Threat Intelligence

Business Email Compromise: The Attack That Needs No Malware

Business email compromise is unusual among major cyber threats in that it frequently involves no malicious software whatsoever. An attacker gains access to a mailbox, or convincingly impersonates someone who has one, and persuades a person to send money or data to the wrong place. Because nothing technically malicious occurs, most security tooling has nothing to detect.

Business Email Compromise: The Attack That Needs No Malware

How a BEC operation is structured

  1. Access or impersonation — the attacker either compromises a mailbox, usually through phishing or credential reuse, or registers a lookalike domain that reads correctly at a glance.
  2. Reconnaissance — they read. Who authorises payments, how invoices are worded, which suppliers are active, when the finance lead travels, what the internal tone sounds like.
  3. Positioning — mail rules are created to hide replies or auto-forward specific threads, so the legitimate owner does not notice the conversation happening in their name.
  4. The request — a payment redirect, an urgent transfer, a change of bank details, or a request for employee data. Timed to coincide with genuine activity so it appears expected.
  5. Pressure — urgency, authority and confidentiality are applied together to discourage verification.
  6. Extraction — funds move quickly through intermediary accounts, which is why the recovery window is measured in hours.

Why it defeats technical controls

The message frequently comes from a genuine, authenticated mailbox belonging to a real colleague or supplier. It passes authentication checks because it is authentic. There is no attachment, no link, and no payload to analyse.

Email authentication standards help considerably against outright spoofing of your domain, and they should be deployed. They do not help when the account is genuinely compromised, or when the attacker uses a similar domain they legitimately control and have configured correctly.

Attackers read email quietly before acting
Attackers read email quietly before acting

The variants worth naming

  • Executive impersonation — an urgent, confidential request appearing to come from senior leadership.
  • Supplier invoice fraud — a real supplier relationship targeted with altered bank details, often the most costly variant because the amounts are routine and expected.
  • Payroll diversion — an employee's salary destination changed through a plausible HR request.
  • Data-focused BEC — requesting employee tax or identity data rather than money, which then feeds identity fraud.
  • Conversation hijacking — inserting into an existing legitimate email thread, which is highly convincing because the prior context is real.

Controls that genuinely work

  1. Out-of-band verification for payment changes. Any change to bank details is confirmed by calling a number already on file — never a number supplied in the request. This single control defeats most BEC.
  2. Require dual authorisation above a threshold, with the second approver independent of the first.
  3. Deploy phishing-resistant MFA so mailbox compromise becomes substantially harder.
  4. Alert on mailbox rule creation, especially rules that forward externally or move messages to obscure folders.
  5. Publish and enforce email authentication for your own domain, and monitor for lookalike domain registrations.
  6. Flag external senders clearly in the mail client so a lookalike domain is visibly external.
  7. Train finance and HR specifically, with realistic scenarios rather than generic awareness content.
  8. Rehearse the response: if a payment is made, the first hours determine whether funds can be recalled, so know in advance who calls the bank and who reports it.
Out-of-band verification is the control that works
Out-of-band verification is the control that works

If it happens

Speed matters more than analysis. Contact the bank immediately to attempt recall, report to the relevant national fraud or law-enforcement body, and preserve the mailbox evidence including sign-in logs and mail rules before anything is cleaned up.

Then establish scope properly. A compromised mailbox is rarely used once, and the same access may have been used to target other suppliers, customers or colleagues.

Related from TechBiz Security

Sources & further reading

Frequently asked questions

What is business email compromise?
BEC is a fraud in which an attacker uses a compromised or impersonated email account to persuade someone to transfer money or sensitive data. It typically involves no malware, which is why conventional security tooling frequently does not detect it.
Why do email security tools miss BEC?
Because the message is often genuinely authentic — sent from a real compromised mailbox, with no attachment or link to analyse. There is no technical indicator of compromise in the message itself, only a socially engineered request.
What is the single most effective control against BEC?
Out-of-band verification of any change to payment details, using a phone number already held on file rather than one supplied in the request. It breaks the fraud regardless of how convincing the email is.
Does DMARC stop business email compromise?
Email authentication prevents attackers from spoofing your own domain, which is valuable and worth deploying. It does not help when a genuine mailbox is compromised, or when the attacker uses a similar-looking domain that they control and have configured correctly.

Related reading

0 comments

Leave a comment

Comments are moderated before appearing.