{"id":3816,"date":"2025-08-12T11:34:59","date_gmt":"2025-08-12T11:34:59","guid":{"rendered":"https:\/\/certera.com\/blog\/?p=3816"},"modified":"2025-09-26T09:04:55","modified_gmt":"2025-09-26T09:04:55","slug":"what-is-business-email-compromise-bec-examples-scams-and-tactics","status":"publish","type":"post","link":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/","title":{"rendered":"What is Business Email Compromise (BEC)? Examples, Scams, and Tactics"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-what-is-business-email-compromise-bec\">What is Business Email Compromise (BEC)?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Business Email Compromise (BEC) is a relatively modern type of cybercrime that scammers use email schemes to deceive business employees and\/or individuals with the purpose of financial fraud or obtaining important information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Usually, cyber attackers disguise themselves as CEOs, company partners, or other executives, customers, or friends of the company.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then, they request the employee to transfer money to another account, reveal sensitive company information, or provide their details.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A BEC attack normally targets a company\u2019s workers or a group of workers within a company, then manipulates them to achieve the attacker&#8217;s objective.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-bec-works\">How BEC Works?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">BEC operates based on several carefully planned tactics, with the primary steps possibly including scoping the target organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A potential risk may involve the attacker closely studying the personnel of the targeted company, its managerial staff and business associates, its operations, among others.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"717\" src=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/08\/how-bec-attack-works-1024x717.webp\" alt=\"How BEC Attack Works\" class=\"wp-image-3843\" srcset=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/08\/how-bec-attack-works-1024x717.webp 1024w, https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/08\/how-bec-attack-works-300x210.webp 300w, https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/08\/how-bec-attack-works-768x538.webp 768w, https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/08\/how-bec-attack-works.webp 1250w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">They may also entice users into surrendering their email passwords or gaining access to them through the use of phishing emails or malware, and obtain additional information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once a sufficient amount of information has been collected, the attackers send extremely well-orchestrated emails that look like they are from a senior executive, a partner, or some other reliable source in the organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Many of these messages always demand immediate action on various financial transactions, personal and highly confidential data, or changes to your payment methods.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These kinds of messages are generally programmed to go unnoticed to avoid suspicion and are, in most cases, formatted like every other genuine business communication.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is all because an employee who receives the fraudulent email in his\/her inbox dreams of being an executive in the shortest time, and therefore complies with the request.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This could lead to the attacker gaining access to the user\u2019s account, withdrawal of the money to the attacker\u2019s account, or other immoral actions, such as the release of sensitive information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Such attacks leverage the existing perception people have of the impersonated individual and wish to make the decision-maker act without making any checks..<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-examples-of-business-email-compromise-bec\">Examples of Business Email Compromise (BEC)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-ceo-fraud\">CEO Fraud<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In a CEO fraud situation, the attacker will pretend to be a chief executive, such as the CEO or the CFO, and contact an employee, ideally in the finance department, through email.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is usually sent to the employee in the company, and when opened, it appears urgent, containing information that the employee must forward cash to a bank account that belongs to the attacker.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The request is often presented as a business proposal or an urgent payment issue, which deviates from the standard check procedure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-invoice-scams\">Invoice Scams<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In an invoice payment scam, the attackers gain access to the email belonging to a particular vendor or supplier of the targeted organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is a fabricated invoice that seems to be authentic, seeking payment for delivered goods or services to extort money, but the bank account details have been compromised by the attackers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This kind of fraud exploits the friendly relationship that most business entities have, as well as the normal course of business, where employees are used to processing invoices.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-account-compromise\">Account Compromise<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Here, an attacker gets complete control of an employee\u2019s email account through phishing or any other means.