CRI Advantage
  • ServiceNow
        • Consulting and Implementation
        • NowAdvantage
        • ElevateNow
        • ServiceNow Products
          • IT Service Management
          • IT Operations Management
          • IT Asset Management
          • Field Service Management
          • Security Operations
          • App Engine Studio
          • Customer Service Management
          • Strategic Portfolio Management
          • Governance, Risk, and Compliance
          • HR Service Delivery
          • Now Assist
          • AI Control Tower
          • AI Agents
          • EmployeeWorks
  • AI Solutions
  • Industries
        • Energy & Utilities
        • Financial Services
        • Healthcare
        • Logistics
        • Manufacturing
        • Public Sector
        • Service Providers
        • Telecom, Media, & Technology
  • Blog
  • About Us
    • Leadership Team
    • Our Clients
    • Resources
  • Careers
  • Contact Us
  • Menu Menu

Business Email Compromise (BEC): The $26 Billion Scam

Dubbed by the FBI as the $26 billion scam, Business Email Compromise (BEC) attacks come with an average cost of $5.01 million per breach according to the 2021 IMB Cost of Data Breach Report. Do you have that type of capital to mitigate the costs of such a breach? If not, read our extensive blog post on BEC and how to protect your organization from such costly email attacks.

What is BEC?

Behind every great human invention, there’s an unfortunate malicious actor trying to exploit it. Your business email addresses are no different – email scams have existed since the dawn of emails and cybercriminals are always one step ahead in adapting their tactics to circumvent the existing security protocols.

BEC (also known as the man-in-the-email scam) is a scam in which financially-motivated adversaries trick unsuspecting executives and employees into making payments or sending sensitive data to fraudulent accounts. Attackers accomplish this by using a variety of social engineering tactics, that manipulate users into sending money or data.

The social engineering aspect of the Business Email Compromise attacks makes them notoriously difficult to prevent, since cybercriminals don’t rely on malware, but instead they employ elaborate impersonations to trick people into acting on the attacker’s behalf.

Types of BEC?

The FBI defines five major types of BEC scams. Let’s have a quick look at each of them:

· CEO Fraud: Malicious actors position themselves as the CEO or executive of a company and typically email an individual within the finance department, requesting funds to be transferred to an account controlled by the attacker.

· Account Compromise: In this case, an employee’s email account is hacked and is used to request payments to vendors that are wired to fraudulent bank accounts.

· False Invoice Scheme: This tactic is commonly used against foreign suppliers. The attacker impersonates a supplier and requests fund transfers to fraudulent accounts.

· Attorney Impersonation: This social engineering tactic targets mostly lower-level employees that don’t have the knowledge to question the validity of the request. In this case, the attacker impersonates a lawyer or legal representative.

· Data Theft: These types of attacks typically target HR employees in an attempt to obtain personal or sensitive information about individuals within the company such as CEOs and executives. This data can then be leveraged for future attacks such as CEO Fraud.

How Do BEC Attacks Work?

BEC scammers weaponize trust among the members of a given business by impersonating a trustworthy individual within the organization—typically a fellow colleague, manager, or vendor. The sender asks the recipient to make a wire transfer, divert payroll, change banking details for future payments, provide data, and so on.

Because BEC focus on human frailty rather than technical vulnerabilities, they require a people-centric defense that can prevent, detect, and respond to a wide range of BEC and EAC techniques.

Below, we will look into the four phases of a typical BEC attack.

Phase I: Research

The first stage of a typical BEC attack starts with careful research of the target. Attackers begin by building a targeted list of emails that are typically mined from LinkedIn profiles or business email databases. Since attacks are generally targeted at personnel authorized to make payments, cybercriminals carefully collect and assemble the various data points to produce the most successful impersonation.

Phase II: Prepare

Scammers prepare for the attack by performing activities such as spoofing email addresses or creating lookalike domains, impersonating trusted vendors, or taking over a legitimate email account of the victim’s manager or colleague.

Phase III: Execute the attack

The actual BEC attack can take place in one email or an entire thread, depending on the adversary’s thoroughness. This communication often uses persuasion, urgency, and authority to gain the victim’s trust. The perpetrator then provides wire instructions to the victim to facilitate making payments to a fraudulent account.

Phase IV: Disperse payments

If attackers can successfully build trust with an individual, this is typically the phase where financial gain or data breach is made and dispersed across different accounts or databases.

