How phishing opens the door to business email compromise
ID: 8e1caf8c-055d-5056-8e3c-10e63ce747dd
STIX ID: report--8e1caf8c-055d-5056-8e3c-10e63ce747dd
Feed Name: Expel Blog
### Executive summary This briefing explains how phishing and business email compromise (BEC) relate—phishing often provides the initial access while BEC uses targeted, context-aware social engineering to cause fraudulent transactions (notably SOC-observed attempts targeting Workday payroll and direct deposit). It emphasizes key BEC characteristics (impersonation of trusted insiders, contextualized messaging, urgency), notes that AI is making deception more convincing, and recommends employee awareness and SOC/defensive measures to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
