Categories: FraudScams Ways

Business Email Compromise (BEC) Scams: 10 Types, Q&A, Preventing And Reporting

Business Email Compromise (BEC), also known as Email Account Compromise (EAC), is a type of phishing attack that targets organizations, with the goal of stealing money or critical information. In a BEC scam, criminals send an email message that appears to come from a known source making a legitimate request, such as:

  • A vendor your company regularly deals with sends an invoice with an updated mailing address.
  • A company CEO asks her assistant to purchase dozens of gift cards to send out as employee rewards.
  • A customer service representative asks you to update your personal information, such as your credit card number or Social Security number.

The email may contain a link that, when clicked, will take the victim to a fake website that looks like the real website of the company they are supposedly doing business with. Once the victim enters their personal information on the fake website, the criminals can steal it.

BEC scams are on the rise, and they are one of the most financially damaging online crimes. In 2022, the FBI received over 24,000 complaints about BEC scams, with losses totaling over $2.4 billion.

Related Post

10 Types of Business Email Compromise (BEC) Scams

  1. CEO Fraud: Impersonating a high-level executive, the scammer requests an urgent wire transfer from an employee, typically in the finance department.
  2. Account Compromise: An employee’s email account is hacked and then used to make requests for invoice payments to fraudulent bank accounts.
  3. Fake Invoice Scheme: Scammers send a fake invoice to a company’s billing department, with the payment instructions directed to a fraudulent account.
  4. Vendor Email Compromise: A legitimate vendor’s email account is compromised and used to send fake invoices to the company.
  5. Data Theft: Scammers target employees with access to sensitive information, such as HR records or financial data, to gain unauthorized access.
  6. Attorney Impersonation: The scammer poses as a lawyer or legal advisor and requests confidential information, often under the guise of an urgent or sensitive legal matter.
  7. Payroll Diversion: An employee’s direct deposit information is altered, sending their salary to a fraudulent bank account.
  8. Tax Fraud: Fraudsters use stolen employee information to file false tax returns and claim refunds.
  9. Real Estate BEC: Scammers target real estate transactions, such as closings, and alter the payment instructions to divert funds to fraudulent accounts.
  10. M&A Fraud: Emails from scammers posing as executives or consultants involved in mergers and acquisitions request sensitive information or funds transfers.

10 Q&A on Business Email Compromise (BEC) Scams

  1. Q: What is a BEC scam?
    A: A BEC scam is a type of fraud where scammers use email to impersonate someone within a company or business relationship to trick employees into transferring funds or sharing sensitive information.
  2. Q: How do BEC scams work?
    A: BEC scams typically involve email spoofing, social engineering, and sometimes malware or phishing to gain access to email accounts or deceive employees into taking fraudulent actions.
  3. Q: Who is targeted in BEC scams?
    A: BEC scams often target employees with access to company finances or sensitive information, including those in finance, HR, and executive roles.
  4. Q: How can I recognize a BEC scam?
    A: Look for unusual or urgent requests, discrepancies in email addresses or domain names, and changes in payment instructions or account information.
  5. Q: What should I do if I suspect a BEC scam?
    A: Verify the request through another channel, such as a phone call, and report your suspicions to your IT or security department.
  6. Q: How can I prevent BEC scams?
    A: Implement email security best practices, provide employee training, and establish protocols for verifying and approving financial transactions and changes to sensitive information.
  7. Q: What are the financial impacts of BEC scams?
    A: BEC scams can result in significant financial losses for businesses, as well as reputational damage and potential legal liabilities.
  8. Q: How do scammers choose their targets?
    A: Scammers often use publicly available information, such as company websites and social media, to identify potential targets and gather information to craft convincing emails.
  9. Q: How do scammers gain access to email accounts?
    A: Scammers may use phishing attacks, social engineering, or malware to compromise email accounts and gather information for their scams.
  10. Q: What should I do if my company has fallen victim to a BEC scam?
    A: Report the incident to law enforcement, notify your financial institution, and take steps to secure your email accounts and systems.

Preventing and Reporting BEC Scams

Preventing BEC Scams

  1. Implement multi-factor authentication for email accounts.
  2. Train employees to recognize and report suspicious emails and requests.
  3. Establish protocols for verifying and approving financial transactions and changes to sensitive information.
  4. Use email security tools to detect and block phishing and spoofing attempts.
  5. Limit the amount of publicly available information about your organization and employees.

Reporting BEC Scams

  1. Report the scam to your organization’s IT or security department.
  2. If funds have been transferred, contact your financial institution immediately.
  3. Report the incident to your local law enforcement agency.
  4. File a complaint with the FBI’s Internet Crime Complaint Center (IC3) at www.ic3.gov.
  5. Notify any affected clients, vendors, or partners to help prevent further damage and loss.

More About “BEC Scams” Here…

FraudsWatch

FraudsWatch is а site reporting on fraud and scammers on internet, in financial services and personal. Providing a daily news service publishes articles contributed by experts; is widely reported in thе latest compliance requirements, and offers very broad coverage of thе latest online theft cases, pending investigations and threats of fraud.

Recent Posts

New Orleans Financier Michael Depetrillo Pleads Guilty in $9.2 Million Forex Investment Fraud Scheme

NEW ORLEANS, LA (February 19, 2025) – Michael Brian Depetrillo, a 43-year-old New Orleans resident,… Read More

14 hours ago

Cryptocurrency Scams: The Ultimate Guide to Avoiding the Latest Threats in 2025

Learn how to identify and avoid cryptocurrency scams in 2024. This comprehensive guide covers the… Read More

14 hours ago

Affinity Fraud 2025: Spot, Avoid, & Report

The digital age has amplified both the connectivity and the vulnerability of our communities. Investment… Read More

4 days ago

Thomas Addaquay Sentenced to 12 Years in Prison for $7 Million Tax Refund and Romance Scam Conspiracy

ATLANTA, GA (February 12, 2025) – A sophisticated, multi-layered fraud operation spanning several years and… Read More

1 week ago

The Escalating Crisis of Identity Theft and Data Breaches: A 2025 Survival Guide

The Digital Age Dilemma: Convenience vs. Catastrophic Risk The digital revolution has woven itself into… Read More

1 week ago

Phobos Ransomware Ring Busted: Roman Berezhnoy and Egor Nikolaevich Glebov Charged in $16M+ Global Cybercrime Spree

WASHINGTON, D.C. – In a sweeping international operation, the U.S. Justice Department has unsealed charges… Read More

1 week ago