BEC
Business Email Compromise is a type of corporate fraud where attackers trick staff into making payments to accounts controlled by the attackers.
Business Email Compromise (BEC) is fraud carried out via business email. Attackers impersonate a senior executive, supplier, or partner to request payments to their own accounts.
How it works
Attackers often start by taking over a legitimate mailbox, for instance through phishing. They secretly monitor emails for weeks to understand invoice and payment approval processes. At the right time, they send a message with changed bank details from the real account or a very similar domain. Traditional security filters often fail because no attachments or links are used.
For example, the accounts department receives an email from a known supplier with a new IBAN. The tone is familiar, and the invoice number is correct. In reality, the supplier's mailbox has been compromised. Only a call back to a known number would have exposed the fraud.
What to look out for
- Never change bank details based solely on an email instruction. Confirm every change by calling a known, trusted phone number.
- Use a four-eyes principle for payments, with clearly defined thresholds.
- Monitor mailbox rules, forwarding settings, and logins from unusual locations.
- Protect your domain with SPF, DKIM, and DMARC to make spoofing more difficult.
- Train accounting staff and assistants specifically, as they are the primary targets.
Switzerland and regulation
BEC and so-called CEO fraud are among the most common types of corporate fraud in Switzerland. The National Cyber Security Centre (NCSC) regularly publishes warnings on this topic. If a company suffers a loss, it should inform its bank immediately and file a police report, as transfers can sometimes still be stopped.
New forms
Attackers increasingly use deepfake voice and video to make payment instructions seem more credible. The defence remains the same: a strict callback process that nobody may bypass, including senior management.
How we implement it
We detect typical indicators of a mailbox takeover, like new forwarding rules and suspicious logins. We then lock affected accounts within the agreed mandate.