4 min read

Why Business Email Compromise Continues to Succeed

Why Business Email Compromise Continues to Succeed
Why Business Email Compromise Continues to Succeed
9:17

Why Business Email Compromise Continues to Succeed

In 2025, the FBI's Internet Crime Complaint Center logged 24,768 business email compromise complaints and $3.05 billion in reported losses, and that figure only counts what victims actually reported. Meanwhile, Microsoft's own Q1 2026 threat data shows traditional malware delivery has dropped to just 5 to 6% of malicious email payloads, while credential phishing now accounts for roughly 94% of them.

Put those two facts together and the picture is clear: attackers aren't breaking in through your defences. They're being let in through your inbox.

 

The Shift From Malware to Social Engineering

For years, email security was built around a simple assumption: the threat is a malicious file or link, so scan every attachment and block every bad URL. That model worked well enough that attackers have largely abandoned it.

Modern endpoint detection, sandboxing, and email filtering have made malware-based attacks expensive to run and easy to catch. Social engineering carries none of that risk. A convincing email asking someone to action a payment, reset a password, or reply with sensitive information contains no malicious code at all, which means there's often nothing for a traditional security tool to flag.

Generative AI has removed the last obstacle that made this harder: quality. Attackers no longer need fluent English or insider knowledge of how a business operates. AI tools can now scrape public information about a company and its staff and draft technically flawless, highly targeted emails in seconds. IBM's 2025 Cost of a Data Breach Report found that 37% of AI-involved breaches included AI-generated phishing content, a share that is expected to keep climbing through 2026.

The channel is also expanding beyond email. Mandiant's M-Trends 2026 report, based on over 500,000 hours of incident response work, found voice phishing has overtaken email phishing as the top social engineering vector in cloud-related compromises, reaching 23% of confirmed initial access methods compared to just 6% for email. A convincing voice clone now needs as little as three seconds of audio, meaning a CEO's conference keynote or a CFO's earnings call is enough raw material for an attacker to work with.

 

Why BEC Specifically Keeps Succeeding

Business email compromise sits at the sharp end of this shift, and a few structural reasons explain why it continues to work even against businesses that consider themselves security-conscious.

It rarely needs malware. Many BEC attacks involve nothing but a well-written email sent from a spoofed domain or a genuinely compromised, legitimate mailbox. There's no payload for antivirus or endpoint detection to catch, because there isn't one.

It targets people outside the obvious risk group. It's tempting to assume finance and executive staff are the primary targets, but 77% of BEC attacks target employees outside of finance or executive roles, often because those employees have less training and less reason to expect a scrutinised request.

It exploits trusted relationships, not just internal ones. Vendor Email Compromise, where an attacker compromises a supplier's or partner's legitimate email account and inserts fraudulent payment instructions into a genuine ongoing conversation, rose 66% in the first half of 2024 alone. The email genuinely comes from a trusted contact, which is exactly what makes it so effective.

It's often deliberately low-value and high-volume. Gift card scams accounted for 37.9% of BEC incidents in one recent quarter precisely because small, low-scrutiny requests are easier to approve without a second thought than a six-figure wire transfer. The average BEC wire transfer request sits at around $24,586, a figure often chosen specifically to stay under thresholds that would trigger additional approval.

It persists quietly through mailbox rules. Once an account is compromised, attackers frequently create hidden inbox rules that auto-forward or auto-delete specific emails, allowing them to monitor a live conversation (such as an ongoing invoice negotiation) for weeks without the account owner noticing anything unusual.

 

Five Defences That Actually Address This

Stopping BEC means shifting focus away from scanning for malicious files and toward validating identity, intent, and process. These five measures address the mechanics of BEC directly, rather than relying on staff to simply "spot the phishing email."

  1. Phishing-resistant MFA. SMS and app-based one-time codes can still be relayed through real-time phishing pages. FIDO2 security keys or passkey-based authentication remove that weakness entirely, since the credential can't be phished or replayed.
  2. Mailbox rule and sign-in monitoring. Automatically investigating new inbox forwarding rules and unusual sign-in patterns, the kind of correlation covered in our earlier piece on overlooked Microsoft Defender features, catches the exact persistence technique BEC relies on before it goes unnoticed for weeks.
  3. Out-of-band verification for payment and vendor changes. Any request to change bank details, approve an unusual payment, or action an urgent transfer should be verified by phone, using a number already on file rather than one provided in the email itself. This single step defeats the majority of both BEC and VEC attempts regardless of how convincing the email looks.
  4. Domain authentication. Properly configured SPF, DKIM, and DMARC records make it significantly harder for attackers to spoof your domain convincingly, and give you visibility into who is sending email that claims to be from your organisation.
  5. Ongoing, realistic training and simulation. One annual training session doesn't hold up against attacks this personalised. Regular, varied simulations, covering email, and increasingly voice-based pretexts, build the habit of pausing on unusual requests rather than relying on staff remembering a slide from months ago.

Old Approach vs What Actually Works

Relying on Why it falls short against BEC
Spam filters and antivirus BEC emails often contain no malicious file or link to detect
SMS-based MFA Can be relayed through real-time phishing proxies
"Spot the phishing email" training alone Modern lures are AI-written and free of the usual red flags
Trusting requests from known contacts Vendor and mailbox compromise make "known" no longer synonymous with "safe"
Annual security awareness sessions Attack techniques and channels evolve faster than a yearly refresh

 

Frequently Asked Questions

What exactly is business email compromise? BEC is a type of cyber-enabled fraud where an attacker impersonates a trusted party, such as an executive, colleague, or vendor, usually via a spoofed or genuinely compromised email account, to trick an employee into transferring money, changing payment details, or disclosing sensitive information.

Why don't our existing email security tools stop it? Most email security tools are built to detect malicious attachments and links. A large proportion of BEC emails contain neither; they rely entirely on convincing text and a plausible sender identity, which is a much harder pattern for automated filtering to catch reliably.

Does multi-factor authentication stop BEC? It significantly reduces account takeover risk, but standard SMS or app-based MFA can still be bypassed through real-time phishing proxies. Phishing-resistant methods like FIDO2 security keys close that gap far more effectively.

How much does BEC actually cost businesses? IBM's research puts the average cost of a BEC-related breach at $4.89 million, making it the second most expensive breach type after only more complex, multi-stage attacks. Reported losses in the US alone reached $3.05 billion in 2025 according to FBI IC3 data.

Can Protrona help us assess our exposure to this kind of attack? Yes. Our security consultancy services include reviewing email authentication, mailbox rule configuration, and payment verification processes, and we run phishing defence and human risk reduction programmes tailored to how your teams actually work.

 


Strengthen your defences against social engineering

BEC succeeds by exploiting process gaps and trust, not just inboxes. A short review of your current email authentication, verification procedures, and staff training will show you exactly where those gaps sit. Get in touch to arrange one.