Back
Sep 8, 2026

Business Email Compromise: The Most Common Breach We See (And What to Do About It)

The call usually comes after something has already happened: bad actors got access to email tokens and started sending messages on behalf of employees, usually something related to finance like fake invoices to customers, wire transfer requests, or vendor payment redirections. CFOs and CEOs are often specifically targeted.

Business email compromise is the most common security incident that drives companies to engage us, and while it’s neither sophisticated nor novel, it’s incredibly common because email infrastructure and human nature combine to create fundamental vulnerabilities that most organizations don’t address until after an incident.

The Pattern We See

A typical scenario that we see involves the following sequence:

  • Credential compromise. An employee clicks a phishing link, enters credentials, or has their session token stolen. Sometimes it’s a password that’s been reused across services and appeared in a breach elsewhere.

  • Token access. The attacker gets access to the employee’s email without needing ongoing password access. Modern email systems use tokens for session persistence. Steal the token, access the mailbox.

  • Reconnaissance. The attacker reads email to learn who handles finances, understand invoicing patterns, and identify pending deals or payments.

  • Impersonation. The attacker sends emails that appear to come from legitimate employees, using real email threads, referencing real invoices, and redirecting payments to accounts they control.

  • Discovery. Eventually something doesn’t add up: a customer asks about a strange payment request, an employee notices sent messages they didn’t write, or the attacker’s modifications to mailbox rules get discovered.

By this point, damage has often occurred: payments have been misdirected, customer trust has been impacted, and the company has to figure out how to respond, disclose, and prevent recurrence.

Why This Keeps Happening

BEC works because email was never designed for the security requirements modern businesses place on it.

Token-based sessions are vulnerable. Session tokens can be stolen through various means, and once stolen, they provide access without needing the user’s password. Many MFA implementations don’t protect against token theft.

Email looks authoritative. When an email comes from a real employee’s actual mailbox, recipients have no good way to verify it’s really that person.

Financial processes trust email. Wire transfers, invoice approvals, payment redirections often rely on email requests. People are trained to respond to urgent requests from known contacts.

The reconnaissance is real. Because attackers read actual email threads, their fraudulent requests reference real deals, real invoice numbers, real vendor relationships. Context makes the fraud convincing and AI makes gathering and using context much more efficient for attackers.

What We Find When We Arrive

When a company engages us after a BEC incident, we often discover this wasn’t the first problem. It was the first problem big enough to force action. Well-meaning employees and executives tell us:

  • “We’ve had some suspicious emails before, but nothing major;”
  • “There was that weird login from another country, but IT looked at it;” or
  • “We had to reset some passwords a few months ago after something strange;”

These near-misses were resolved at the surface level using backups, password resets, and other quick fixes that allow business to continue.

BEC is often the incident that finally impacts organizations drastically enough, whether through fake invoices going out, ransomware reaching their infrastructure, or their customers noticing something wrong with the company’s products and services or in their interactions and communications. At that point, there’s no avoiding it.

Customers and partners demand information and accountability and “we’re going to try harder” isn’t an acceptable response. They need credible plans and ongoing updates and evidence demonstrating your security improvements.

The Response

Immediate response to BEC requires several tracks simultaneously:

Containment. Revoke all active sessions for affected accounts. Reset credentials. Review mailbox rules for attacker-created forwarding. Identify all accounts that may be compromised.

Investigation. Understand what was accessed, when access started, what was sent from the compromised accounts. Review sent mail, deleted items, and any rules created by the attacker.

Get a security assessment

Find out where your exposure is before an incident forces the question.

Get a security assessment →

Notification. Determine who received fraudulent communications. Alert customers, vendors, and partners who may have received fake requests. This is where legal obligations come in.

Technical remediation. Address the vulnerabilities that allowed the compromise. This often means implementing protections such as phishing-resistant MFA that aren’t always implemented with email platforms but should be for most businesses. For many companies, enhanced detection, response and monitoring capabilities provided by email security gateways and managed service providers are also called for.

Prevention That Actually Works

The controls that prevent BEC aren’t mysterious, but most organizations just haven’t implemented them.

Phishing-resistant MFA. Hardware security keys or passkeys that can’t be phished. Token theft becomes much harder when the authentication mechanism is bound to specific devices.

Conditional access policies. Restrict email access based on device compliance, location, and risk signals. An unfamiliar device logging into email from an unfamiliar location should trigger additional verification or block access.

Email authentication. DMARC, DKIM, and SPF configured correctly. These don’t prevent all impersonation, but they make certain spoofing techniques harder.

Monitoring and alerting. 24/7 monitoring that can detect suspicious login patterns, mailbox rule changes, and unusual sending behavior. When someone accesses email from a new location at 3am and creates a forwarding rule, that should trigger an alert.

Financial process controls. Out-of-band verification for payment changes. If someone emails asking to change wire instructions, you call them on a known number to confirm. Email alone shouldn’t be sufficient authorization.

The Investment Trigger

BEC is often what causes companies to invest in security beyond the minimum. The executive team comes to intimately understand the business risk and the abstract concern becomes concrete.

The companies that handle this well use the incident as a catalyst: they respond to the immediate problem while also building a security program including detection and response capabilities, proper email security controls, and incident response procedures that appropriately mitigate their risks.

The companies that handle it poorly reset their accounts and try to smooth over customer and partner concerns. Until the next incident.

BEC is common because email wasn’t designed for how businesses use it today. The controls that prevent it aren’t mysterious. They’re just not implemented until after the first major incident.


Need help with an active incident — or preventing the next one?

Our CISOs have handled BEC, ransomware, and breaches. We can help you respond or prepare.

Let's Connect →