Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeGlossaryBusiness Email Compromise (BEC)
Glossary

Business Email Compromise (BEC)

Business email compromise (BEC) is a fraud in which an attacker uses a hijacked or spoofed business email account to trick staff into sending money or data.

Definition

What is Business Email Compromise?

Business email compromise (BEC) is a fraud in which an attacker uses a legitimate but hijacked business email account, or a convincing imitation of one, to persuade an employee or a business partner to send money, change payment details or hand over sensitive information. There is usually no malware involved. The attack relies on trust in a familiar name and on the normal rhythm of business correspondence, which is why it slips past filters built to catch malicious attachments.

A typical case begins with a phished password. The attacker signs in to a real mailbox, often in accounting or at a vendor, and reads quietly for weeks to learn who approves payments and how they write. They create inbox rules that hide their activity, then at the right moment send an email from the real account asking for a wire to a new bank account, or intercept a genuine invoice and swap the payment details. Variants include CEO fraud, where an executive's address is spoofed to demand an urgent transfer, payroll diversion, where HR is asked to change a direct deposit, gift card requests sent to a new assistant, and attorney impersonation around a confidential deal. The money moves through mule accounts and is usually gone within days.

For a small business the exposure is direct financial loss that insurance may only partly cover, plus liability when a client is defrauded through the company's compromised mailbox. Defenses are procedural as much as technical: MFA on every mailbox, Conditional Access to block foreign sign-ins, alerts on new forwarding rules, email authentication (SPF, DKIM and DMARC) so the domain cannot be spoofed, and a rule that any change to payment details is verified by phone at a known number.

NetSys addresses BEC on both sides. Its Microsoft 365 security service enforces MFA and Conditional Access, monitors for suspicious inbox rules and sign-ins, and configures DMARC; its security awareness training teaches staff to recognize payment-change requests and to verify them out of band. Both are part of a managed agreement.

Why it matters for a small business

BEC is the fraud most likely to cost a small business real money, because it targets the payment process rather than the computer, and a wire is often unrecoverable once it clears. A single compromised mailbox in accounting can cost a company a vendor payment and a client relationship. The defenses are inexpensive compared with one lost wire: MFA, sign-in restrictions, alerts on forwarding rules, and a standing policy that nobody changes bank details without a phone call to a number already on file.

Common Questions

Business Email Compromise (BEC): FAQs

How do I know if my business email has been compromised?

Warning signs include inbox rules you did not create, especially ones that forward mail outside the company or move messages to obscure folders; vendors or clients replying to emails you never sent; sign-in alerts from unfamiliar locations; and password reset messages you did not request. In Microsoft 365 an administrator can check the unified audit log for sign-ins and rule changes. If you suspect a compromise, reset the password, revoke active sessions, remove unknown rules and check whether MFA methods were added by someone else. Then review what the attacker read.

What is the difference between phishing and business email compromise?

Phishing is the technique: a deceptive message that tricks someone into giving up a password or clicking a link. Business email compromise is a fraud that often starts with phishing but continues after the attacker has a real account. In BEC the attacker sends messages from a genuine mailbox or a near-identical domain, with no malicious link at all, and asks for a payment or a change in bank details. Filters that look for bad attachments miss it, which is why procedural controls and MFA matter more.

Does cyber insurance cover business email compromise?

Some policies do, under a social engineering or funds transfer fraud endorsement, but the sub-limit is often much lower than the main policy limit, and carriers investigate whether required controls such as MFA and payment verification procedures were in place. Read the policy for the specific wording. Coverage also rarely restores a client's money when a fraud is run through your compromised mailbox, which can leave the business liable. The controls that reduce the risk are the same ones underwriters ask about.

Reading this because of a questionnaire or a renewal?

Get the controls, not just the definition.

A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.