The defining feature of business email compromise is that nothing about the payment looks wrong. There is a real vendor, a real invoice, and a real amount owed. The only thing the attacker changes is the destination account. Because the payment is authorized by an employee who believes they are doing their job, most banking controls treat it as a valid instruction.
Attackers typically arrive through one of three doors: a compromised mailbox inside the supplier, a compromised mailbox inside the buyer, or a lookalike domain that differs from the real one by a character or a top level domain. Once inside a thread, they wait for an invoice to appear and then intercept or reply to it with new remittance details.
Because the exploited step is the exchange of bank details rather than the payment itself, controls that inspect only the payment file cannot see the fraud. The compromise happened earlier, in email.
Common questions
How is business email compromise different from phishing?
Phishing usually harvests credentials or delivers malware to a broad list. Business email compromise targets a specific payment relationship and often uses a genuine mailbox, so there is no malicious link or attachment to detect.
Can a bank reverse a business email compromise wire?
Rarely. A domestic wire is final once settled, so recovery depends on the receiving bank freezing funds before they are withdrawn or moved onward. Speed of reporting matters more than anything else.
Who inside a company is usually targeted?
Accounts payable staff, controllers, and anyone who can change vendor master data. Attackers also impersonate executives to pressure a single approver into bypassing normal steps.
Primary sources
- FBI Internet Crime Complaint Center (IC3), annual Internet Crime Report
- FinCEN advisories and guidance
- CISA advisories
Citing this entry? Cite as Coffr, LLC and link to https://getcoffr.com/glossary/business-email-compromise.