logo

Business Email Compromise (BEC)

Category:

Social Engineering

Summary:

How BEC uses impersonation or a hijacked mailbox to redirect payments and data, why it costs so much, and how to prevent it.

Business Email Compromise (BEC) impersonates — or outright takes over — a trusted mailbox (a CEO, a supplier, finance) to trick staff into wiring money or leaking sensitive data. It’s low-tech compared to most attack classes on this site, but it’s also one of the costliest: no malware, no exploit, just a convincing message hitting someone with the authority to act on it. BEC is built on pretexting, delivered through phishing or credential theft such as credential stuffing.

Common Techniques

  • CEO / wire fraud — a spoofed or compromised executive account requests an urgent, confidential payment.
  • Vendor / invoice redirect — a familiar supplier’s invoice arrives with new “updated” bank details.
  • Lookalike domains — a near-identical domain (swapped characters, extra hyphen) passes a quick visual check.
  • Thread hijacking — an attacker replies inside a real, compromised email thread, inheriting its trust and context.
  • Gift-card and payroll-diversion scams — smaller, faster asks (gift cards, direct-deposit changes) that draw less scrutiny than a wire.

Want to save time on reporting?

Let PentestPad generate, track, and export your reports - automatically.

logo-cta

Testing

An authorized simulation sends a spoofed-executive or lookalike-domain request through a payment-style workflow — an invoice change, a wire approval — and measures who verifies before acting and who doesn’t. Track outcomes by team and role, since finance and payroll typically carry the most exposure. Document every request, response, and verification gap in the pentest report so remediation can target the weakest step in the approval chain.

Remediation

Require out-of-band payment verification — dual approval plus a callback to a known-good number — for any payment or banking-detail change. Deploy SPF, DKIM, and DMARC, and banner external mail so a spoofed “internal” sender stands out immediately. Monitor for lookalike domains registered against your brand, and enforce phishing-resistant MFA on mailboxes so a stolen password alone can’t deliver a takeover.