Threat

BEC

Business Email Compromise is a type of corporate fraud where attackers trick staff into making payments to accounts controlled by the attackers.

Business Email Compromise (BEC) is fraud carried out via business email. Attackers impersonate a senior executive, supplier, or partner to request payments to their own accounts.

How it works

Attackers often start by taking over a legitimate mailbox, for instance through phishing. They secretly monitor emails for weeks to understand invoice and payment approval processes. At the right time, they send a message with changed bank details from the real account or a very similar domain. Traditional security filters often fail because no attachments or links are used.

For example, the accounts department receives an email from a known supplier with a new IBAN. The tone is familiar, and the invoice number is correct. In reality, the supplier's mailbox has been compromised. Only a call back to a known number would have exposed the fraud.

What to look out for

  • Never change bank details based solely on an email instruction. Confirm every change by calling a known, trusted phone number.
  • Use a four-eyes principle for payments, with clearly defined thresholds.
  • Monitor mailbox rules, forwarding settings, and logins from unusual locations.
  • Protect your domain with SPF, DKIM, and DMARC to make spoofing more difficult.
  • Train accounting staff and assistants specifically, as they are the primary targets.

Switzerland and regulation

BEC and so-called CEO fraud are among the most common types of corporate fraud in Switzerland. The National Cyber Security Centre (NCSC) regularly publishes warnings on this topic. If a company suffers a loss, it should inform its bank immediately and file a police report, as transfers can sometimes still be stopped.

New forms

Attackers increasingly use deepfake voice and video to make payment instructions seem more credible. The defence remains the same: a strict callback process that nobody may bypass, including senior management.

How we implement it

We detect typical indicators of a mailbox takeover, like new forwarding rules and suspicious logins. We then lock affected accounts within the agreed mandate.