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After getting access to the internal network, the attacker listens to the flow of communications and the financial transactions and business processes taking place in the organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Also Read<\/strong>: <a href=\"https:\/\/certera.com\/blog\/phishing-campaign-targets-woocommerce-stores-with-fake-security-alerts\/\">Phishing Campaign Targets WooCommerce Stores with Fake Security Alerts<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attacker subsequently uses the obtained privilege to forward emails purporting to be from the owner of the account, for instance, a request for a change of the banking details or wiring instructions of funds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Due to the sender using a genuine email address, the messages are unlikely to trigger alarms in the recipient\u2019s digital defenses.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-attorney-impersonation\">Attorney Impersonation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Among all roles, the threat actors can pretend to be a legal representative or an attorney, especially if the conversation is related to a delicate issue.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They write an email informing the recipient that they are dealing with matters of high urgency, such as legal concerns, mergers, or acquisitions, then proceed to request the recipient to transfer money or disclose personal information immediately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The appearance of urgency, together with the phrasing of the email, is meant to influence the recipient into obeying the request without questioning it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-data-theft\">Data Theft<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In this, the attacker is not interested in money as in ordinary cases, but seeks information belonging to the targeted company.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attacker will then send an email purporting to be an internal employee or organizational partner with a demand for employee tax information, company financial records, or customer information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The procured information can then be exploited for other identity thefts, more <a href=\"https:\/\/certera.com\/blog\/phishing-attacks-explained-how-to-spot-and-prevent-online-scams\/\">phishing scams<\/a>, or even sold to other third parties.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-common-bec-attack-methods\">Common BEC Attack Methods<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-phishing-emails\">Phishing Emails<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Phishing emails are basically known as fraudulent messages that are normally employed by attackers with the aim of making the recipient disclose personal details or click on a certain link.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sometimes, the phished emails originate from identities familiar to the targets, including colleagues, business partners, or clients, and the emails appear to request login credentials, account details, or any other sensitive information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Malware can also be attached to phishing emails, where the attacker wants to gain access to the victim\u2019s email address or network.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-spear-phishing\">Spear Phishing<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A branch of phishing is spear phishing because it personalizes the information of an individual within the organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attackers procure as much information about the target from social media accounts, corporate sites, or prior conversations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The email may look like it has been sent by someone else, typically a person the recipient knows and trusts, which makes the likelihood of the trick being successful high<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-email-spoofing\">Email Spoofing<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/certera.com\/blog\/what-is-email-spoofing-detailed-guide\/\">Email spoofing<\/a> means that the sender changes the \u2018<strong>From<\/strong>\u2019 address in a message to something else to make it seem that the email is coming from another user.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attackers can fake the email addresses of top managerial officials, employees, or business partners to adopt the appearance of genuine emails.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Phishing emails are typically crafted to look like a legitimate email from a credible sender; they typically contain requests for sensitive data or for the recipient to transfer money due to some emergency.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-account-compromise-0\">Account Compromise<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The process starts with intruders stealing an employee\u2019s login credentials to their email via phishing scams, <a href=\"https:\/\/certera.com\/blog\/what-is-malware-how-to-prevent-malware-attacks\/\">malware<\/a>, or by guessing a password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once within, they track the account to understand current interactions and various money-making activities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attacker then follows through with the account and forges an email to other employees or a business partner, which makes the email look authentic and forces the target to respond positively.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-payment-diversion\">Payment Diversion<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A malicious performer gains unauthorized access to an email account or mimics a vendor to send an email requesting the recipient to update their payment information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They simply instruct the recipient to make forward payments to a different account owned by the attacker.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thus, the change looks quite reasonable since this method is suitable for the scenarios observed in continuous partnerships with a business.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-types-of-bec-scams\">Types of BEC Scams<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-payroll-redirect\">Payroll Redirect<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Here, the attackers mimic employees and ask for alterations to the most common disbursement method.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These hackers usually direct themselves to the HR or the payroll branch of a company by sending counterfeit vouchers or emails with a view of redirecting salaries to specific accounts controlled by the con artist.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This type of scam may lie dormant until the victim sees the light one day and finds they have not been paid.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-gift-card-fraud\">Gift Card Fraud<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In gift card fraud, the attackers call the employees in the company and pretend to be the executives or managers, then they tell the employees to buy the gift cards for business or for other purposes, like for some clients.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attackers then demand gift card numbers and PINs, which they can either use themselves or pass on to others for resale.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Such requests are often expressed in the most urgent and secretive of tones.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-vendor-email-compromise\">Vendor Email Compromise<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In this fraud, the attackers gain unauthorized access to the email account of a legitimate supplier and then proceed to send fake billing statements or remittance advice to other clients.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since the emails are sourced from a genuine vendor, people are likely not to question the received emails, thus offering the fraudsters a higher chance of success.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Also Read:<\/strong> <a href=\"https:\/\/certera.com\/blog\/cyber-attack-recovery-5-crucial-steps-to-bounce-back-swiftly\/\">Cyber Attack Recovery: 5 Crucial Steps to Bounce Back Swiftly<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-supply-chain-attack\">Supply Chain Attack<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It is a type of cybercrime where hackers access the email networks of organizations in a chain, especially those with poor security measures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They then use the compromised accounts to make fraudulent invoices or change payment information in transactions involving companies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This can result in disruption of flows and loss-making along the value processes of the supply chain.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-executive-threats\">Executive Threats<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In this type of attack, the criminals email executives or any other senior employee and demand a certain amount of money to be paid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is because they have compromising information that they intend to publish, or else prepare a nasty, scandalous story.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These threats can be quite potent if the attackers have some form of insight into the personal or professional life of the target executive, thus making the threat appear real.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-bec-and-phishing-tactics\">BEC and Phishing Tactics<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">BEC and phishing are two of the commonly noted cyber threats that tend to incorporate social engineering to a great extent. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Knowledge of the following strategies used in such attacks is crucial in cases of risk:<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-spear-phishing-0\">Spear Phishing<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The most common type of phishing is spear phishing, in which a scammer sends emails that are specifically crafted to appear to be from a known sender.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Phishers find out as much as they can about their targets to make their simulated messages seem as genuine as possible, using the targets\u2019 identities to pose as co-workers, vendors, or bosses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These emails may contain links or attachments that, when clicked, feed the attackers with login credentials or that install the BEC type of malware.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-whaling\">Whaling<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Spear phishing differs from whaling in that it focuses on high-ranking employees within a company, often the CEO, CFO, or any other top executive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These are written and structured professionally, in some cases directing them as an urgent or confidential message.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is to lure the executive into providing more crucial information or ratifying hefty transactions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-domain-spoofing\">Domain Spoofing<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In domain spoofing, the attackers mimic the legitimate email addresses either by modifying a little bit of the address, for instance, swapping \u2018L\u2019 for \u2018I\u2019, or by adding some characters that do not belong.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This tactic is used to make the recipients feel that the email was authored by a familiar person so that they will obey all the fraudulent requests.