Real-Life Examples of BEC Attacks & Their Cost

Many organizations, from small businesses and major enterprises to NGOs and entire governments, have experienced BEC attacks in the past. Let’s look through some real-life examples:

1. Facebook and Google: $121m BEC scam

Considered to be one of the biggest BEC scams to date, this elaborate BEC attack resulted in $121 million in collective losses for both tech giants. The attack occurred between 2013 and 2015 and its’ perpetrator Evaldas Rimasauskas, was sentenced to five years in prison. The attack itself is a typical False Invoice Scheme – the attackers set up a sake company (Quanta Computer) that impersonated a real-life hardware supplier, then proceeded to present the two tech companies with convincing invoices and counterfeit lawyers’ letters and contracts to ensure that once the funds were paid, the bank would accept the stolen capital.

This is probably one of the most important BEC attacks to date because it teaches us a valuable lesson – if two of the world’s biggest tech companies lost millions of dollars over a two-year period, it could happen to any business. It could happen to you!

2. Toyota 2019: $37 million BEC attack

In 2019 Japan’s Toyota Boshoku Corporation was hit with a $37 million BEC attack, where hackers were able to manipulate an employee to transfer the funds out of the European subsidiary before being detected.

3. Government of Puerto Rico: $2.6 million transfer

As we talked about earlier, nobody is immune to a BEC attack and that includes the governments of nation-states. This attack could make your blood boil, because it exploited a serious tragedy –  in early 2020 while dealing with the aftermath of a 6.4-magnitude earthquake, the Puerto Rican government discovered they had fallen victim to a BEC scam. The direct victim of the scam was Rubén Rivera, finance director of Puerto Rico’s Industrial Development Company who received a convincing email explaining that there had been a change to the bank account tied to remittance payments and ended up transferring over $2.6 million to a fraudulent bank account.

How to Protect Your Business from BEC Attacks?

Safeguarding your business from malicious actors and the numerous online threats is what we do at CRI Advantage. Recently, we discussed the cybersecurity do’s and don’ts and we will reiterate some of those suggestions within the context of BEC attacks.

Do enable MFA on business accounts and workflows that will significantly reduce the likelihood of accounts being compromised and used to carry out BEC attacks. Keep in mind the high-risk employees like C-level executives, employees with authority to conduct payments, HR departments, and admin accounts. With the growing popularity of remote work, it’s also essential to create your own authentication means when none exists.

Don’t rely purely on native email security, especially nowadays when more and more people are working remotely. While email providers such as Office365have significantly improved their native security, the built-in cloud security should be the base, not the entirety of your email security.

Do engage your employees with regular tests to encourage healthy skepticism and assess the levels of cybersecurity awareness. BEC attacks are tricky to prevent, exactly because they target people’s lack of skepticism towards individuals they trust. Conducting regular exercises where you sent targeted BEC-type emails to your employees will help you assess the levels of cybersecurity awareness in your company and conduct the proper training across the board.

BEC is a serious threat to any business, are you willing to take the risk? If not, book a consultation and we will review your business needs and help you identify potential cyber risks. If you aren’t ready to book a consultation, you can complete your own Cybersecurity assessment by filling out the Blueprint exercise below.

The first step: complete your cybersecurity blueprint exercise

Uncover the strengths and weaknesses of your current cyber efforts.

Share This Post

  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail

More Like This

Workers In Office Looking At Technology

Uncovering the ServiceNow Zurich Release: What You Need to Know

CRI
https://criadvantage.com/wp-content/uploads/2025/10/Workers-in-office-looking-at-technology.jpg 1250 2000 Abstrakt Marketing /wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png Abstrakt Marketing2025-10-09 12:47:452026-04-02 09:00:59Uncovering the ServiceNow Zurich Release: What You Need to Know
A Beginner’s Guide To Agentic Ai

A Beginner’s Guide to Agentic AI

CRI
https://criadvantage.com/wp-content/uploads/2025/07/A-Beginners-Guide-to-Agentic-AI.jpg 1250 2000 Abstrakt Marketing /wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png Abstrakt Marketing2025-07-08 06:41:372026-04-02 09:01:03A Beginner’s Guide to Agentic AI
Smiling Male Employees Discussing Cooperation Planning

