Business email compromise, abbreviated BEC, is a fraud in which a criminal gains control of, or convincingly impersonates, an email account that a business or individual already trusts, and uses it to redirect a legitimate transfer of funds. The Internet Crime Complaint Center's own definition is that BEC "is a sophisticated scam targeting both businesses and individuals performing a transfer of funds," and that it "is frequently carried out when a subject compromises legitimate business e-mail accounts through social engineering or computer intrusion techniques resulting in an unauthorized transfer of funds." The FBI's public service announcements pair the term with email account compromise, writing it as BEC/EAC, to make clear that a personal mailbox counts too. What separates BEC from a generic phishing email is that nothing about the underlying transaction is invented. The money was going to move; the instruction that moved it came from the wrong person.
Business Email Compromise (BEC)
Business email compromise is a fraud in which a criminal takes over or convincingly imitates a legitimate email account and uses it to redirect a payment that was going to happen anyway. The FBI treats it as one crime pattern with many settings, from a closing table to a vendor invoice to a payroll portal.
Quick Summary
- The FBI's Internet Crime Complaint Center defines it as "a sophisticated scam targeting both businesses and individuals performing a transfer of funds," carried out by compromising legitimate business email accounts through social engineering or computer intrusion.
- The distinguishing feature is that the payment is real. The invoice, the closing, the payroll run or the supplier relationship all exist; only the destination account has been changed.
- It is the umbrella over several frauds that look unrelated from the outside, including diverted real estate closing wires and redirected paychecks.
- Not every variant asks for money. IC3 records versions that request employees' personal information or W-2 forms, which are then used to set up the next fraud.
- The single most effective control is verifying any change of banking details on a second channel, using contact details already held rather than the ones in the message.
Definition
Advanced Explanation
The mechanism is access first, instruction second. A criminal reaches a mailbox, either by stealing credentials through a convincing login page or by intruding on the account some other way, and then reads. What follows is patient rather than technical: learning who signs off on payments, how invoices are worded, when a closing or a payroll run is due, which vendor is expecting money. The fraudulent message, when it arrives, is written in the voice of the account it came from and often continues a real email thread. In many cases the account is not compromised at all and the sender has simply registered a domain that differs by one character, which is why IC3's prevention list asks readers to view full email extensions and to check the sender address on a phone, where it is usually hidden.
The species look unrelated and are counted as one crime. A buyer receives revised wire instructions from what appears to be the title company on the day of closing. An accounts-payable clerk receives an invoice from a long-standing supplier with updated banking details. An employee's self-service payroll account is reached and the direct deposit routing is changed. A finance officer receives a note from the chief executive asking for an urgent transfer and discretion about it. The FBI classifies all of these under BEC, which is why the closing-wire case on this site is documented as a species of it rather than as its own crime type, and why the payroll version has its own page while the pattern belongs here. A variant that asks for no money at all belongs to the same family: IC3 records requests for employees' personal information or Wage and Tax Statements, harvested to build the next fraud.
The scale is large and each figure carries a window, which is the part most often dropped. IC3's public service announcement I-091124-PSA, "Business Email Compromise: The $55 Billion Scam," reports 305,033 domestic and international incidents and $55,499,915,582 of exposed dollar loss between October 2013 and December 2023, with the scam reported in all fifty states and 186 countries. In the single year covered by the 2025 Internet Crime Report, business email compromise was the second costliest cyber-enabled fraud crime type in the report's own ranking, at $3,046,598,558 across all its variants, behind investment fraud. Those are cumulative and annual measures of different things, and quoting one as the other overstates by more than an order of magnitude. The same PSA also notes a route that did not exist a decade ago, with funds sent to accounts at third-party payment processors, peer-to-peer payment services and cryptocurrency exchanges rather than to a conventional bank.
