Business Email Compromise

Business Email Compromise

Business Email Compromise is a fraud scheme in which criminals pose via email as a superior or business partner in order to trigger money transfers. The attack does not rely on malware, but on deceiving employees.

Business Email Compromise is a fraud scheme using fake or stolen email access within companies. The perpetrators write to an employee and pose as the boss, a customer, or a supplier. The message usually contains an urgent request: a bank transfer, a changed account number, the purchase of gift cards. The fraud works without malicious programs and without any technical break-in into computers. It relies solely on a person believing a seemingly genuine message and releasing money. The German term for this is often 'Chef-Masche' (boss scam).

The most expensive fraud on the internet

In the loss statistics of investigative authorities, BEC has topped the list for years. The American FBI reported around 2.9 billion US dollars in damages for 2023 from this scheme alone. That puts it clearly ahead of ransomware, which is reported on far more often. The reason is simple: a single successful transfer can involve six- or seven-figure sums.

For companies, the attack is especially unpleasant because it leaves almost no technical traces. An email from a genuine address with a genuine signature looks harmless to any security program. There is no virus for a scanner to detect. Only the content is suspicious, and in the end a human being is the one who judges it.

Then there’s the time pressure. Once the money is on a foreign account and has been redistributed, it is rarely recovered. Banks can only stop transfers within the first few hours. That is why the extent of the damage depends heavily on how quickly someone notices the fraud.

From reconnaissance to the transfer

It begins with research. The perpetrators gather publicly available information about a company: the names of the management, responsibilities within accounting, ongoing projects. Much of this is found on the company website or in career networks. Sometimes they additionally gain access to a real mailbox, for instance via an intercepted password.

Then comes the message. It either comes from a deceptively similar address with a swapped letter, or it actually comes from the hijacked account and inserts itself into an ongoing email exchange. The tone is brief and urgent, often with a note that the matter is confidential and must not be discussed. This is precisely meant to prevent anyone from asking further questions.

Language models have changed this scheme. In the past, clumsy phrasing and spelling mistakes gave away many forgeries. Today an AI writes flawless German in the appropriate tone, and does so within seconds. Imitated voices on the phone have also started to appear. The most important protection is therefore not a filter, but a firm rule: payment instructions are confirmed via a second, known channel, for example by calling back a saved number.

Who is affected

Not only large corporations are targeted. Craft businesses, associations, medical practices, and schools regularly appear in police reports. One well-known variant targets property buyers: shortly before payment, an email arrives claiming the notary’s account number has changed. Another variant targets apprentices, who are asked, in the boss’s name, to buy gift cards.

In the news, the term is most often encountered in quarterly reports from security firms and in warnings from the German Federal Office for Information Security (BSI). Insurers also use it, since many cyber policies treat BEC as a separate category. An important distinction: phishing refers to capturing login credentials via fake links. BEC frequently makes further use of such data, but the actual goal is the payment.

A common misconception is that better software solves the problem. It helps, but it is not enough. What actually works are clear procedures: the dual-control principle for transfers above a certain amount, fixed verification steps for account changes, and explicit permission to double-check even with the boss.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.