Business email compromise (BEC)—also known as email account compromise (EAC)—is one of the most financially damaging online crimes. It exploits the fact that so many of us rely on email to conduct business—both personal and professional.
In a BEC scam, criminals send an email message that appears to come from a known source making a legitimate request, like in these examples:
- A vendor your company regularly deals with sends an invoice with an updated mailing address.
- A company CEO asks her assistant to purchase dozens of gift cards to send out as employee rewards. She asks for the serial numbers so she can email them out right away.
- A homebuyer receives a message from his title company with instructions on how to wire his down payment.
Versions of these scenarios happened to real victims. All the messages were fake. And in each case, thousands—or even hundreds of thousands—of dollars were sent to criminals instead.
A scammer might:
- Spoof an email account or website. Slight variations on legitimate addresses (firstname.lastname@example.org vs. email@example.com) fool victims into thinking fake accounts are authentic.
- Send spearphishing emails. These messages look like they’re from a trusted sender to trick victims into revealing confidential information. That information lets criminals access company accounts, calendars, and data that gives them the details they need to carry out the BEC schemes.
- Use malware. Malicious software can infiltrate company networks and gain access to legitimate email threads about billing and invoices. That information is used to time requests or send messages so accountants or financial officers don’t question payment requests. Malware also lets criminals gain undetected access to a victim’s data, including passwords and financial account information.
If you or your company fall victim to a BEC scam, it’s important to act quickly:
Public Service Announcements from IC3
04.06.2020 Cyber Criminals Conduct Business Email Compromise Through Exploitation of Cloud-Based Email Services, Costing U.S. Businesses More Than $2 Billion
Cyber criminals are targeting organizations that use popular cloud-based email services to conduct BEC scams.
09.10.2019 Business Email Compromise: The $26 Billion Scam
Business email compromise/email account compromise is a sophisticated scam that targets both businesses and individuals who perform legitimate transfer-of-funds requests.
10.24.2018 Business Email Compromise: Gift Cards
The Internet Crime Complaint Center (IC3) received an increase in the number of BEC complaints requesting victims purchase gift cards.
06.11.2018 Business Email Compromise Contributes to Large-Scale Business Losses Nationwide
BEC schemes have cost victims billions of dollars in fraud losses over the last five years. This activity is a pervasive threat with significant financial losses and a considerable global impact.
Related FBI News and Multimedia
04.13.2020 FBI Warns of Advance Fee and BEC Schemes Related to Procurement of PPE and Other Supplies During COVID-19 Pandemic
The FBI is warning government and health care industry buyers of rapidly emerging fraud trends related to procurement of personal protective equipment (PPE), medical equipment such as ventilators, and other supplies or equipment in short supply during the current COVID-19 pandemic.
04.06.2020 FBI Anticipates Rise in Business Email Compromise Schemes Related to the COVID-19 Pandemic
There has been an increase in BEC frauds targeting municipalities purchasing personal protective equipment or other supplies needed in the fight against COVID-19.
A leader of a business email compromise ring that stole more than $120 million from two American companies is spending time behind bars. Learn how to protect yourself from this growing crime.
The FBI worked with partner agencies domestically and in multiple countries around the world in a large-scale, coordinated effort to dismantle international business email compromise (BEC) schemes.
The FBI partnered with domestic and international law enforcement agencies on Operation WireWire, a large-scale, coordinated effort to dismantle business e-mail compromise schemes.
The latest evolution of the sophisticated business e-mail compromise scam targets businesses for access to sensitive tax-related data.
The FBI says criminals put a holiday twist on the methods they use to scam you online during this time of year.
FBI Chicago has important information for area business owners who find themselves the victim of a Business E-mail Compromise (BEC) scam.
The organized crime groups that perpetrate the financial cyber fraud called business e-mail compromise have victimized companies and organizations around the world.
Public service announcement warning of the dangers of business e-mail compromise scams (BECs).
BEC scams involves the compromise of legitimate business and e-mail accounts for the purpose of conducting unauthorized wire transfers.
A guide providing best practices on what to do to safeguard the email system of a business from being compromised.
A sophisticated scam is costing companies worldwide millions of dollars.