Business email compromise (BEC) is an attack where a threat actor impersonates a trusted colleague or internal contact via email to deceive employees within an organization.
Business Email Compromise (BEC)
Another type of impersonation is through email. We call it a business email compromise, or BEC.
Here's an example of a business email compromise. Maybe the adversary is sending out a message to the victim saying, "Hey, Jane." So Jane is the victim here. This is Susan from finance. This email is impersonating Susan from finance, and probably even has Susan's email address up in the reply-to.
I can tell you I'm not a big fan of this term business email compromise, because it has the word compromise in the name. What that sounds like is that the email has been compromised. So the adversary gets a hold of Susan's email address and then sends out this email on behalf of Susan to Jane, which could very well be the case, and that would be considered a business email compromise. But it's really easy to fake somebody's message — the Susan that's written in there, or the reply-to address that's in there. That's not difficult to do at all. So it doesn't necessarily need to stem from a compromise.
But I suppose we could just think of the compromise as being that somebody is trying to compromise using business email. It's an attempt to compromise by impersonating somebody within the company and sending that message out to somebody else within the company through email.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →