Last Modified: August 18, 2026
A sophisticated scam targeting people and businesses everywhere
Business Email Compromise (BEC) is a sophisticated scam using email and/or other electronic communication to impersonate a business executive, employee, or other person with authority to request payments or access to employee payroll and W2 information on behalf of a business.
A BEC scam may begin when a legitimate user downloads malicious software (malware) by clicking on a malicious attachment or link in a spam or phishing email; or acts upon a spoofed email payment request crafted to look like it came from a company executive. An example of such a spoofed email address from ceo@abc_company.com might appear as ceo@abc-company.com. In cases where malware or malicious links are used, the malware can provide criminals with full control of the user’s computer, including access to passwords, documents, and email. Alternatively, criminals can obtain a user’s email login information if it was stolen previously and sold online. In either case, the criminal’s goal is to assume the identity of the legitimate user and request new payments, change the banking information of pending payments, or request copies of employee records for some alleged payroll purpose. Prior to executing the BEC scam, more sophisticated cyber criminals may even monitor business communications for extended periods of time in order to understand operating procedures and the communication style of the individuals they want to impersonate. While email is most common, sophisticated BEC criminals have also used a fax or phone call to confirm or follow up on an email request to send money.
The BEC threat is highly adaptable and constantly evolving, but criminals have been particularly active in targeting small to large companies and individuals which may transfer high-dollar funds or sensitive records in the course of business. As such, the following industries are popular with criminals utilizing BEC scams:
For more information, please visit: http://www.ic3.gov/media.
Materials Courtesy of the Department of Justice and the Federal Bureau of Investigation