Awareness

BEC Attacks: A US$2.7 Billion Threat to US and UK Firms

Published  ·  11 min read

You get an email from your CEO, it looks completely normal, the tone is right, the signature is right, and it references a real project you have been working on, so you do what any good employee would do, you follow the instructions.

That is the moment you become a victim of Business Email Compromise, and you are not alone, because BEC has become one of the costliest cyber threats facing organizations in the United States and the United Kingdom.

The numbers are staggering, the FBI's Internet Crime Complaint Center reported over $2.7 billion in BEC losses in a single year, and the problem is getting worse, not better.

Important Disclaimer

This article is intended for educational and defensive purposes only, the techniques described here are shared to help security professionals understand emerging threats so they can better protect their systems.

Do not use these techniques against systems you do not own or do not have explicit written permission to test, unauthorized testing is illegal in most jurisdictions.

The author assumes no liability for any damages, legal consequences, or other outcomes resulting from the use or misuse of this information, always obtain proper authorization before conducting any security testing, and stay legal, stay ethical, stay responsible.

What Is Business Email Compromise?

A business email compromise is a type of cyber fraud where the attacker impersonates a known person, normally an executive, vendor, or partner, to get employees to transfer money or share sensitive information.

What makes BEC different from other cyber threats is that there is no malware, no malicious link, and no attachment carrying a payload, the email is a perfectly legitimate message, correctly authenticated, and sent from a real account or a convincingly registered lookalike domain.

BEC exploits human trust, not technical vulnerabilities, which is why traditional email security tools often fail to detect it.

The Scale of the Problem

The numbers tell a story of a threat that is not going away.

US Losses

The FBI's IC3 tracks BEC as one of the most financially damaging cybercrime categories, here is how the losses have grown.

Year

BEC Losses (USD)

Complaints

2023

$2.94 billion

2024

$2.77 billion

21,442

2025

$3.05 billion

24,768

The 2025 figure represents a 9.9 percent increase over 2024, and BEC remains the most financially damaging single fraud category for businesses.

Per-complaint losses average over $122,000, and 86 percent of BEC funds move via wire transfer or ACH, meaning these attacks are landing inside real financial workflows.

UK Losses

The UK is not immune, the UK Government's Cyber Security Breaches Survey found that 43 percent of UK businesses experienced a cyber security breach or attack, with phishing continuing to be the most common form of attack.

In finance and insurance, BEC was the top cause of cyber incidents, accounting for 53 percent of all reports.

One notable UK case involved Zephyr Energy, an oil and gas company listed in the UK, which lost £700,000 after a single payment was diverted to a contractor through a highly sophisticated BEC attack.

The UK economy has an estimated total annual cost of cybercrime of £27 billion.

How BEC Works

Most BEC attacks follow a recognizable pattern, understanding this lifecycle is the first step toward stopping it.

Stage 1: Reconnaissance

Through their intelligence gathered on names, positions, and email format from LinkedIn, business sites, and past security breaches, they gain knowledge about who is in charge of who and who is in charge of the money.

Stage 2: Pretexting

Based on the information they have obtained, they will develop a credible pretext, which might be an urgent supplier payment, secret acquisition, or even an urgent update of the bank account number that could seamlessly fit into the working day of the target.

Stage 3: Impersonation

They spoof or closely mimic a trusted email address, they will spoof or even purchase a similar-looking domain that differs from the genuine one by only one letter. So the message appears to come from a genuine colleague or partner.

Stage 4: Pressure

The message applies pressure to act and not to verify its authenticity, usually through the application of authority, confidentiality, or a strict deadline that doesn’t allow for much thinking.

Stage 5: Execution

The victim, thinking that the request is legitimate, transfers the money or provides the information, and by the time it is discovered, the money have been transferred through a chain of accounts and are almost impossible to trace back.

AI Is Making BEC More Dangerous

Here is where things get really concerning, AI is transforming BEC from a social engineering problem into a precision weapon.

AI-Generated Phishing Emails

AI can generate polished emails, mimic tone, summarize past conversations, and adapt language to match the target, what once looked suspicious can now look routine.

Recent data shows that AI-generated phishing emails achieve a 54 percent click-through rate, which dwarfs the 12 percent success rate of traditional, human-written campaigns.

Dual-Channel Attacks

Attackers are increasingly using multiple communication channels, either simultaneously or in sequence, to defeat security protections, a LevelBlue report found that 43 percent of BEC lures were requests for contact, seeking to establish the victim's mobile number or personal email address.

In 66 percent of dual-channel attacks, the attackers tried to move the conversation to SMS messaging, and in 32 percent of cases to messaging apps like WhatsApp, once the conversation moves off email, enterprise security controls become useless.

Deepfake CEO Fraud

Voice cloning and deepfake video calls are being used to impersonate executives during financial approval workflows, confirmed deepfake-enabled BEC events have doubled every six months since mid-2024, and the average successful loss per event is now USD 1.4 million.

In one notable demonstration, Barracuda researchers showed how an attacker could use Microsoft Copilot to escalate a single compromised employee account into a full-scale BEC attack, impersonating a CEO and redirecting a $247,500 wire transfer with minimal manual effort.

AI Email Assistants as Attack Tools

Attackers are now using AI email assistants to accelerate every stage of the attack, in the Barracuda proof-of-concept, the attacker used Copilot to analyze the compromised inbox, identify organizational relationships, and draft phishing emails that matched the employee's writing style.

Copilot was then used to summarize recent financial communications, a single prompt produced a briefing of invoices, pending wire transfers, and other sensitive financial discussions, including a $247,500 wire transfer awaiting final approval.

