Business Email Compromise: How Scammers Target Your Workplace Emails

Business Email Compromise: How Scammers Target Your Workplace Emails
Business email compromise cost organizations $2.4 billion in 2021, according to FBI reporting. Despite this staggering figure, many employees remain unaware of how these attacks work or how to spot them before financial damage occurs. Unlike traditional phishing that relies on malicious links or attachments, BEC attacks exploit trust and authority through carefully crafted social engineering.
Understanding how scammers research targets, spoof legitimate communications, and manipulate payment processes provides the foundation for protection. This knowledge matters for everyone who handles email at work—from recent graduates in their first office roles to small business owners managing vendor relationships. The attacks continue to evolve, with 2024 data showing a 33% increase in effectiveness, driven by AI-enhanced tactics and increasingly sophisticated impersonation techniques.
Understanding Business Email Compromise
Business email compromise represents a category of fraud where attackers impersonate trusted entities to manipulate employees into unauthorized actions. These typically involve wire transfers, payroll diversions, gift card purchases, or sensitive data disclosure. The defining characteristic: no malware required. Scammers succeed through psychological manipulation rather than technical exploits.
The scale of BEC attacks extends beyond headline-grabbing cases. Google and Facebook collectively lost $121 million to a Lithuanian scammer who impersonated a legitimate vendor between 2013 and 2015, intercepting and redirecting invoice payments. Small businesses face similar risks without the security infrastructure of large enterprises, making them proportionally more vulnerable.
Three distinct characteristics separate BEC from standard phishing. First, attackers conduct extensive reconnaissance before initiating contact. Second, they often compromise legitimate email accounts rather than simply spoofing addresses. Third, the requests appear contextually appropriate—a payment during a known vendor relationship or an urgent request during typical business hours.
How Scammers Research Their Targets
The reconnaissance phase determines attack success. Scammers mine publicly available information to build profiles of organizations, employees, and communication patterns. This research creates the foundation for convincing impersonation.
LinkedIn provides a primary intelligence source. Company pages reveal organizational structure, reporting relationships, and employee titles. Individual profiles often display work anniversaries, project involvement, and professional connections. A scammer researching a medium-sized company can map who reports to whom, identify financial decision-makers, and determine which employees handle vendor payments—all without accessing internal systems.
Corporate websites supplement social media research. Press releases announce mergers, executive changes, and major contracts. Team pages provide names, titles, and sometimes direct contact information. Company blogs and news sections reveal operational details, upcoming events, and business priorities. Armed with this context, scammers craft emails that reference real projects, legitimate vendors, and actual corporate initiatives.
Public records add another layer. Business registries, property records, and legal filings provide additional validation details. Scammers use this information to enhance credibility, referencing real addresses, registration numbers, or legal entities when impersonating vendors or partners.
The Four Phases of BEC Attacks
CrowdStrike’s threat intelligence framework identifies four distinct phases in successful BEC campaigns. Understanding this progression helps recognize attacks at various stages.
Identity Research and Selection
Attackers identify high-value targets within organizations. Finance teams, accounts payable personnel, HR staff with payroll access, and executive assistants represent primary targets. The selection criteria include payment authority, access to sensitive data, and position within approval workflows. Scammers also evaluate communication patterns—identifying employees who regularly interact with vendors, handle urgent requests, or process payments without extensive verification.
Employee and Process Research
Once targets are identified, scammers study organizational processes. They monitor email patterns to understand approval workflows, payment timing, and communication norms. This phase often involves compromising a low-level account to observe internal communications without triggering alarms. Attackers note how payment changes are requested, what verification (if any) occurs, and which employees possess override authority for urgent situations.
Account Compromise or Spoofing
Scammers execute the technical component of their attack through two primary methods. Account compromise involves credential theft through phishing, password spraying, or adversary-in-the-middle attacks that intercept authentication. Once inside a legitimate account, attackers can send emails from trusted addresses, reply to existing threads, and access sensitive communications for further intelligence.
Domain spoofing offers an alternative approach requiring less technical sophistication. Scammers register domains nearly identical to legitimate ones—replacing characters, adding hyphens, or using different top-level domains. An email from ceo@companny.com instead of ceo@company.com easily escapes casual scrutiny, particularly on mobile devices where full addresses may not display.
Launch and Execution
The final phase leverages accumulated intelligence to create urgent, contextually appropriate requests. These typically exploit authority (executive impersonation), trust (vendor relationships), or fear (legal threats, compliance deadlines). The requests often include elements designed to bypass normal procedures: confidentiality demands, time pressure, executive authority, or references to legitimate projects.
Common BEC Attack Variants
Proofpoint’s threat research identifies several distinct BEC patterns, each targeting different vulnerabilities within organizations.
CEO Fraud and Executive Impersonation
The most recognized variant involves impersonating senior executives to authorize fraudulent payments or data transfers. An email appearing to come from the CEO requests an urgent wire transfer, often claiming to be in a meeting or traveling and unable to make calls. The message typically emphasizes confidentiality and time sensitivity to discourage verification attempts.
