TechKnowSurge
VideoSecurityFree

Business Email Compromise (BEC)

Business email compromise (BEC) is an attack where a threat actor impersonates a trusted colleague or internal contact via email to deceive employees within an organization.

Complete this video to capture a CTF flag worth 1 point.

About this video

Business email compromise (BEC) is an email-based impersonation attack in which a threat actor poses as a trusted person inside an organization to deceive another employee. A common scenario involves the attacker sending a message that appears to come from someone in a finance or leadership role, using that false identity to manipulate the recipient into taking a harmful action, such as transferring funds or disclosing sensitive information. The attack can originate from an actual hijacked email account, but it does not have to — spoofing a sender name or reply-to address is a straightforward technique that requires minimal effort from the attacker. The terminology around BEC can be misleading, since the word "compromise" implies that an email account has been breached. In reality, the compromise referred to is the attempt itself — an effort to undermine trust and security within an organization by exploiting the credibility of internal relationships. Whether the attacker uses a genuinely hijacked account or simply fabricates the sender details, the goal and the danger remain the same: convincing an employee that a fraudulent message is legitimate communication from a known colleague.

What you'll learn

What's covered

Business Email Compromise (BEC)

Key terms

Business Email Compromise
BEC
An attack where a threat actor impersonates a trusted person within an organization via email to deceive employees, often by spoofing or compromising a legitimate email address.
Spoofing
An attack where an adversary impersonates a trusted entity by falsifying data such as an IP address or email address.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Threat Actor
An individual or group responsible for a security incident or attack.
Impersonation
A social engineering tactic in which an adversary poses as a trusted individual or authority figure to gain a victim's confidence and compliance.

Topics

Business Email Compromise Email Impersonation Social Engineering Phishing Cybersecurity Threat Actors

Transcript

Another type of impersonation is through email. We call it a business email compromise, or BEC.

Here's an example of a business email compromise. Maybe the adversary is sending out a message to the victim saying, "Hey, Jane." So Jane is the victim here. This is Susan from finance. This email is impersonating Susan from finance, and probably even has Susan's email address up in the reply-to.

I can tell you I'm not a big fan of this term business email compromise, because it has the word compromise in the name. What that sounds like is that the email has been compromised. So the adversary gets a hold of Susan's email address and then sends out this email on behalf of Susan to Jane, which could very well be the case, and that would be considered a business email compromise. But it's really easy to fake somebody's message — the Susan that's written in there, or the reply-to address that's in there. That's not difficult to do at all. So it doesn't necessarily need to stem from a compromise.

But I suppose we could just think of the compromise as being that somebody is trying to compromise using business email. It's an attempt to compromise by impersonating somebody within the company and sending that message out to somebody else within the company through email.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →