logo

Business Email Compromise Detection

ID: 62df7e6d-3fe2-5822-8014-1b8729d7dbf1

STIX ID: report--62df7e6d-3fe2-5822-8014-1b8729d7dbf1

Feed Name: ReliaQuest Blog

Threat Score
70/100

Date Published: 2024-03-12

Date Updated: 2026-04-29

...
...

ReliaQuest documents a 246% increase in business email compromise (BEC) attempts over the past year and provides technical guidance to detect and mitigate BEC, including KQL correlation queries for session replay detection, visual authentication-sequence analysis, and linking suspicious sessions to high-risk actions (e.g., inbox rule creation). The report includes a case study of inbox-rule-based defense evasion, discusses common false positives (VPNs, proxies, mobile networks), warns that GenAI and AITM techniques will accelerate BEC, and recommends stronger admin account separation, advanced MFA (e.g., FIDO2), conditional access tuning, transaction verification, and blocking newly registered domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.