Invoice and Payment Diversion
Scammers intercept or spoof communications from legitimate vendors to redirect payments. An email appearing to come from a regular supplier announces updated banking details for future payments. Organizations process the change through normal procedures, subsequently paying invoices to attacker-controlled accounts. The fraud remains undetected until the legitimate vendor inquires about unpaid invoices.
Account Compromise and Thread Hijacking
This sophisticated variant involves compromising legitimate accounts and inserting into existing email threads. An attacker monitoring a conversation about payment or data exchange waits for an opportune moment, then responds from the compromised account with fraudulent instructions. Because the email comes from a real account within an established thread, recipients rarely question its legitimacy.
Attorney and Legal Impersonation
Attackers pose as external counsel or legal representatives to request sensitive information or urgent actions. These emails exploit the authority and confidentiality associated with legal matters, often targeting HR departments for employee data or finance teams for payment information related to claimed legal proceedings.
Data Theft for Future Attacks
Some BEC campaigns prioritize information over immediate financial gain. Attackers compromise accounts to harvest sensitive data—W-2 forms, vendor lists, contract details, or customer information. This data fuels subsequent attacks, enables identity theft, or gets sold to other criminals.
Red Flags in Workplace Emails
Recognizing BEC attempts requires attention to contextual and technical indicators that deviate from normal patterns.
Domain and Address Anomalies
Examine sender addresses carefully, particularly for financial requests or sensitive information. Common spoofing tactics include:
- Character substitution: replacing “l” with “1” or “i”
- Domain extensions: using .co instead of .com
- Added elements: hyphens, prefixes, or extra words
- Similar-looking characters: rn appearing as m
Urgency and Pressure Tactics
Legitimate business processes rarely require immediate action without verification. Suspicious urgency indicators include:
- Demands for same-day wire transfers
- Requests to bypass normal approval workflows
- Claims that verification will jeopardize deals or relationships
- Emphasis on confidentiality that prevents consultation
Unusual Requests and Process Deviations
Context matters when evaluating email legitimacy. Red flags include:
- First-time payment change requests via email
- Requests for gift cards or unusual payment methods
- Solicitations outside normal business relationships
- Changes in communication style or language patterns
Technical Indicators
Beyond content, technical elements often reveal spoofing:
- Reply-to addresses differing from sender addresses
- Emails from external sources claiming to be internal
- Generic greetings when personalization is expected
- Missing or altered email signatures
Simple Verification Techniques
Effective BEC prevention requires habits that introduce friction into potentially fraudulent transactions without significantly impeding legitimate work.
Out-of-Band Verification
Never verify suspicious requests using contact information provided in the email itself. Instead, use independently confirmed contact details from previous communications, company directories, or published sources. Place a phone call to known numbers rather than replying to email. This simple step prevents scammers from simply confirming their own fraudulent requests.
Domain Inspection Habits
Develop routines for examining email addresses, especially for financial or sensitive requests. Hover over sender names to reveal full addresses before responding. On mobile devices where this proves difficult, flag uncertain messages for desktop review before taking action. Compare current sender addresses against previous legitimate communications from the same individual or organization.
Process Adherence and Documentation
Establish and follow verification protocols for common BEC targets. Payment changes require written and verbal confirmation from known contacts. Sensitive data requests need documented authorization. Urgent exceptions require supervisor approval. Document verification attempts including date, time, method, and result for audit purposes and fraud investigation.
Collaborative Verification
When uncertain about email legitimacy, consult colleagues before acting. Forward suspicious messages to IT or security teams for evaluation. Discuss unusual requests with supervisors even when they appear to originate from those same supervisors. Legitimate communications withstand scrutiny; scammers abandon efforts when verification introduces delays.
Building Fraud-Resistant Payment Processes
Organizations reduce BEC risk significantly through systematic process improvements that make attacks impractically difficult.
Dual Authorization Requirements
Require two-person approval for payments above defined thresholds or for any payment-related changes. This prevents single-point compromise from resulting in loss. Establish clear authorization levels and enforce them consistently, with no exceptions for urgency or executive requests without proper verification protocols.
Payment Change Verification Scripts
Create standardized procedures for vendor payment updates:
- Email notification of pending change triggers mandatory phone verification
- Caller uses independently confirmed contact information
- Specific details are confirmed: bank name, account number, routing number
- Change request is documented with verification details
- A waiting period applies before first payment to new account
Pre-Approved Vendor Lists
Maintain approved vendor databases with verified payment information. Payments to new vendors require enhanced verification including business registry confirmation, reference checks, and additional approval levels. This prevents opportunistic scams targeting accounts payable with fake invoice submissions.
Time-Based Controls
Eliminate same-day processing for payment changes or new vendor setups. This waiting period allows discovery of compromises, vendor notification of suspicious changes, and proper verification completion without time pressure. Legitimate business partners accommodate reasonable security procedures.
Social Media Security for Professionals
Professional networking platforms provide valuable career opportunities while simultaneously creating BEC vulnerabilities through information disclosure.
