logo

Business Email Compromise (BEC)

ID: a517e320-6f79-56d4-9e26-57011bdfb5a1

STIX ID: report--a517e320-6f79-56d4-9e26-57011bdfb5a1

Feed Name: Arctic Wolf

Threat Score
45/100

Date Published: 2025-09-30

Date Updated: 2026-07-26

Author: Arctic Wolf

...
...

Business Email Compromise (BEC) is a targeted social‑engineering cybercrime in which attackers impersonate executives, vendors, or legal representatives—or compromise real email accounts—to trick organizations into transferring funds or disclosing sensitive data. The report summarizes BEC attack types (CEO fraud, account compromise/EAC, attorney impersonation, false invoices, data theft), the typical lifecycle (reconnaissance, compromise/impersonation, social engineering, execution/exfiltration), business impacts (direct financial loss, operational disruption, reputational and regulatory consequences), and layered defenses (MFA, DMARC/SPF/DKIM, transaction verification processes, security awareness training, and incident response planning).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.