This article explains how business email compromise (BEC) scams work when attackers impersonate executives or suppliers to request urgent wire transfers, bank-detail changes, or credentials, often without malware or links. It cites real, high-loss cases (including Google/Facebook and aerospace supplier FACC) and provides common BEC pretexts your team can practice spotting and verifying.
How the attack works
Business email compromise (BEC) does not rely on malware or malicious links. Instead, it relies on a plausible, well-researched email that asks a specific person to do something that fits inside a normal working day. Attackers typically impersonate a senior executive, a supplier, or an internal colleague, and the request is almost always a wire transfer, a change to payment details, or sensitive credentials.
Identity spoofing techniques behind these emails include lookalike domains, display-name spoofing, header spoofing, Reply-To manipulation, and in some cases a genuinely compromised mailbox. When attackers use a real compromised account, they don't need to fake anything, which makes detection harder.
Why these scams succeed
Three scenarios illustrate the pattern: a fake CEO requesting an urgent, confidential acquisition payment; a supplier notifying a bank detail change timed just before a real invoice is due; and a fake IT helpdesk asking an employee to confirm a password or approve a login prompt.
Each scenario exploits the same weaknesses:
- Urgency and confidentiality that discourage verification
- Trust in an existing relationship, such as a supplier that a business already works with
- Employees who fear looking obstructive or distrustful toward a senior figure
Real-world examples cited include a $121 million fake-invoice scheme that billed Facebook and Google using invoices impersonating a hardware supplier both companies genuinely used, and a roughly €50 million CEO-impersonation request against aerospace supplier FACC tied to a supposed acquisition project. In the invoice case, the fraudulent payments continued for two years because they fit an existing business relationship.
What to watch for
Red flags across these scenarios include:
- Urgency tied to closing a deal or completing a transfer
Key findings
- BEC relies on a plausible, well-researched email request rather than malware or links: “the entire attack is a well-researched email asking a specific person to do something that fits plausibly inside a normal working day.”
- Attackers commonly impersonate “a senior executive, a supplier, or an internal colleague” to request “a wire transfer, a change to payment details, or sensitive credentials.”
- Identity spoofing methods described include lookalike domains, display-name spoofing, header spoofing, Reply-To manipulation, and using a compromised mailbox.
- Real examples cited include: a $121M fake-invoice scheme targeting Facebook and Google, and a ~€50M CEO-impersonation request against FACC tied to a supposed acquisition project.
- Recommended defenses emphasize process controls (dual authorization, callback verification) and technical email authentication (DMARC/SPF/DKIM), plus an “always acceptable to pause and verify” culture.
Who’s being targeted
- Commonly targeted roles: Finance, Accounts Payable, Payroll, HR, Executives, All Employees.
- Affected industries: Technology (internet services), Manufacturing (aerospace supplier), Any organization with finance/accounts payable/payroll functions.
- Attack channels: email.
- Impersonated: CEO / senior leader, Existing supplier / vendor, Internal IT / helpdesk.
Red flags to watch for
- Urgency tied to closing “today” and pressure to act fast
- Confidentiality request discouraging verification
- Unusual payment request coming directly from senior leadership
- Bank detail change timed “just before a real invoice is due”
- Request relies on existing relationship to avoid scrutiny
- Payment instructions arrive via email without independent verification
- Asks for passwords or login approvals via email
- Uses “system update” urgency to justify unusual requests
- Tries to normalize bypassing standard IT verification channels
Frequently asked questions
What is business email compromise (BEC)?
BEC is a scam where attackers impersonate a senior executive, supplier, or internal colleague to request a wire transfer, a change to payment details, or sensitive credentials, typically without malware or links.
How do attackers impersonate executives or suppliers in BEC scams?
Common methods include lookalike domains, display-name spoofing, header spoofing, Reply-To manipulation, and sending from an already compromised mailbox.
What real-world losses have resulted from BEC attacks?
Cited cases include a $121 million fake-invoice scheme against Facebook and Google impersonating a hardware supplier, and a roughly €50 million CEO-impersonation request against aerospace supplier FACC.
How can organizations reduce BEC risk?
Recommended controls include verifying unusual payment or bank-change requests by phone using a number already on file, requiring dual authorization above a set threshold, and deploying DMARC alongside SPF and DKIM.
Read the video transcript
Imagine this hits your inbox: “Confidential: need this acquisition transfer processed today.” And it looks like it’s from our CEO. This is classic business email compromise. No malware, no links, just a well‑researched email pressuring one person to move money fast, outside normal approval steps. It’s fooled big names: Facebook and Google lost over $120 million to fake supplier invoices; aerospace firm FACC lost about €50 million to a CEO‑style acquisition email just like this. Your move: if an email asks for a payment or bank‑detail change, pause, and call the person or supplier on a known phone number to confirm, never the number in the email.