfoldsSEC 04
  • Stage 01 · Setup
    The attacker spoofs a look-alike domain or hijacks a real mailbox, then studies payment cadence, tone, and pending invoices.
  • Stage 02 · The Ask
    An urgent, authority-backed, secrecy-shrouded request to move money or change bank details arrives, timed to a real transaction.
  • Stage 03 · Diversion
    Funds wire to a mule account before anyone performs the out-of-band check that would expose the fraud.
Counter-ProtocolSEC 05
Defense: Verify every payment or bank-detail change out-of-band; slowing down is the job.
  • Callback on a known number. Confirm any transfer or bank-detail change by calling the requester or vendor back on a previously established number — never one from the message.
  • Require dual authorization. A second approver for wires above a threshold.
  • Freeze vendor-change requests. Bank-detail changes need documented, independent confirmation and a cooling-off delay.
  • Reject urgency plus secrecy. No genuine executive demands an urgent secret wire by email.
  • Report fast. Suspected fraud to the bank and IC3 within hours — funds reported within ~24–72 hours are far likelier to be clawed back.