Business email compromise (BEC) is a scam where an attacker impersonates an executive, supplier or colleague by email to trick someone into sending money or changing payment details. There is often no malware – it relies on a convincing message and a rushed decision.
How it works
- Reconnaissance – the attacker learns who pays invoices, who the suppliers are, when the boss travels (often from a compromised mailbox)
- The setup – a lookalike domain, a spoofed sender, or a genuinely hacked account
- The ask – an urgent wire transfer, a change of bank details on a supplier account, or gift cards – always with pressure and secrecy
- The loss – money moves to an account the attacker controls and is gone within hours
Why it beats technical defences
Filters look for malware and bad links; a plain-text email asking for a payment change has neither. BEC targets the process and the person, so the defence has to as well.
The controls that stop it
- Verify out of band – any payment or bank-detail change confirmed by a phone call to a known number, never a number in the email
- Dual approval for payments over a threshold
- MFA on all mailboxes, so accounts are harder to hijack
- Email authentication (SPF, DKIM, DMARC) to make spoofing your domain harder
- Staff training on the exact pattern – urgency, secrecy, payment change
We put these in place through our cybersecurity service.
Related security guides
- What a firewall does
- Multi-factor authentication explained
- Network segmentation
- EDR vs antivirus vs MDR
- Security awareness training
- How to prevent ransomware
Want this handled? See our cybersecurity service or talk to our Edmonton team.
Frequently asked questions
Is BEC the same as phishing?
It is a targeted form of it. Regular phishing casts wide with malicious links; BEC is researched, personalised, and usually asks for a payment or data change rather than a click.
How do we recover money lost to BEC?
Contact your bank immediately – within 24 hours there is sometimes a chance to recall the transfer. Report it to police and, in Canada, the Canadian Anti-Fraud Centre. Prevention matters far more than recovery.
Does MFA stop BEC?
It stops the account-takeover version by making mailboxes hard to hijack. It does not stop a spoofed external email – that needs verification procedures and training.
How does Scandifix help?
We set up MFA and email authentication, help you write the payment-verification procedure, and train staff on the BEC pattern.