How ServiceNow Supports Scalable IT Solutions for Growing Businesses

CRI, Scalability
https://criadvantage.com/wp-content/uploads/2025/04/Smiling-male-employees-discussing-cooperation-planning.jpg 1250 2000 Abstrakt Marketing /wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png Abstrakt Marketing2025-04-04 09:19:322026-04-02 09:01:04How ServiceNow Supports Scalable IT Solutions for Growing Businesses

5 Signs Your Business Needs a Virtual CISO

Cyber Security
https://criadvantage.com/wp-content/uploads/2024/12/Blog-Format-16-1-1.jpg 800 1200 Nate Riggins /wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png Nate Riggins2024-06-25 18:20:492026-04-02 09:01:095 Signs Your Business Needs a Virtual CISO
CRI wins servicenow partner award

CRI Advantage Honored as ServiceNow’s Consulting and Implementation Partner of the Year – Premier Segment, Americas Region

CRI, Press Releases
https://criadvantage.com/wp-content/uploads/2024/12/ServiceNow-Partner-Winner-Cover.png 800 1200 Nate Riggins /wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png Nate Riggins2024-02-28 19:14:082026-04-02 09:01:09CRI Advantage Honored as ServiceNow’s Consulting and Implementation Partner of the Year – Premier Segment, Americas Region
romance scams

2024 Valentine’s Day Scams

Cyber Security
https://criadvantage.com/wp-content/uploads/2024/12/Blog-Format-16.jpg 800 1200 Nate Riggins /wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png Nate Riggins2024-02-14 04:50:572026-04-02 09:01:102024 Valentine’s Day Scams
Top 5 Cybersecurity Predictions for 2024

Top 5 Cybersecurity Predictions for 2024 

Cyber Security
https://criadvantage.com/wp-content/uploads/2024/12/Blog-Format-13-1-1.jpg 800 1200 Nate Riggins /wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png Nate Riggins2023-12-01 00:30:482025-01-09 12:53:30Top 5 Cybersecurity Predictions for 2024 
Press Release: CRI Advantage Achieves Recertification for ISO 27001:2022, ISO 9001:2015, and ISO 20000-1:2018

CRI Advantage Achieves Recertification for ISO 27001:2022, ISO 9001:2015, and ISO 20000-1:2018 

CRI, Press Releases
https://criadvantage.com/wp-content/uploads/2024/12/Press-Release-1-1.jpg 800 1200 Nate Riggins /wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png Nate Riggins2023-11-21 22:10:542025-01-09 12:56:57CRI Advantage Achieves Recertification for ISO 27001:2022, ISO 9001:2015, and ISO 20000-1:2018 
blackfriday cybersecurity scams

Navigating Cyber Monday Deals Safely in the Face of Top Cybersecurity Scams

Cyber Security
https://criadvantage.com/wp-content/uploads/2024/12/Blog-Format-12-1-1.jpg 800 1200 Nate Riggins /wp-content/uploads/2024/11/CRI-Logo-Transparent.-blue.png Nate Riggins2023-11-21 21:48:232026-04-02 09:01:10Navigating Cyber Monday Deals Safely in the Face of Top Cybersecurity Scams
Previous Previous Previous Next Next Next

Categories

  • Agentic AI
  • AI Solutions
  • Board Member
  • CMDB
  • CRI
  • CSM
  • Cyber Security
  • Digital Transformation
  • Events
  • Generative AI
  • Human Resources
  • IT Staffing
  • ITOM
  • ITSM
  • Miscellaneous
  • Podcasts
  • Press Releases
  • Scalability
  • ServiceNow
  • ServiceNow Releases
  • Software as a Service
  • TPSM
  • vCIO
  • vCISO
  • Webinars
Cri Logo Transparent. Blue

ServiceNow IT solutions tailored to your industry-specific needs.

Learn More

Stay Connected

Youtube (1)

Reseller Partner Of The Year Americas Specialist  Ci Partner Of The Year Americas  Validated Practice Badge ItsmCsm Badge Elite White 2593f49e1d

What We Offer

ServiceNow Solutions

AI Solutions

IT Solutions

Industry Solutions

Contact Us

520 Energy Place
Idaho Falls, ID 83401

(208) 343-9192

[email protected]

Website by Abstrakt Marketing Group ©
  • DCAA COMPLIANT | DOD TS & DOE Q FCL | CAGE CODE: 1HBW0 | DUNS: 608143277
  • Privacy Policy
  • Sitemap
Scroll to top Scroll to top Scroll to top

This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.

AcceptLearn more

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Accept settingsHide notification only