Why Traditional Defenses Fail

Email security platforms are fundamentally signature-based and content-aware, they look for known malicious links, attachments carrying payloads, and spoofed sending domains, but BEC carries no weapon.

There is no malware, no attachment, and no link to a credential-harvesting page, a BEC email is a perfectly legitimate message, correctly authenticated, sent from a real account or a convincingly registered lookalike domain.

What BEC exploits is not a technical vulnerability, it exploits the psychology of organizational trust.

Organizations without managed detection capabilities experience a median BEC dwell time of over 24 days, that is enough time for an attacker to map a finance team, study ongoing transactions, and strike at exactly the right moment.

Real Scenarios

Scenario 1: Vendor Invoice Scam

The Setup

A manufacturing company of mid-size nature is maintaining its relationship with a supplier of parts for months and receives invoices on a monthly basis, and the finance team knows the routine.

The Attack

An attacker compromises the supplier's email account, they spend weeks reading email threads, learning the language used in financial communications, and understanding the payment approval process.

Then they strike, they send an email that looks like a routine invoice, but with updated bank details, the email is signed with the supplier's name, and it references a real purchase order.

The Result

The finance team processes the invoice, the payment is sent to the attacker's account, by the time the real supplier calls to ask about the overdue payment, the money is gone.

The Lesson

BEC does not need malware, it just needs a believable story and a moment of trust.

Scenario 2: CEO Emergency Situation

The Setup

There is a professional services company based in the UK that has a very busy finance department, the CEO of the company is out of office and hard to reach, and there is an important acquisition process under way.

The Attack

The attacker impersonates the CEO and sends him an email. The email mentions the acquisition, refers to a need for urgent wire transfer to the "new legal counsel," and is marked "confidential."

The Result

The finance director, trying to be helpful to his CEO and not to delay an important process, approves the transfer, the funds go to the account controlled by the attacker, and the CEO, who is contacted later, has no idea what happened.

The Lesson

BEC taps into the desire to help others and fear of authority figures.

How to Defend Against BEC

Protecting from BEC is possible only when technology, process, and human intervention work together.

1. Establish a Verification Process

The verification of any payment request and bank detail change should be conducted via another verified form of communication like a known telephone number and not just via emails no matter how legitimate they might seem.

2. Multi-Factor Authentication (MFA)

The use of MFA will make it harder for attackers to carry out mailbox takeovers because apart from a username and password, they will have to provide one other means of authentication.

3. Educating Employees on BEC Tactics

Perform frequent phishing simulations in order to educate your employees on BEC tactics and the method of verifying anything unusual.

4. Watch Out for Any Changes to Forwarding or Inbox Rules

Attackers will often set up inbox rules that make their actions untraceable; therefore, look out for any suspicious changes to inbox rules that hide their activities.

5. Implement DMARC Enforcement

DMARC protects companies from domain spoofing but a mere fraction of high-profile companies have achieved DMARC enforcement.

6. Use Behavioral Detection

BEC attacks succeed not because defenses are weak, but because BEC was designed to look like a legitimate conversation, shift from blocking at the edge to detecting in the flow.

7. Have an Incident Response Plan

If you are hit, act fast, contact your bank immediately, report the fraud to law enforcement, and work with legal counsel, time is critical when it comes to recovering funds.

Quick Reference: BEC Defense Checklist

Defense Layer

Action

Verification Process

Confirm payment requests through a separate channel

Multi-Factor Authentication

Enforce MFA on all email accounts

Employee Training

Run BEC-specific phishing simulations

Inbox Rule Monitoring

Alert on suspicious forwarding and deletion rules

DMARC Enforcement

Implement p=reject policies

Behavioral Detection

Monitor for anomalous email activity

Incident Response

Have a plan for when BEC succeeds

The Bottom Line

BEC is a US$2.7 billion problem for US and UK firms, and it is getting worse, not better, the FBI reported over $3 billion in losses in 2025, and AI is making attacks more convincing, more personalized, and more scalable.

Traditional email security tools cannot stop BEC because BEC does not carry a weapon, it exploits trust, and trust cannot be blocked by a firewall.

Defending against BEC requires a combination of technology, process, and human vigilance, verify payment requests through a separate channel, enforce MFA, train your employees, monitor for suspicious inbox rules, and have a plan for when an attack succeeds.

The attackers are using AI, you need to use it too.

FAQ Section

What is Business Email Compromise?

This is cyber fraud that involves attackers pretending to be people employees trust to make them conduct financial transactions and give out information.

How much harm can BEC cause to businesses?

According to the FBI, the losses caused by BEC amounted to more than $2.7 billion within a year and rose to more than $3 billion in 2025.

How does AI complicate BEC?

AI has the capability of creating well-written emails, mimicking the tone of messages, summarizing previous conversations, and adjusting language according to the targeted person.

What does a dual channel BEC attack mean?

A dual channel attack means using more than one communication methods, simultaneously or sequentially, for shifting the conversation away from email and bypass enterprise security controls.

Why do traditional email security tools fail against BEC?

BEC carries no malware, no attachment, and no malicious link, the email is a legitimate message, exploiting human trust rather than technical vulnerabilities.

What measures should my company take to prevent BEC?

Make sure there is a verification process in place for any payment request, employ MFA, train employees on BEC, review inbox rules, and be prepared for any incidents.

Sources:

FBI IC3 2025 Annual Report

UK Cyber Security Breaches Survey 2025/2026

Microsoft Digital Defense Report 2025

LevelBlue SpiderLabs (via ComputerWeekly)

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067