Response is a matter of hours, and the FBI states it without a threshold. IC3's guidance is to contact the originating financial institution as soon as the fraud is recognized and request a recall or reversal along with a hold harmless letter or letter of indemnity, and to file a complaint at ic3.gov. Its PSA puts the urgency plainly, that "time is of the essence," and is equally plain that the complaint should be filed "regardless of the amount lost." Anyone quoting a minimum loss or a fixed number of hours has added something the FBI has not published. What the mechanics of a recall can and cannot achieve once a wire has been accepted is a separate subject, and it is the reason speed matters more than the size of the loss.
How to Remember
Real invoice, real closing, real payroll. Only the account number was changed, and only a second channel will catch it.
Used in a Sentence
“The bookkeeper paid the updated bank details on a familiar supplier's invoice, and the firm learned two weeks later that the supplier's mailbox had been the subject of a business email compromise.”
How It Works
Access is obtained. Credentials are captured through a fake login page, or the mailbox is reached some other way. Sometimes no account is compromised and a near-identical domain is registered instead.
The criminal reads and waits. Payment routines, vendor names, approval chains and upcoming transactions are learned from the mail itself.
A single instruction is sent at the right moment, usually a change of banking details on a payment that is already expected and already approved.
The payment is made to the new account, often by wire, and increasingly to an account at a payment processor or cryptocurrency exchange rather than a bank.
The money is moved onward quickly, which is why the interval between discovery and the recall request decides how much can be frozen.
An example of how the arithmetic usually looks. A twelve-person design firm pays a fabrication contractor monthly. In March an email arrives on the existing thread, from the contractor's own address, attaching the usual invoice for $47,500 and noting new banking details "following a change of bank." The firm pays it. In April the same account is paid a further $18,200. In May the contractor calls about two unpaid invoices, and the firm discovers it has sent $65,700 to an account the contractor never held. The fraud required no forged signature and no broken payment system. It required one unverified change of account details on an invoice that was genuinely owed, and a single telephone call to a number the firm already had would have ended it in March.
Pros and Cons
This is a crime rather than a product, so what follows is why it succeeds and what stops it.
What makes it work
- The transaction is genuine, so the request passes every test that asks whether the payment is expected.
- The message arrives from a real address, often inside a real thread, which defeats the habit of checking who sent it.
- Banking details change legitimately often enough that a change is not itself suspicious.
- Wires and instant transfers settle quickly, and money moved onward is difficult to trace.
- Requests are framed as urgent and confidential, which suppresses the one step that would catch them.
What reliably defeats it
- Verifying every change of payment details by voice, on a number already held rather than one in the message.
- Treating a banking-detail change as a change of vendor record, requiring the same approval as adding a new payee.
- Two-factor authentication on business and personal mail, which removes the value of a stolen password.
- Displaying full email addresses and domains, so a one-character domain is visible rather than hidden behind a display name.
- Reporting immediately to the sending bank and to ic3.gov, without waiting to establish how much was lost.
People Also Asked
Answers to the most frequently asked questions.
What is business email compromise?
How is business email compromise different from phishing?
Does business email compromise only affect companies?
What should someone do immediately after paying a fraudulent instruction?
How large a problem is business email compromise?
Sources
AdviceOnly maintains high editorial standards to improve the quality and accuracy of our educational content. Content is written with the assistance of artificial intelligence tools following a rigorous quality assurance process, and periodically reviewed by credentialed and experienced human financial advisors. References used include government data, academic papers, interviews with industry experts, and reputable primary sources. You can learn more about our efforts to produce accurate content in our editorial policy.
- Federal Bureau of Investigation, Internet Crime Complaint Center. "Business Email Compromise (BEC)."
- Federal Bureau of Investigation, Internet Crime Complaint Center. "Business Email Compromise: The $55 Billion Scam." PSA I-091124-PSA.
- Federal Bureau of Investigation, Internet Crime Complaint Center. "2025 Internet Crime Report."
Have a question a definition can't answer?
We built this glossary to help you make better decisions about your money and your life. When a definition and an example aren't enough, one of our advice-only financial planners can tell you what it means for your situation. The only thing you pay for is the advice: a flat fee you agree to up front, with no commissions and no percentage of your investments.