What is business email compromise (BEC)?

Business email compromise (BEC) is a fraud technique in which attackers use email that appears legitimate — a spoofed executive, a look-alike domain, or most dangerously a genuinely compromised business mailbox — to trick employees into transferring money or changing payment details. Because the message often contains no malware and no malicious link, conventional email security has nothing to detect.

Also known as: BEC attack · CEO fraud · email account compromise · wire transfer fraud

Why BEC bypasses email security

Email filters hunt for malicious attachments, links and spoofing indicators. The highest-loss BEC variant defeats all three: the attacker controls a real vendor mailbox (taken over via phishing), replies inside a genuine invoice thread, and quietly supplies new bank details. Every technical signal says the message is authentic, because it is. Only the payment instruction gives the attack away.

The scale is documented: the FBI’s IC3 2025 Internet Crime Report records over 3 billion dollars in reported US BEC losses in a single year across roughly 24,800 complaints — about 123,000 dollars per incident — making BEC the second-costliest cybercrime category.

What stops it

Process controls help — mandatory call-back verification of bank-detail changes — but they are manual and brittle under volume. Dedicated payment security closes the gap technologically: platforms like Trustmi correlate vendor behavior, email context, files and payment data across the whole flow, flagging the payment whose pattern is wrong even when each individual message looks clean.

Sources: FBI IC3 — 2025 Internet Crime Report

// In the Cyberdis portfolio

Trustmi stops BEC-driven payments before money moves — distributed by Cyberdis.

// FAQ

Common questions.

Is BEC the same as phishing?

Phishing is usually the entry (stealing the mailbox credentials); BEC is the monetization — using that access, or convincing impersonation, to redirect business payments. Anti-phishing controls reduce mailbox takeovers but do not catch the fraudulent payment instruction itself.

Why did our email filter not flag the fraudulent invoice?

Because there was nothing technically malicious to flag: a real mailbox, a real thread, a clean PDF — only the bank details changed. Detection has to happen at the payment-flow level, not the message level.

What does Trustmi do differently?

Trustmi watches the payment flow end to end — vendor records, emails, files, payment instructions — and stops anomalous payments before funds move. It layers on top of your ERP and email security rather than replacing them. Cyberdis distributes Trustmi with engineer-led PoCs on your real payment workflow.

Related explainers: What is vendor impersonation fraud?What is payment fraud?

Weighing approaches? Dedicated payment fraud prevention vs ERP controls and email security