What business email compromise (BEC) is#
BEC is a targeted attack where an attacker impersonates an executive or vendor to redirect payments or extract data, often from a legitimate compromised mailbox rather than a spoofed one.
Why it matters#
BEC causes more financial loss than any other cybercrime category, and it frequently passes authentication because the mailbox is real.
How mailbox providers use it#
Gmail, Microsoft, and Yahoo combine authentication results, sender reputation, and recipient engagement into a placement decision made per message. Business email compromise (BEC) feeds directly into that model, and weaknesses compound with other signals.
How to measure the impact#
- Baseline inbox placement with seed tests before any change.
- Make one change at a time and hold volume steady.
- Re-test after 48 to 72 hours; provider models need time to update.
- Track Postmaster Tools and SNDS alongside your seed results.
Improving it#
- Require MFA on all mailboxes and disable legacy authentication protocols.
- Alert on new inbox rules that forward or delete mail, a common attacker persistence step.
- Verify payment changes by phone using a known number, never the one in the email.
- Flag external mail with display names matching internal staff.
Frequently asked questions#
How is BEC different from phishing?
Phishing casts wide for credentials; BEC is targeted social engineering for money, often using a real hijacked account.