In 2025, the FBI's Internet Crime Complaint Center logged 24,768 business email compromise complaints and $3.05 billion in reported losses, and that figure only counts what victims actually reported. Meanwhile, Microsoft's own Q1 2026 threat data shows traditional malware delivery has dropped to just 5 to 6% of malicious email payloads, while credential phishing now accounts for roughly 94% of them.
Put those two facts together and the picture is clear: attackers aren't breaking in through your defences. They're being let in through your inbox.
For years, email security was built around a simple assumption: the threat is a malicious file or link, so scan every attachment and block every bad URL. That model worked well enough that attackers have largely abandoned it.
Modern endpoint detection, sandboxing, and email filtering have made malware-based attacks expensive to run and easy to catch. Social engineering carries none of that risk. A convincing email asking someone to action a payment, reset a password, or reply with sensitive information contains no malicious code at all, which means there's often nothing for a traditional security tool to flag.
Generative AI has removed the last obstacle that made this harder: quality. Attackers no longer need fluent English or insider knowledge of how a business operates. AI tools can now scrape public information about a company and its staff and draft technically flawless, highly targeted emails in seconds. IBM's 2025 Cost of a Data Breach Report found that 37% of AI-involved breaches included AI-generated phishing content, a share that is expected to keep climbing through 2026.
The channel is also expanding beyond email. Mandiant's M-Trends 2026 report, based on over 500,000 hours of incident response work, found voice phishing has overtaken email phishing as the top social engineering vector in cloud-related compromises, reaching 23% of confirmed initial access methods compared to just 6% for email. A convincing voice clone now needs as little as three seconds of audio, meaning a CEO's conference keynote or a CFO's earnings call is enough raw material for an attacker to work with.
Business email compromise sits at the sharp end of this shift, and a few structural reasons explain why it continues to work even against businesses that consider themselves security-conscious.
It rarely needs malware. Many BEC attacks involve nothing but a well-written email sent from a spoofed domain or a genuinely compromised, legitimate mailbox. There's no payload for antivirus or endpoint detection to catch, because there isn't one.
It targets people outside the obvious risk group. It's tempting to assume finance and executive staff are the primary targets, but 77% of BEC attacks target employees outside of finance or executive roles, often because those employees have less training and less reason to expect a scrutinised request.
It exploits trusted relationships, not just internal ones. Vendor Email Compromise, where an attacker compromises a supplier's or partner's legitimate email account and inserts fraudulent payment instructions into a genuine ongoing conversation, rose 66% in the first half of 2024 alone. The email genuinely comes from a trusted contact, which is exactly what makes it so effective.
It's often deliberately low-value and high-volume. Gift card scams accounted for 37.9% of BEC incidents in one recent quarter precisely because small, low-scrutiny requests are easier to approve without a second thought than a six-figure wire transfer. The average BEC wire transfer request sits at around $24,586, a figure often chosen specifically to stay under thresholds that would trigger additional approval.
It persists quietly through mailbox rules. Once an account is compromised, attackers frequently create hidden inbox rules that auto-forward or auto-delete specific emails, allowing them to monitor a live conversation (such as an ongoing invoice negotiation) for weeks without the account owner noticing anything unusual.
Stopping BEC means shifting focus away from scanning for malicious files and toward validating identity, intent, and process. These five measures address the mechanics of BEC directly, rather than relying on staff to simply "spot the phishing email."
| Relying on | Why it falls short against BEC |
|---|---|
| Spam filters and antivirus | BEC emails often contain no malicious file or link to detect |
| SMS-based MFA | Can be relayed through real-time phishing proxies |
| "Spot the phishing email" training alone | Modern lures are AI-written and free of the usual red flags |
| Trusting requests from known contacts | Vendor and mailbox compromise make "known" no longer synonymous with "safe" |
| Annual security awareness sessions | Attack techniques and channels evolve faster than a yearly refresh |
What exactly is business email compromise? BEC is a type of cyber-enabled fraud where an attacker impersonates a trusted party, such as an executive, colleague, or vendor, usually via a spoofed or genuinely compromised email account, to trick an employee into transferring money, changing payment details, or disclosing sensitive information.
Why don't our existing email security tools stop it? Most email security tools are built to detect malicious attachments and links. A large proportion of BEC emails contain neither; they rely entirely on convincing text and a plausible sender identity, which is a much harder pattern for automated filtering to catch reliably.
Does multi-factor authentication stop BEC? It significantly reduces account takeover risk, but standard SMS or app-based MFA can still be bypassed through real-time phishing proxies. Phishing-resistant methods like FIDO2 security keys close that gap far more effectively.
How much does BEC actually cost businesses? IBM's research puts the average cost of a BEC-related breach at $4.89 million, making it the second most expensive breach type after only more complex, multi-stage attacks. Reported losses in the US alone reached $3.05 billion in 2025 according to FBI IC3 data.
Can Protrona help us assess our exposure to this kind of attack? Yes. Our security consultancy services include reviewing email authentication, mailbox rule configuration, and payment verification processes, and we run phishing defence and human risk reduction programmes tailored to how your teams actually work.
BEC succeeds by exploiting process gaps and trust, not just inboxes. A short review of your current email authentication, verification procedures, and staff training will show you exactly where those gaps sit. Get in touch to arrange one.