Business Email Compromise
A targeted financial fraud where an attacker poses as a trusted executive, supplier, or colleague over email to trick an employee into transferring money or sensitive data.
Definition
Business Email Compromise (BEC) is a form of targeted email fraud in which an attacker impersonates a trusted party, such as a senior executive, supplier, or internal colleague, to manipulate an employee into transferring funds, redirecting a payment, or releasing sensitive information. Unlike mass phishing, BEC is highly tailored, often free of malicious links or attachments, and relies almost entirely on social engineering and abuse of trust. This text-only nature is precisely why BEC frequently slips past traditional spam and malware filters.
BEC typically begins with reconnaissance. Attackers study a target organization using public sources, leaked credentials, or a previously compromised mailbox to learn who approves payments, how invoices are processed, and the tone executives use. They then send a message that looks routine: a CEO requesting an urgent wire transfer, a supplier sharing updated bank details, or a payroll change request. The message exploits authority, urgency, and trust rather than any technical flaw, which is what makes it dangerous.
Common variants include CEO fraud (impersonating a senior leader to authorize a transfer), invoice or vendor fraud (intercepting or faking supplier payment instructions), payroll diversion (redirecting an employee's salary), and account compromise (sending fraudulent requests from a genuine, hijacked mailbox). Attackers often spoof a display name, register a look-alike domain, or reply within a real email thread to appear legitimate. In Indonesia and across Southeast Asia, finance and procurement teams at banks and regulated enterprises are frequent targets given the high transaction values involved.
BEC matters because the losses are large and the attack leaves little technical evidence. There is usually no malware to detect and no obvious link to flag, so prevention depends on people and process. Effective defenses combine human awareness with controls such as out-of-band verification of payment changes, dual approval for transfers, supplier bank-detail confirmation by phone, and email authentication standards like DMARC, SPF, and DKIM to reduce spoofing. Because the human is the last line of defense, sustained awareness and behavior change are essential.
At a glance
- Severity
- Critical
- Prevalence
- Common and high-value
- Primary targets
- Finance, procurement, and payroll teams
- Also known as
- BEC, CEO fraud
How it works
- 1
Reconnaissance: the attacker studies the target organization using public sources, leaked credentials, or a compromised mailbox to learn who approves payments.
- 2
Impersonation: they pose as a trusted party, such as a CEO, supplier, or internal colleague, often spoofing a display name or registering a look-alike domain.
- 3
Routine-looking request: the message asks for something that looks ordinary, like an urgent wire transfer or updated bank details.
- 4
Exploiting trust: the request relies on authority, urgency, and trust rather than any malicious link or attachment, so it often bypasses spam and malware filters.
- 5
Fraudulent payment: the employee, believing the request is legitimate, transfers funds or updates payment details, sending money directly to the attacker.
Warning signs
- Urgent request to change bank details or process an unscheduled payment
- Message tone slightly different from how the sender usually writes
- Look-alike domain or subtly altered display name
- Request to bypass normal approval steps or keep the matter confidential
- Reply appearing within a real email thread but requesting something unusual
How to defend
- Verify any payment or bank detail change through a separate, known channel, ideally by phone
- Require dual approval for wire transfers above a set threshold
- Confirm supplier bank details by calling a known number, not one in the email
- Deploy DMARC, SPF, and DKIM to reduce email spoofing
- Train finance and procurement teams to recognize and question urgent payment requests
Real-world example
An employee in the finance team at an Indonesian trading company receives an email that appears to come from a long-standing supplier, requesting that future payments go to a newly updated bank account. The message looks routine and references a real outstanding invoice, but a phone call to the supplier's known contact reveals the account details were never changed, exposing the fraud before the payment is sent.
How Claro helps
Claro helps organizations measure and reduce BEC exposure by simulating realistic executive-impersonation and supplier-fraud scenarios against finance, procurement, and leadership teams, then turning the results into a per-user and per-department human risk score. When someone acts on a simulated BEC lure, Claro delivers just-in-time training on verification habits such as confirming payment changes through a second channel. Over time, leaders see whether real behavior is improving, with bilingual reporting aligned to OJK, PDP Law, and ISO 27001 expectations rather than just training completion counts.
Frequently asked questions
What makes BEC different from typical phishing?
BEC is highly tailored to a specific organization and rarely contains malicious links or attachments, relying almost entirely on impersonation and social engineering. This text-only nature is exactly why it often slips past traditional spam and malware filters.
What are the common types of BEC?
The main variants are CEO fraud, where a leader is impersonated to authorize a transfer; invoice or vendor fraud, where supplier payment instructions are faked; payroll diversion, where an employee's salary is redirected; and account compromise, where fraudulent requests are sent from a genuine, hijacked mailbox.
Can email filters detect BEC?
Rarely, on their own. Because BEC messages typically contain no malware or malicious link, they often pass technical filters. Detecting BEC depends more on process controls like out-of-band verification and dual approval than on technology alone.
How can a company recover from a BEC payment fraud?
Report the fraud to the bank and relevant authorities immediately, since fast action sometimes allows a wire transfer to be recalled before funds are withdrawn. Organizations should also review how the fraud succeeded and tighten verification processes for future payment changes.
Related terms
Spear Phishing
A targeted phishing attack that uses personalized details about a specific individual or organization to make a fraudulent message far more convincing.
Whaling
A highly targeted phishing attack aimed at senior executives and other high-value individuals to steal money, credentials, or sensitive data.
Social Engineering
The manipulation of people into revealing sensitive information or taking unsafe actions by exploiting trust, emotion, and human psychology rather than technical flaws.
Phishing Simulation
A controlled, authorized exercise that sends realistic but harmless fake phishing messages to employees to measure how they respond and to train safer behavior.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo