Business Email Compromise: The Fraud That Doesn't Break Any Encryption
Business email compromise, usually shortened to BEC, has been the largest reported category of cybercrime loss tracked by the FBI's Internet Crime Complaint Center for years running, ahead of ransomware and ahead of credential theft. It's also one of the least technically sophisticated attacks in active use. There's often no malware, no zero-day, no cracked cipher. The entire attack lives in the…
Business email compromise, or BEC, is the most frequently reported cybercrime, surpassing ransomware and credential theft in losses tracked by the FBI. This attack occurs due to a gap between an email appearing legitimate and actually being so. BEC has two forms - account takeover and domain impersonation. In account takeover, attackers steal credentials or session tokens to log into an email account and send fraudulent messages.
SPF, DKIM, and DMARC protocols fail to detect these attacks as they appear authentic. In domain impersonation, attackers create a lookalike domain and impersonate a trusted sender. DMARC enforcements at p=reject can prevent these attacks, but they don't protect against account takeover BEC. Both types require patience, timing, and a payment process with no verification steps.
Process controls, like out-of-band verification, dual control on wire transfers, and training staff to recognize patterns, can prevent BEC attacks. Phishing-resistant multi-factor authentication does not stop account takeover BEC as attackers can steal session tokens, which bypass the need to re-authenticate.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.