24/7 INCIDENT RESPONSE
(877) 259-0509
← Topics

CYBER CENTAURS TOPIC

What Is Business Email Compromise?

Incident Response

Business email compromise is a fraud and account-abuse pattern involving trusted email identities, payment manipulation, impersonation, or mailbox control.

Business Email Compromise, or BEC, is a fraud and account-abuse scenario in which an attacker uses email identity, impersonation, or mailbox access to deceive an organization into sending money, changing payment details, disclosing information, or taking another unauthorized action. BEC may involve credential theft, session abuse, spoofing, lookalike domains, mailbox rules, or social engineering.

How BEC Differs From Generic Phishing

Phishing often focuses on tricking a recipient into clicking a link, opening an attachment, or providing credentials. BEC is usually more targeted and business-process oriented. The attacker may study vendors, executives, invoices, open deals, legal matters, or payment workflows, then insert believable instructions at the right moment.

Some BEC matters involve a fully compromised mailbox. Others rely on impersonation without direct mailbox access. A Business Email Compromise Investigation must distinguish those possibilities because containment, notification, and evidentiary conclusions depend on whether the attacker accessed accounts or only sent deceptive messages.

Evidence Commonly Reviewed

  • Microsoft Entra ID sign-in records, conditional access outcomes, MFA events, and unfamiliar locations.
  • Exchange Online mailbox audit events, message traces, forwarding settings, inbox rules, and delegate access.
  • Suspicious OAuth consent, application permissions, admin activity, or changes to authentication methods.
  • Email headers, reply chains, lookalike domains, payment instructions, and invoice changes.
  • Endpoint evidence where malware, browser credential theft, or remote access may have contributed.

Mailbox Rules and Forwarding

Malicious inbox rules and forwarding configurations can be important BEC evidence. Rules may move messages, mark them read, delete warnings, forward external copies, or hide conversations from the legitimate user. These artifacts may support unauthorized mailbox control, but they should be correlated with authentication and audit logs before drawing conclusions.

BEC investigations frequently overlap with session hijacking and MFA fatigue because attackers may use stolen credentials, tokens, cookies, or repeated prompt approval to gain account access. MFA reduces risk, but it does not make mailbox compromise impossible.

Business Impact

In Data Breach & Incident Response, BEC work is not limited to confirming whether an account was accessed. Investigators also evaluate what mail may have been viewed, whether sensitive attachments were exposed, whether payment instructions changed, whether external parties were impersonated, and whether legal or notification obligations may be triggered.

A careful report distinguishes verified facts from unresolved questions. For example, suspicious sign-in activity may support unauthorized access, but it may not prove which messages were read unless mailbox audit data, message access events, or other records support that conclusion.

References

NEED ASSISTANCE?

Discuss the Matter
With Cyber Centaurs.

If this topic relates to an active incident, forensic matter, or security concern affecting your organization, contact Cyber Centaurs to discuss the circumstances directly.

CONTACT CYBER CENTAURS →