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-lookalike-domain\">Lookalike Domain<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Like domain spoofing, attackers take an extreme effort to register domains that are very similar to a legitimate company\u2019s domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For instance, they will replace one of the letters in the domain name, such as in \u2018<strong>example.com<\/strong>\u2019, they will type \u2018<strong>examp1e.com<\/strong>\u2019.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They then use these domains to send out phishing emails that make recipients believe the e-mailed communication is legitimate, thereby leading to BEC scams.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-email-account-compromise\">Email Account Compromise<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Phishing, malware, or the use of <a href=\"https:\/\/certera.com\/blog\/brute-force-attack-types-examples-tools-prevention\/\">brute force<\/a> to get into an employee\u2019s account and have it controlled by the attackers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If infiltrated, they can eavesdrop on phone calls, analyze the organizational flow, and execute realistic fake emails to other employees or other associates. This is usually a warm-up to continue with more complex BEC attacks.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-conclusion\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Ensure the safety of your business with Certera, mainly offering a <a href=\"https:\/\/certera.com\/buy-ssl-certificates\">wide range of SSL Certificates<\/a>, <a href=\"https:\/\/certera.com\/solutions\/pki-solutions\">PKI Solutions<\/a>, and <a href=\"https:\/\/certera.com\/sitelock\">Web Security Solutions like Sitelock<\/a> that will safeguard your online resources and entire web presence.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What is Business Email Compromise (BEC)? Business Email Compromise (BEC) is a relatively modern type of cybercrime that scammers use email schemes to deceive business employees and\/or individuals with the purpose of financial fraud or obtaining important information. Usually, cyber attackers disguise themselves as CEOs, company partners, or other executives, customers, or friends of the<span class=\"morelink d-block mt-3\"><a href=\"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/\">Read More<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":3821,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31,19],"tags":[743,742],"class_list":["post-3816","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-attack","category-website-security","tag-bec-attacks","tag-business-email-compromise-bec","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What is Business Email Compromise (BEC)? Examples &amp; Methods<\/title>\n<meta name=\"description\" content=\"Understand here What is Business Email Compromise, how it works, Real-world examples, scams and how attacker perform phishing &amp; BEC attacks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is Business Email Compromise (BEC)? Examples &amp; Methods\" \/>\n<meta property=\"og:description\" content=\"Understand here What is Business Email Compromise, how it works, Real-world examples, scams and how attacker perform phishing &amp; BEC attacks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/\" \/>\n<meta property=\"og:site_name\" content=\"EncryptedFence by Certera - Web &amp; Cyber Security Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/certeraLLC\/\" \/>\n<meta property=\"article:published_time\" content=\"2025-08-12T11:34:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-09-26T09:04:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/08\/business-email-compromise-bec-attacks.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"620\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janki Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:site\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Janki Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/\"},\"author\":{\"name\":\"Janki Mehta\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\"},\"headline\":\"What is Business Email Compromise (BEC)? Examples, Scams, and Tactics\",\"datePublished\":\"2025-08-12T11:34:59+00:00\",\"dateModified\":\"2025-09-26T09:04:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/\"},\"wordCount\":1963,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/business-email-compromise-bec-attacks.webp\",\"keywords\":[\"BEC Attacks\",\"Business Email Compromise (BEC)\"],\"articleSection\":[\"Cyber Attack\",\"Website Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/#respond\"]}],\"copyrightYear\":\"2025\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/\",\"name\":\"What is Business Email Compromise (BEC)? Examples & Methods\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/business-email-compromise-bec-attacks.webp\",\"datePublished\":\"2025-08-12T11:34:59+00:00\",\"dateModified\":\"2025-09-26T09:04:55+00:00\",\"description\":\"Understand here What is Business Email Compromise, how it works, Real-world examples, scams and how attacker perform phishing & BEC attacks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/#primaryimage\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/business-email-compromise-bec-attacks.webp\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/business-email-compromise-bec-attacks.webp\",\"width\":960,\"height\":620,\"caption\":\"Business Email Compromise (BEC) Attacks\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/what-is-business-email-compromise-bec-examples-scams-and-tactics\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/certera.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What is Business Email Compromise (BEC)? Examples, Scams, and Tactics\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"name\":\"EncryptedFence by Certera - Web & Cyber Security Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"alternateName\":\"Certera's EncryptedFence Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/certera.