// PHISHING

BEC and CEO fraud: how companies lose money to a fraudulent invoice

A business email compromise (BEC) attack needs no virus and no malicious link. The attacker poses as a director or as a supplier, writes a believable email, and has a payment sent or an account number changed. No technique, only manipulation, which is exactly why neither the antivirus nor the spam filter catches it. The defense therefore rests on process, not on a tool: on two-person approval of payments and on verifying every change of account through a channel other than email.

Phishing

By Patrik Žák

// 01

What is BEC and why does it need no malware?

BEC, business email compromise, is a fraud in which the attacker poses as a trusted party and gets the company to make a payment or to change payment details. It isn’t a technical attack: it has no attachment and no malicious link, and it relies purely on the recipient believing the sender.

The absence of technique is exactly its strength. The antivirus has nothing to scan, the spam filter has no suspicious link to check, and the email looks like ordinary work correspondence. What separates BEC from technical phishing, meaning the technical tricks that get around MFA, is that it gets around no protection at all. It simply needs none.

Formally, BEC is a kind of spear phishing, that is, a targeted message built on what the attacker knows about the victim. Where BEC sits in the typology of phishing is worked through in the glossary. Here it is about the scenario and the defense, not about definitions.

// 02

What such a fraud looks like

The fraud comes in several forms, differing in who the attacker poses as and in what they ask for. Here are four you run into in a B2B environment.

  • A change of the supplier’s bank account. The attacker poses as a supplier the company pays regularly and announces a new account number by email. The next invoice then goes to the fraudster’s account. This one is called invoice fraud.
  • An urgent transfer from the director. An employee gets a message in the name of the managing director or the finance director asking for a quick transfer, with an emphasis on haste and discretion. This one is called CEO fraud, a fraud in the name of management.
  • A lawyer or an acquisition under confidentiality. The attacker poses as an attorney handling a confidential transaction and asks for a payment nobody may talk about. The secrecy is there to keep the victim from verifying the request.
  • A redirected salary. The attacker poses as an employee and asks the payroll department to change the account number for the salary. The next salary then goes elsewhere.

// 03

Why does it get past filters and past careful people?

BEC doesn’t work on a flaw in a system but on pressure on a person. The attacker combines authority, urgency, and secrecy, three levers that are hard to resist when they come from someone the victim is supposed to trust. Each of the three works on the reader, not on the mailbox, which is why a careful person can fall for it too.

Authority means the request comes in the name of a superior or an important client whom a person hesitates to question. Urgency pushes for speed so there is no time to verify: the payment has to leave today or the deal falls through. Secrecy, meaning the instruction not to discuss it with anyone else, cuts the victim off from the colleague who would have spotted the fraud.

Two tricks with the email itself get added to that. A lookalike domain looks almost like the real one, with a character swapped or added, so it passes at first glance. And with thread hijacking, meaning the takeover of an existing thread, the attacker slips into a real conversation that is already running. That takes access to someone’s mailbox: a password that has leaked once is one way in. The message then doesn’t look new and suspicious but like the continuation of something already under way.

// 04

How a company actually loses the money

The loss comes from a single transfer to an account the attacker controls. Either the payment details on a legitimate invoice get changed, or an extraordinary payment goes out that nobody questions. Once the money has left, the way back is hard.

The fraudster quickly sends the money on from the account and withdraws it, so by the time the company finds out it was a fraud, the money is gone. The bank doesn’t reverse the transfer automatically, because from its side this was a payment the company entered itself. Recovery then depends on how fast the fraud is reported and on whether the chain of accounts can be traced.

Data from the FBI’s Internet Crime Complaint Center (IC3) show that this is no marginal problem. In its annual IC3 report for 2024, the FBI put the reported losses from business email compromise at roughly USD 2.77 billion, which makes it the second costliest category of cybercrime right after investment fraud.

// 05

What actually works against BEC

Because BEC aims at the payment process, the defense is a process as well, not antivirus software. What matters is that no payment and no change of account can be approved by one person alone, and that a change of details is always verified through a channel other than email.

  • Two-person approval of payments above a set amount: a second person has to confirm the transfer, so one deceived employee isn’t enough.
  • Verification of an account change by calling back on a known number, not on the one from the email. When a supplier reports a new account, call them on the number you already had.
  • SPF, DKIM, and DMARC on your email: technical records that make spoofing your domain harder and mark the messages that fail those checks.
  • A visible label for external senders: a tag showing that the message came from outside draws attention to an email that pretends to be internal.
  • Exercises on specific scenarios, so people know that haste and secrecy are warning signs in themselves.

Technical measures such as SPF or DMARC help, but the weight sits in the process and in the people. Whether your people fall for a spoofed request is verified by a controlled campaign with a fraudulent invoice scenario, and how to set up the payment approval process and the mail is something we can go through in a consultation. The goal isn’t to catch people out but to find where the process leaks.

// 06

What is business email compromise (BEC)?

BEC is a fraud in which the attacker poses as a trusted party, typically as the company’s management or as a supplier, and by email gets the victim to make a payment or to change a bank account. It uses no malware and no malicious link, relying purely on manipulation. That is why neither the antivirus nor the spam filter catches it.

// 07

How does BEC differ from ordinary phishing?

Ordinary phishing sends a link or an attachment to many people at once and aims at a password or at getting malware to run. BEC is targeted and has no technique: it aims at one company, leaves nothing to scan, and its goal is the payment or the change of payment details itself. The defense against it is therefore a matter of process, not of technology.

// 08

How do you defend against fraudulent invoices?

Two things work: two-person approval of payments, so one deceived person isn’t enough, and verification of every change of bank account through a channel other than email, meaning a call back on a number you already know. The technical records SPF, DKIM, and DMARC help alongside that, as does labeling external senders. Process comes before tools.

Updated .

// NEXT STEP

Want us to check the same thing in your environment?

Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.