Business Email Compromise (BEC): How It Works, How to Stop It
Business email compromise explained: CEO fraud, fake invoices and hijacked mailboxes, plus the process and email controls that stop BEC scams.
On this page
Business email compromise (BEC) is a scam in which a criminal pretends to be a trusted person, such as your CEO, a supplier or a lawyer. The message usually comes from a lookalike address, a forged display name or a real mailbox the attacker has taken over. Its goal is to get staff to send money or sensitive data. BEC rarely uses malware. It works by being believable, so stopping it takes both email controls and payment procedures.
What business email compromise looks like
A BEC email rarely looks dangerous. There is no strange attachment and often no link. It reads like a normal message from someone you know, sent at a busy moment:
Law enforcement agencies in many countries consistently rank BEC among the most financially damaging types of cybercrime. The reason is simple: one successful email can redirect a large transfer, and once the money has gone it is often hard to recover.
The five common BEC scenarios
- CEO fraud: an "executive" asks finance for an urgent, confidential transfer, or asks someone to buy gift cards.
- Fake or altered invoices: a "supplier" says its bank details have changed and sends a new invoice.
- Vendor email compromise: the attacker takes over a real supplier's mailbox and replies inside an existing thread. This is the hardest to spot because the address is genuine.
- Payroll diversion: an "employee" asks HR to change the account their salary goes to.
- Data theft: an "executive" asks for staff tax forms, customer lists or contracts.
How attackers make the email look real
| Technique | Example | What catches it |
|---|---|---|
| Display-name spoofing | "Minh Nguyen (CEO)" <ceo.office@freemail.example> | Impersonation detection, External tag |
| Lookalike domain | congty-vn.com instead of congty.vn; rn instead of m | Lookalike-domain detection, protected domains |
| Exact-domain spoofing | Forged From: ceo@example.com | SPF, DKIM, DMARC at p=reject |
| Compromised real mailbox | The real supplier's account, in a real thread | Payment verification, "bank details changed" policy |
| Account takeover inside your company | A phished employee password | 2FA, alerts, forwarding controls, audit log |
Notice the last two rows. When the attacker uses a genuine account, authentication checks pass. That is why business procedures matter as much as filters.
Process controls that stop BEC
These cost nothing, and they stop most BEC attempts even when an email gets through:
- Call back on a known number. Any change of bank details, and any unusual payment request, is confirmed by phone. Use the number already on file, never the one in the email.
- Two people approve payments above a threshold you agree on.
- "Bank details changed" means stop and check. Treat it as high risk every time, even when it comes from a supplier you have worked with for years.
- Urgency and secrecy are red flags. "Don't tell anyone" and "it must go out in the next hour" are classic pressure tactics.
- Payroll changes need identity checks, made in person or through your HR system rather than by email.
- A blame-free reporting culture. Staff who report a near miss quickly protect everyone else.
Email controls that stop BEC
Lock down your own domain
Publish SPF and DKIM records, then move DMARC from p=none to p=quarantine and on to p=reject. This stops attackers sending as your exact domain. It does nothing against lookalike domains, so you need the controls below as well. Step by step: DMARC policy setup.
Flag outside senders and first contacts
An External tag on mail from outside the organisation turns "the CEO" asking for a transfer into an obvious anomaly. A "first time you've received mail from this sender" notice catches the new lookalike address that a fake supplier writes from.
Detect impersonation and lookalike domains
The system should compare the display name of every inbound message against your colleagues' names and a list of protected names. If an outside address uses the CFO's name, the message is flagged. It should also compare sender domains against yours and against protected domains such as your bank and main suppliers, so that examp1e-billing.com or a homograph is caught.
Stop the account-takeover version
Many BEC cases begin with one phished password. Defences include:
- Two-factor authentication for everyone, and mandatory 2FA for admins.
- Control over external forwarding. Attackers often add a rule that quietly forwards mail to an outside address.
- The audit log and remote sign-out, so you can see what happened and end the attacker's sessions.
- Click-time link checking and phishing reporting, so the credential-phishing email that starts it all is stopped. See phishing protection for business email.
How Zomail helps against BEC
Zomail's inbound anti-phishing controls, added in October 2026, map directly onto these techniques:
- Impersonation detection. Zomail flags mail where an outside sender uses the display name of someone in your organisation, or a protected name you add (for example, your chairman). Matching ignores accents and case and also finds the name inside a longer display name such as "CEO Minh Nguyen". If that person really uses a personal address, you can enter it so their genuine mail is not flagged.
- Lookalike-domain detection. Zomail catches domains such as
congty-vn.composing ascongty.vn, homographs, and lookalikes of the protected domains you list for partners and banks. A Strict mode also catches near-misses, at the cost of more false positives. - DMARC-fail spoof handling. You decide what happens to mail that fails DMARC or pretends to come from your own domain.
- A choice of action for each finding. Warn in the message (the default), move to Junk, or hold in quarantine.
- An External tag and a first-time-sender notice on mail from outside, with an optional
[EXTERNAL]subject prefix for Outlook and phone users. - Report phishing. Admins are alerted and can purge the message from every mailbox, after a dry-run count, and block the sender for the whole organisation.
On the account side, Zomail offers TOTP two-factor authentication, mandatory 2FA for admins, app passwords, remote sign-out, admin policies for external forwarding (and forwarding needs a confirmation code), an audit log with CSV export, and message trace. The anti-spam and anti-phishing guide and admin basics cover the settings.
What to do if you've been hit
- Call your bank at once and ask for a recall of the transfer. Speed matters more than anything else.
- Secure the mailbox. Reset the password, sign out all sessions, check 2FA, and remove any forwarding rules or filters you don't recognise.
- Purge the scam email from other mailboxes and block the sender and the lookalike domain.
- Review the audit log and message trace to see what the attacker read or sent.
- Warn the suppliers or customers whose names were used, and report the crime to the police.
- Fix the process gap that let the payment through.
For broader hardening, see our email security best practices.
If you want impersonation and lookalike detection to come with your mailboxes rather than as a separate gateway, Zomail includes it on Cloud plans and on Private Mail. Prices are shown live on the pricing page.
FAQ
What is the difference between phishing and business email compromise?
Phishing is the broad category, often mass emails that try to steal passwords. BEC is a targeted kind of fraud. It impersonates a specific trusted person to trigger a payment or a data transfer, and it usually has no malicious link or attachment.
Does DMARC stop BEC?
Partly. DMARC at p=reject stops criminals from sending as your exact domain. It does not stop lookalike domains, display-name tricks or mail from a genuinely compromised account. Those need impersonation detection, External tags and payment verification.
How can I spot a BEC email?
Look for urgency, secrecy, a change of bank details, a request to bypass the normal process, and a sender address that doesn't quite match. An External tag on a message "from" a colleague is a strong warning sign.
Can a real supplier's email be part of a BEC scam?
Yes. In vendor email compromise the attacker controls the supplier's real mailbox, so every technical check passes. Only out-of-band verification, a phone call to a number you already have, reliably catches it.