Avatier

Social engineering of a person

Business email compromise

Also called: BEC

Business email compromise is a fraud in which an attacker uses a hacked or impersonated business email account to trick staff into sending money or sensitive data. Typical requests are urgent wire transfers, changed bank details or employee tax records, made to look like they come from an executive, colleague or supplier.

How it works

The attacker gains access to a real mailbox, often by phishing, or registers a lookalike address. They read past threads to learn who approves payments and how invoices are worded, then send a request that matches. Mail rules may hide replies from the real account owner so the fraud goes unnoticed for longer.

A real example

In September 2024 the FBI's IC3 reported $55,499,915,582 in domestic and international exposed dollar losses from business email compromise between October 2013 and December 2023.

Source: Business Email Compromise: The $55 Billion Scam (I-091124-PSA) — FBI Internet Crime Complaint Center (IC3), 2024-09-11

The Identity Attack Ledger holds 12 cited incidents for social engineering of a person in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Protect mailboxes with phishing-resistant MFA, alert on new forwarding and inbox rules, and confirm any payment change through a known phone number before money moves.

Related terms

Sources

  1. Business Email Compromise: The $55 Billion Scam (I-091124-PSA) — FBI Internet Crime Complaint Center (IC3), 2024-09-11

Last reviewed Oct 2, 2026