Skip to content

Home Topics Email Security Management Business email compromise

Email Security Management · Business email compromise

Business email compromise (BEC) FAQ: 4 questions answered

Short answer

Phishing casts wide for credentials; BEC is targeted social engineering for money, often using a real hijacked account.

BEC is a targeted attack where an attacker impersonates an executive or vendor to redirect payments or extract data, often from a legitimate compromised mailbox rather than a spoofed one.

How is BEC different from phishing?

Phishing casts wide for credentials; BEC is targeted social engineering for money, often using a real hijacked account.

Why does business email compromise (BEC) matter for deliverability?

BEC causes more financial loss than any other cybercrime category, and it frequently passes authentication because the mailbox is real.

What is the first step to get started with business email compromise (BEC)?

Require MFA on all mailboxes and disable legacy authentication protocols.

What is the most common business email compromise (BEC) mistake?

Assuming DMARC protects against BEC from a compromised real account.

Keep reading on Business email compromise