BEC (Business Email Compromise)
Last updated
Definition
Business Email Compromise is fraud conducted through a trusted mailbox: an attacker either takes over a real business email account – today most often via adversary-in-the-middle phishing kits like Evilginx that steal session tokens and bypass weak MFA – or convincingly spoofs one, then impersonates an executive, employee, or vendor to redirect wire transfers, change payroll deposit details, or reroute vendor payments. There is often no malware involved at all, just a plausible fraudulent email, which is why it slips past antivirus-era thinking entirely.
Why it matters to an MSP
FBI IC3 reporting consistently ranks BEC among the top cybercrime loss categories, with billions in reported losses annually, and SMBs are prime targets: a single fraudulent wire can be a six-figure, often unrecoverable loss. The countermeasures form a layered, sellable package. Technical: phishing-resistant MFA with Conditional Access and legacy auth disabled; hardened email security – DMARC/DKIM/SPF enforcement plus an API-layer tool such as Acronis Email Security, Avanan, Mesh, or IRONSCALES on top of Microsoft's EOP/Defender. Human: security awareness training with phishing simulations. And – critically, because no technology covers it – finance-process controls at the client: out-of-band verification of any payment or banking change, and dual approval on wires. Advising on that last layer is what separates an MSP acting as a security partner from one merely selling licenses.
Related terms: Phishing, MFA, Security Awareness Training