Business email compromise (BEC)
Fraud where the attacker poses as an executive or vendor from a legitimate or spoofed mailbox to divert payments or data. It usually carries no malware.
Full definition
Business email compromise (BEC) is a fraud where the attacker poses as an executive, an employee or a vendor so that someone with payment authority transfers money or shares sensitive information. Unlike classic phishing, it often includes no malicious links or attachments: it is plain text, which is why technical filters struggle to catch it.
There are two main variants: impersonation, where the attacker writes from a lookalike domain or forges the sender, and real compromise, where the attacker writes from the legitimate mailbox of an already stolen account, often after weeks of reading conversations to pick the exact moment to request a change of bank account.
Effective defense is about process and behavior: out-of-band verification for any change in payment details, dual approval for transfers, and targeted training for finance, procurement and executive assistants, the roles that receive these emails.
Related terms
Whaling
Spear phishing aimed at executives with signing power or privileged access. It goes after payments, strategic information or the executive's own mailbox.
Spear phishing
Phishing aimed at a specific person, built with real data about their role, company and tools. Far more effective than mass campaigns.
Spoofing
Forging a sender's identity: email, domain, phone number or website. It is the technical layer that makes impersonation believable.
Account takeover (ATO)
Taking control of a legitimate account with stolen credentials. From inside, the attacker reads, impersonates and escalates without raising alarms.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.