Reviewed September 2026FBI + CISA informed

Stop business email compromise by protecting both the mailbox and the business process attackers are trying to manipulate.

BEC succeeds when an attacker can convincingly impersonate a trusted person, compromise a real mailbox, exploit a weak payment or payroll process, or abuse a legitimate email thread. Email filtering matters, but the strongest program assumes some fraudulent messages will reach a human and makes high-risk transactions independently verifiable.

The FBI describes BEC schemes that use spoofing, spearphishing, compromised accounts, and malware to manipulate business communications. CISA recommends layered email and identity protections including DMARC, SPF, DKIM, strong authentication, attachment controls, and user-focused defenses.

Threat model

Model the transaction the attacker wants, not only the phishing email.

Common BEC outcomes include fraudulent wire transfers, altered vendor banking instructions, payroll diversion, gift-card purchases, fraudulent invoices, sensitive tax or payroll data disclosure, and account takeover used to continue a trusted conversation. Attackers may impersonate an executive from a look-alike domain, compromise a vendor, take over an employee mailbox, or insert themselves into an existing thread.

Map the business workflows that can move money or sensitive information because of an email instruction. Identify who can request the transaction, who can approve it, which systems perform it, what supporting evidence is required, and whether a single compromised mailbox can defeat the entire process.

High-risk workflows deserve stronger independent verification than ordinary email. The control objective is simple: possession of a believable message or even a real mailbox should not be sufficient to change where money or sensitive information goes.

Business-process controls

Verify changes through a channel the email does not control.

Banking changes

Require independent verification of new or changed payment instructions using previously established contact information—not the phone number contained in the change request. Record who performed the verification and what source was used.

Dual authorization

Use separation of duties for high-value wires, payroll changes, vendor setup, and unusual payments. The second approver should evaluate the transaction, not simply click approval because the first person already did.

Out-of-pattern review

Escalate changes in account country, payment timing, amount, beneficiary, urgency, secrecy, or communication style. A legitimate request can still be risky when it differs materially from the established business relationship.

Vendor enrollment

Establish trusted vendor contact and banking data during onboarding. Make later changes follow a stronger workflow than ordinary invoice processing so a compromised vendor mailbox cannot silently replace account details.

Identity protection

Make mailbox takeover harder and recovery more trustworthy.

Require strong multi-factor authentication for workforce email and especially privileged administration. For higher-risk users and administrators, prefer phishing-resistant authentication where supported. Protect authentication recovery, help-desk reset, device registration, and emergency accounts because attackers often pivot to the weakest recovery path when primary authentication is hardened.

Separate administrative accounts from routine email and browsing. Restrict tenant-wide roles, monitor privileged sign-ins, and review role assignment changes. A compromised global administrator can weaken authentication policy, create persistence, change forwarding, or suppress evidence across many mailboxes.

Disable or tightly control legacy authentication that bypasses modern controls. Revoke sessions and tokens during suspected compromise instead of assuming a password reset ends attacker access.

Domain authentication

Use SPF, DKIM, and DMARC to reduce spoofing of domains you control.

Inventory every legitimate service that sends mail for the organization before enforcing policy. Configure SPF to authorize intended sending infrastructure, DKIM to cryptographically sign appropriate messages, and DMARC to establish alignment, policy, and reporting. Move toward an enforcement policy after monitoring legitimate senders and correcting failures. DMARC reduces abuse of your own domain but does not prevent an attacker from registering a visually similar domain or compromising a legitimate mailbox.

Look-alike domains

Monitor high-value brand and executive impersonation patterns where proportionate. Train users to evaluate unexpected requests through known workflows rather than relying on visual inspection of a sender address alone.

External-message cues

Use clear external-sender indicators and protect them from easy spoofing. Cues are supplemental controls: users can become habituated, and compromised internal accounts will not carry an external label.

Mailbox and tenant controls

Limit the persistence and concealment techniques used after account takeover.

Forwarding and inbox rules

Detect unexpected external forwarding, suspicious rules that hide replies or financial messages, and rapid changes after unusual sign-ins. Attackers commonly use mailbox rules to observe conversations and suppress warning messages.

Application consent

Review OAuth and application grants that can read mail, send mail, or maintain access without an interactive sign-in. Restrict high-impact consent to approved administrators and investigate newly granted access during account-compromise response.

Attachment and link controls

Use malware inspection, safe-link or reputation controls, file-type restrictions, macro policy, and browser isolation where appropriate. Keep controls aligned to actual business workflows so users do not create unmanaged bypasses.

Executive and finance protection

Apply stronger monitoring and verification to accounts involved in payments, payroll, executive communication, legal matters, and vendor management because compromise of these users creates disproportionate fraud opportunities.

Detection

Correlate email behavior with identity and transaction behavior.

Incident response

Move immediately when money or mailbox access may be compromised.

If a fraudulent transfer may have occurred, contact the financial institution immediately and use established fraud-recovery procedures. The FBI directs victims to report BEC through the Internet Crime Complaint Center. Preserve relevant email, headers, authentication logs, payment records, mailbox rules, application grants, and communications while operational response continues.

For suspected mailbox takeover, contain the identity, revoke sessions and tokens, reset or replace authentication factors as appropriate, review privileged roles and recovery settings, remove malicious rules and forwarding, review delegated access and application consent, and investigate the period before detection for additional fraud or data exposure.

Notify affected vendors and internal stakeholders through trusted contact paths when an attacker may have sent fraudulent instructions from a real account. Correcting the technical compromise does not automatically stop downstream fraud that is already in motion.

90-day implementation

Build the fraud controls and mailbox controls together.

Days 1–30

Inventory payment and payroll workflows, high-risk mailboxes, sender domains, privileged roles, forwarding settings, authentication posture, and vendor-change procedures. Identify any transaction a single email can authorize.

Days 31–60

Implement independent verification, dual authorization where needed, stronger MFA, domain authentication improvements, forwarding controls, consent governance, and high-value mailbox monitoring.

Days 61–90

Run a BEC exercise, test financial escalation contacts, measure suspicious-rule and payment-change detections, review vendor procedures, and close gaps found in identity recovery and incident handoffs.

Continue learning

Related guides after Business Email Compromise & Email Security

Follow the next implementation topic without returning to search.

Put this guide to work

Turn Business Email Compromise & Email Security Program Guide | Zeph Tech into a decision-ready next step.

Use the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.