Fraud that does not look like an attack
Business email compromise is financial fraud carried out over email. There is usually no malware, no exploit and no attachment. The message asks someone to move money or change payment details, and it is convincing enough that they do.
That absence of technical payload is the defining property. Security tooling built to detect malicious content has nothing to detect. The message is text, the request is plausible, and in the most dangerous variants the sender is entirely genuine.
Scale is substantial. The FBI's 2025 Internet Crime Report records 24,768 BEC complaints against reported losses of 3,046,598,558 dollars. Set against 1,008,597 total complaints and 20.877 billion in total reported loss, that is roughly 2.5 percent of complaints producing 14.6 percent of the money.
Two caveats before that figure travels further. IC3 data is complaint based, so it counts what victims chose to report to one US agency and undercounts by an unknown margin. And it is US weighted. There is no equivalent European figure, because BEC is handled as fraud by national police forces rather than reported as a cyber incident, and it falls outside the NIS2 reporting regime.
The recognised subtypes
CEO fraud. An executive appears to instruct an urgent transfer, usually with a reason for bypassing normal process. Confidential acquisition, regulatory deadline, executive travelling and unreachable.
Vendor or supplier invoice fraud. A supplier appears to notify a change of bank details. Frequently the highest value variant, because invoice amounts are large and the request is routine.
Payroll diversion. An employee appears to ask HR to redirect their salary to a new account. Low value individually, and easy to repeat.
Attorney impersonation. Pressure applied under claimed legal urgency and confidentiality.
Gift card fraud. Low value, high volume. By APWG's Q1 2026 measurement it accounted for 48 percent of BEC cash out requests against 19 percent for wire transfer, though the average wire request of 42,663 dollars means the loss distribution runs the other way entirely.
Three routes in, and why the third is worst
Free webmail with a changed display name. The attacker registers an ordinary account and sets the display name to a person you know. Most mail clients show the display name prominently and the address barely, or not at all on mobile.
This is the majority route. APWG measurement published in May 2026 found 72 percent of BEC originating from free webmail domains, Gmail representing 53 percent of those.
Lookalike domain. The attacker registers something that resembles your domain or a supplier's and sends from it. This is the typosquatting problem applied to fraud, and it carries more credibility than webmail at the cost of a registration and some setup.
Compromised mailbox. The attacker is inside a real account, at your organisation or at a supplier. No spoofing at all.
The third is the dangerous one, and it deserves its own section.
One caveat on the numbers. No published source gives a clean three way split of these routes. APWG's 72/28 measures sending infrastructure, and the 28 percent bucket mixes lookalike domains with compromised mailboxes. Anyone quoting a precise breakdown is estimating.
Inside a compromised mailbox
When the attacker holds the account, every signal a defender would normally check comes back clean. The sender is real. SPF, DKIM and DMARC all pass, correctly. The thread history is genuine. The writing style matches, because the attacker has read months of archive before sending anything.
What they do first is establish quiet. Microsoft's published analysis of adversary in the middle campaigns documents the pattern: a mailbox rule that archives and marks as read anything matching particular keywords, so replies and warnings never reach the real user's inbox.
Then they wait and read, learning the payment cycle, the supplier relationships, and who approves what.
Then they hijack a thread. Rather than composing a fresh message, they reply inside an existing conversation about a real invoice, changing the bank details. Barracuda's January 2026 analysis of 3.1 billion emails found conversation hijacking at 0.10 percent of malicious email against BEC at 0.06 percent, and reported that 34 percent of companies experienced account takeover monthly, with 25 percent of those involving suspicious inbox rule changes.
Speed at the final step can be considerable. Microsoft observed payment fraud initiated within five minutes of session hijacking in some cases.
Where the mailbox access comes from
Almost always stolen authentication material rather than an exploit.
Adversary in the middle phishing proxies the genuine login page. The victim authenticates against the real service, completes the multi factor challenge, and the proxy captures the resulting session token. Multi factor authentication is not defeated in any technical sense, it is bypassed, because the attacker takes the output rather than attacking the process. See session cookie theft.
Infostealer malware produces the same material at scale from infected devices, frequently devices the organisation does not manage.
Access is also bought. Europol's 2026 assessment reports initial access to corporate environments priced under 2,800 euros, and ENISA's 2025 threat landscape documents infostealer operations at scale, including a single family recorded on 394,000 machines between March and May 2025.
Why email authentication does not solve this
SPF verifies that the sending server is authorised for the domain in the envelope. DKIM verifies that the message was signed by the domain and not altered. DMARC ties those to the visible From domain and tells receivers what to do on failure.
Every one of those operates on domains. None of them has any view of whether the display name is honest.
An attacker sending from their own Gmail account with your CFO's name in the display field passes all three, because they are not claiming to be your domain. They are claiming to be a person, and no protocol checks that.
Against the lookalike domain route, the same logic applies. The attacker owns the lookalike domain, publishes their own records, and authenticates correctly.
Against a compromised mailbox, there is nothing to detect at all.
So email authentication addresses exact domain spoofing of your own domain, which is real and worth closing, and which is precisely why attackers moved to the three routes above. Deploy DMARC. Do not expect it to address BEC.
What actually detects it
Mailbox rule auditing. Alert on rule creation, particularly rules that move, delete or mark as read based on keywords. This is the single highest yield signal for compromised mailbox BEC, and it is available in every major platform.
Authentication anomaly detection. Impossible travel, new device, unusual client, session established from an address inconsistent with the user's pattern.
Payment process controls that do not depend on email. Out of band verification of any bank detail change, using a number from your own records. Dual authorisation above a threshold. A documented rule that urgency never waives verification, which exists precisely because urgency is the lever every variant pulls.
External exposure monitoring. Credentials and session cookies for your domain circulating in stealer log data are an advance warning that mailbox compromise is available to anyone who wants it. Internal telemetry does not produce that signal.
If it happens
Move in hours, not days.
Contact your bank immediately and ask for a recall. Report to your national police and financial crime reporting channel. For US linked transfers, the FBI's Recovery Asset Team is the relevant mechanism.
The IC3 2025 figures give a realistic picture of what recovery looks like. The Recovery Asset Team actioned 3,900 incidents, covering 1.164 billion dollars of attempted theft, and froze 679 million, a 58 percent success rate on cases actioned.
Read that carefully, because it is routinely misquoted. It is funds frozen as a share of attempted theft in cases the team took on, not a recovery rate across all BEC. They actioned 3,900 incidents against 24,768 complaints. And only 326 of those actions were international, which matters considerably if you are in Europe.
Then secure the account properly: revoke all sessions before resetting the password, audit mailbox rules and forwarding, check for added authentication methods, and review what was sent from the account while it was held.