Since the early days of email, businesses have been targeted by email scams. Many of us remember the “Nigerian Prince” scams from the 1990s, which characterized phishing attacks and managed to deceive thousands of people despite their obvious absurdity. However, as these scams became more prevalent and costlier, awareness about such attacks increased, leading threat actors to switch to more effective tactics.
This shift gave rise to business email compromise (BEC) attacks, which have become increasingly popular over the past decade. The key feature of a BEC attack is impersonation, where criminals masquerade as trusted individuals, often colleagues or company executives, using spoofed email addresses or compromised accounts. They then deceive their targets into revealing sensitive information or authorizing unauthorized financial transactions.