How organizations combat business email compromise
This type of cybercrime remains one of the most common and potentially damaging. Here’s why your people are key to a frontline defense.
4 minute read
Key takeaways:
- Educate employees to exercise skepticism when receiving unusual email requests, even when the email appears to come from a known of trusted contact.
- Encourage employees not to bypass identity access controls or share login credentials.
- Remember that fraudulent emails and email scams may be the first step in complex cybercrime campaigns, such as ransomware or data theft.
Business email compromise (BEC) is a specialized phishing technique that targets individuals with the intent of tricking them into sending money or sharing sensitive information. It remains one of the most lucrative types of cybercrime, with losses exceeding $3 billion across nearly 25,000 complaints reported to the FBI in 2025.1
The methods perpetrators use in BEC continue to change as technology and business processes evolve. But this crime still depends on establishing and exploiting trust. Perpetrators may impersonate internal colleagues, senior leadership, or trusted consultants, as well as established vendors or customers. They use persuasive social engineering tactics to convince individuals of their identity and the legitimacy of their requests.
Ongoing developments in artificial intelligence (AI) and account hacking have made some BEC scams very difficult to detect. The best defense is still a workforce that stays alert to this persistent threat while balancing efficiency with security objectives.
Criminals often tailor their BEC scams to the organization and individuals they target by adding highly specific details based on internet research. However, most scams fall into these broad categories:
Fraud & Cybersecurity
New threats emerge every day that can negatively impact transactions and businesses. Explore the latest insights and resources to help prepare and protect you and your business.