Information Scammers Extract from LinkedIn
Attackers mining professional profiles gather organizational intelligence without technical sophistication:
- Reporting relationships and organizational hierarchy
- Project involvement and current initiatives
- Work location and travel patterns
- Professional connections revealing vendor and partner relationships
- Job transitions indicating process knowledge transfer periods
Strategic Profile Management
Balance professional visibility with security awareness through selective sharing:
- Limit detailed organizational structure information
- Avoid posting about specific vendors or partners
- Refrain from sharing travel plans or time-sensitive absences
- Consider who can view connection lists and detailed work history
- Review privacy settings to restrict information access
Team Photo and Organizational Disclosure
Images and posts revealing office layouts, team structures, or employee identifications provide reconnaissance value. Consider whether group photos, team announcements, or celebration posts disclose information useful for impersonation. This doesn’t require paranoia—simply awareness that public information serves multiple purposes.
Creating Security-Aware Culture
Technical controls alone prove insufficient against social engineering. Organizational culture determines whether security practices become habitual or get bypassed as inconvenient obstacles.
Positive Reinforcement Approaches
Frame security awareness as professional competence rather than paranoid burden. Recognize employees who report suspicious emails, challenge unusual requests, or identify process improvements. Celebrate near-misses as learning opportunities rather than focusing only on breaches. This encourages reporting and vigilance without creating fear or blame.
Regular Scenario Training
Use concrete examples from real BEC cases to illustrate attack patterns. Walk through specific scenarios relevant to organizational roles—what would accounts payable see, how would HR receive data requests, what might executive assistants encounter. Scenario-based training proves more effective than abstract policy review.
Clear Escalation Paths
Employees need simple, known procedures for reporting suspicious communications without fear of wasting others’ time. Establish designated contacts for security questions with clear expectations that inquiries are welcomed and valued. Respond to reports promptly with clear feedback about legitimacy and appropriate actions taken.
Leadership Modeling
Executives and managers set cultural tone through their own practices. Leaders who verify payment changes, question suspicious emails, and acknowledge their own uncertainties normalize security-conscious behavior. Conversely, leaders who demand exceptions to security procedures or criticize verification delays undermine defensive culture.
Emerging BEC Techniques
Attack methods evolve as defenses improve and new technologies provide additional manipulation opportunities.
AI-Enhanced Voice Cloning
Scammers increasingly supplement email with voice calls using AI-generated audio mimicking executives or vendors. These calls confirm fraudulent email requests, defeating verification procedures that rely solely on phone contact. Defense requires authentication beyond voice recognition—established code words, callback to known numbers, or person-specific questions.
QR Code Phishing in Business Context
Quishing attacks embed QR codes in emails that appear to link to legitimate business resources—document previews, meeting links, or vendor portals. Mobile scanning bypasses email security that would flag malicious URLs in text format. Treat QR codes with the same scrutiny as links, particularly in unexpected contexts.
Merger and Acquisition Exploitation
Attackers monitor corporate announcements for mergers, acquisitions, or leadership transitions. These periods create confusion about processes, introduce new names and relationships, and provide cover for unusual requests. Organizations should heighten verification requirements during transitional periods despite pressures to demonstrate efficiency.
When BEC Succeeds: Response Actions
Despite preventive measures, some attacks succeed. Rapid response limits damage and aids recovery.
Immediate containment steps include notifying financial institutions to attempt transaction reversal, documenting all related communications, reporting to law enforcement through FBI’s IC3 system, and alerting potentially affected vendors or partners. Preserve evidence by maintaining email copies and transaction records rather than deleting compromised communications.
Post-incident analysis should identify attack vectors, compromised accounts, and process failures that enabled success. This guides remediation efforts including password resets, account security review, and process improvements. Share lessons learned across the organization to prevent similar future incidents.
Practical Prevention Summary
Business email compromise exploits human trust and organizational processes rather than technical vulnerabilities. Protection requires awareness, verification habits, and systematic processes:
- Examine sender addresses carefully for financial or sensitive requests
- Verify changes through independent contact information
- Establish dual-authorization and time-delayed processes for payments
- Monitor social media disclosures that aid reconnaissance
- Foster culture where security questions are welcomed
- Stay current on emerging attack techniques
The $2.4 billion annual losses to BEC reflect thousands of individual incidents across organizations of all sizes. Each incident began with an email that appeared legitimate to someone handling routine work responsibilities. The difference between victim and defender often reduces to whether verification occurred before action—a simple habit that prevents massive consequences.
Enjoyed this article?
Subscribe to Professor Simon's weekly newsletter for practical insights, career guidance, and leadership lessons delivered every Friday.
A confirmation email will be sent. If you don't receive it, please check your spam or junk folder.
No spam. Unsubscribe anytime.
Prefer to Listen?
Listen to Professor Simon’s IT & Cybersecurity Podcast for practical conversations about cybersecurity careers, certifications, security leadership, and real-world lessons from the field.
Listen on Spotify

