{
  "id": 660580,
  "title": "Business Email Compromise: The Fraud That Doesn't Break Any Encryption",
  "url": "https://urgent.news/2026/08/12/business-email-compromise-the-fraud-that-doesnt-break-any-encryption",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-12T12:18:18.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/havenmessenger/business-email-compromise-the-fraud-that-doesnt-break-any-encryption-4h56"
  },
  "original_language": "en",
  "account": "Business email compromise, or BEC, is the most frequently reported cybercrime, surpassing ransomware and credential theft in losses tracked by the FBI. This attack occurs due to a gap between an email appearing legitimate and actually being so. BEC has two forms - account takeover and domain impersonation. In account takeover, attackers steal credentials or session tokens to log into an email account and send fraudulent messages. SPF, DKIM, and DMARC protocols fail to detect these attacks as they appear authentic. In domain impersonation, attackers create a lookalike domain and impersonate a trusted sender. DMARC enforcements at p=reject can prevent these attacks, but they don't protect against account takeover BEC. Both types require patience, timing, and a payment process with no verification steps. Process controls, like out-of-band verification, dual control on wire transfers, and training staff to recognize patterns, can prevent BEC attacks. Phishing-resistant multi-factor authentication does not stop account takeover BEC as attackers can steal session tokens, which bypass the need to re-authenticate.",
  "summary": "Business email compromise, usually shortened to BEC, has been the largest reported category of cybercrime loss tracked by the FBI's Internet Crime Complaint Center for years running, ahead of ransomware and ahead of credential theft. It's also one of the least technically sophisticated attacks in active use. There's often no malware, no zero-day, no cracked cipher. The entire attack lives in the…",
  "key_points": [],
  "editors_take": "The prevalence of business email compromise highlights the limitations of current email security protocols in preventing sophisticated attacks that exploit human vulnerabilities rather than technical weaknesses.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}