CIOPages
Back to Glossary

Cybersecurity & Identity

Business Email Compromise (BEC)

Business Email Compromise is a class of attack in which criminals use fraudulent or compromised email to deceive employees into transferring funds or sensitive data. Rather than deploying malware, BEC relies on social engineering — impersonating executives, suppliers, or trusted partners to authorize fraudulent payments. It exploits human trust and business process rather than technical vulnerabilities.

Context for Technology Leaders

BEC matters because it consistently ranks among the costliest categories of cybercrime by financial loss, often exceeding the damage from ransomware. A technology leader must recognize that BEC bypasses most technical defenses because it targets people and processes, not systems. Generative AI has sharpened the threat by making fraudulent messages more convincing and enabling voice and video impersonation that defeats older detection heuristics.

Key Principles

  • 1BEC targets people and process, so technical controls alone cannot stop it — verification procedures are the real defense.
  • 2Payment and change requests need out-of-band verification, because trusting the email channel is precisely the vulnerability.
  • 3AI has made impersonation more convincing, eroding the spelling and tone cues that once helped users spot fraud.

Strategic Implications for CIOs

For CISOs and CIOs, defending against BEC means investing in process controls — payment verification, dual authorization, supplier bank-change procedures — as much as in email security technology. Because AI-generated impersonation is defeating traditional awareness cues, defenses must shift from spotting suspicious writing to enforcing verification regardless of how convincing a request appears. The financial magnitude of BEC justifies treating it as a business-process risk, not just an email-security problem.

Common Misconception

That email security filters are enough to stop BEC. Many BEC messages contain no malware or malicious links and pass technical filters cleanly — the only reliable defense is out-of-band verification of financial and data requests.

Related Terms