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\",\"name\":\"Certera\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"caption\":\"Certera\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/certeraLLC\\\/\",\"https:\\\/\\\/x.com\\\/certera_llc\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/certera-llc\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\",\"name\":\"Janki Mehta\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"caption\":\"Janki Mehta\"},\"description\":\"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\\\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.\",\"sameAs\":[\"https:\\\/\\\/certerassl.com\\\/\"],\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/author\\\/certerabguser\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What is Business Email Compromise (BEC)? Examples & Methods","description":"Understand here What is Business Email Compromise, how it works, Real-world examples, scams and how attacker perform phishing & BEC attacks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/","og_locale":"en_US","og_type":"article","og_title":"What is Business Email Compromise (BEC)? Examples & Methods","og_description":"Understand here What is Business Email Compromise, how it works, Real-world examples, scams and how attacker perform phishing & BEC attacks.","og_url":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/","og_site_name":"EncryptedFence by Certera - Web &amp; Cyber Security Blog","article_publisher":"https:\/\/www.facebook.com\/certeraLLC\/","article_published_time":"2025-08-12T11:34:59+00:00","article_modified_time":"2025-09-26T09:04:55+00:00","og_image":[{"width":960,"height":620,"url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/08\/business-email-compromise-bec-attacks.webp","type":"image\/jpeg"}],"author":"Janki Mehta","twitter_card":"summary_large_image","twitter_creator":"@certera_llc","twitter_site":"@certera_llc","twitter_misc":{"Written by":"Janki Mehta","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/#article","isPartOf":{"@id":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/"},"author":{"name":"Janki Mehta","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7"},"headline":"What is Business Email Compromise (BEC)? Examples, Scams, and Tactics","datePublished":"2025-08-12T11:34:59+00:00","dateModified":"2025-09-26T09:04:55+00:00","mainEntityOfPage":{"@id":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/"},"wordCount":1963,"commentCount":0,"publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"image":{"@id":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/08\/business-email-compromise-bec-attacks.webp","keywords":["BEC Attacks","Business Email Compromise (BEC)"],"articleSection":["Cyber Attack","Website Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/#respond"]}],"copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/certera.com\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/","url":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/","name":"What is Business Email Compromise (BEC)? Examples & Methods","isPartOf":{"@id":"https:\/\/certera.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/#primaryimage"},"image":{"@id":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/08\/business-email-compromise-bec-attacks.webp","datePublished":"2025-08-12T11:34:59+00:00","dateModified":"2025-09-26T09:04:55+00:00","description":"Understand here What is Business Email Compromise, how it works, Real-world examples, scams and how attacker perform phishing & BEC attacks.","breadcrumb":{"@id":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/#primaryimage","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/08\/business-email-compromise-bec-attacks.webp","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/08\/business-email-compromise-bec-attacks.webp","width":960,"height":620,"caption":"Business Email Compromise (BEC) Attacks"},{"@type":"BreadcrumbList","@id":"https:\/\/certera.com\/blog\/what-is-business-email-compromise-bec-examples-scams-and-tactics\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/certera.com\/blog\/"},{"@type":"ListItem","position":2,"name":"What is Business Email Compromise (BEC)? Examples, Scams, and Tactics"}]},{"@type":"WebSite","@id":"https:\/\/certera.com\/blog\/#website","url":"https:\/\/certera.com\/blog\/","name":"EncryptedFence by Certera - Web & Cyber Security Blog","description":"","publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"alternateName":"Certera's EncryptedFence Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/certera.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/certera.com\/blog\/#organization","name":"Certera","url":"https:\/\/certera.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","caption":"Certera"},"image":{"@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/certeraLLC\/","https:\/\/x.com\/certera_llc","https:\/\/www.linkedin.com\/company\/certera-llc\/"]},{"@type":"Person","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7","name":"Janki Mehta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","caption":"Janki Mehta"},"description":"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.","sameAs":["https:\/\/certerassl.com\/"],"url":"https:\/\/certera.com\/blog\/author\/certerabguser\/"}]}},"_links":{"self":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/3816","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/comments?post=3816"}],"version-history":[{"count":6,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/3816\/revisions"}],"predecessor-version":[{"id":3958,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/3816\/revisions\/3958"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media\/3821"}],"wp:attachment":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media?parent=3816"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/categories?post=3816"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/tags?post=3816"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}