For business management solutions email us or call 020 3004 4600

What is Business Email Compromise (BEC)?

Business Email Compromise (BEC) is a type of cyber fraud where criminals impersonate a trusted contact, such as a senior executive, supplier or customer, usually by email, to trick an employee into making a fraudulent payment or disclosing sensitive information.

How Business Email Compromise works

An attacker typically compromises or spoofs a legitimate-looking email account or domain, then researches the target organisation through sources such as LinkedIn or the company website to identify a plausible scenario, such as an urgent invoice or a change to a supplier's bank details. Unlike many phishing attacks, BEC relies on social engineering rather than malware, often containing no malicious link or attachment at all, which makes it harder for technical filters to catch and puts more weight on staff awareness and payment verification procedures.

How UK businesses defend against BEC

  • A finance assistant receives an email appearing to come from the finance director asking for an urgent supplier payment, but the email address is a lookalike domain rather than the genuine one.
  • A business updates its process so any change to a supplier's bank details must be verified by phone using a known contact number, not the number given in the email requesting the change.
  • An accounts team member spots a BEC attempt because the "urgent" tone and pressure to bypass normal approval steps doesn't match the organisation's usual payment process.
  • A company runs simulated BEC and phishing exercises to help staff recognise the warning signs of these targeted email scams before a real one arrives.

How Advantage helps SMEs reduce BEC risk

Advantage helps SMEs reduce the risk of Business Email Compromise through a combination of email security controls, domain protection and staff awareness training, alongside guidance on payment verification processes that make BEC scams harder to succeed.

Explore Advantage's cyber security services →

Frequently Asked Questions

How is BEC different from phishing?

Phishing is a broad term for fraudulent messages, often sent in bulk, trying to get people to click links or share credentials. BEC is a more targeted form of fraud that usually aims to trick a specific employee into making a payment or sharing sensitive data by impersonating a trusted contact.

Why is BEC hard to detect with technical security tools alone?

Many BEC emails contain no malicious links or attachments, so they can bypass filters designed to catch malware, relying instead on convincing language and impersonation, which makes staff awareness and verification processes especially important.

What should a business do if it suspects a BEC attempt?

Contact the bank immediately if a payment has already been made, report the incident, and verify any similar future requests through a separate, trusted communication channel rather than replying to the email in question.