What is business email compromise?
BEC is a type of cyberattack where criminals impersonate a trusted person such as your CEO, a vendor, or a colleague to manipulate employees into performing sensitive actions. Unlike phishing emails packed with suspicious links, BEC attacks often look completely legitimate.
- $3 billion
losses due to BEC.
- 63%
organizations have faced BEC.
Why is BEC hard to detect?
No malicious links or attachments
BEC emails are mostly plain text, with legitimate-looking attachments or URLs. There's nothing for a URL scanner or attachment sandbox to flag.
Legitimate senders
Attackers spoof display names, register lookalike domains, or compromise real accounts, so the "from" field passes a quick glance.
Bypasses spam filters
No mass sending, no blacklisted IPs, no known malware signatures. BEC emails often score clean.
Exploits authority
A request from a CEO or a known vendor doesn't trigger suspicion. It often means that the request is complied with.
Engineered timing
Attacks land at end of quarter, before a holiday, or mid-transaction, when there's a higher chance of approvals going through without much scrutiny.
Common types of BEC attacks
How does eProtect stop BEC?
Edge blocking before delivery
Threats are intercepted at the mail gateway before they've landed in an inbox and been acted on. eProtect stops BEC at the earliest possible point in the email pipeline.
Sender authentication enforcement
eProtect enforces SPF, DKIM, and DMARC policies at the gateway, blocking emails that fail authentication before they reach the inbox. Unauthenticated messages don't get a second chance.
Display name spoofing detection
Attackers often keep the domain legitimate but fake the display name. eProtect ensures that only certain senders can use certain display names and the others are flagged for further verification.
Lookalike domain detection
Domains like "zohò.com" or "zoh0.com" are designed to deceive at a glance. eProtect identifies and blocks emails from domains that closely mimic your trusted senders.
Behavioral pattern analysis
eProtect senses any differences in usual email receiving patterns such as email sent at odd times, urgent message content, or an unwarranted request, and flags such emails before user interaction.
Why should you choose eProtect for BEC protection?
Cloud-native deployment. No hardware, no complex configuration.
Real-time filtering at the email gateway, before threats reach inboxes.
AES-256 encrypted email archiving with tamper-proof audit trails.
eDiscovery and legal hold for fast incident response and compliance.
Works alongside all cloud and on-premise email providers.
Frequently asked questions
Attackers impersonate trusted senders by spoofing display names, registering lookalike domains that differ by a character or two, or compromising a real account entirely. The goal is to make the sender field pass a quick glance so the request gets acted on before anyone thinks to verify.
BEC involves impersonating someone without actually accessing their account such as through spoofed addresses or lookalike domains. EAC goes a step further: the attacker gains real access to a legitimate account and operates from inside it, making fraudulent requests far harder to distinguish from genuine ones.
Watch for urgent requests involving payments, payroll changes, or wire transfers, especially when they come with pressure to act quickly and bypass normal approval channels. Other red flags include requests to switch to a new bank account, a sender whose email domain differs slightly from the usual one, and instructions that arrive just before a holiday or end of quarter.
Traditional phishing casts a wide net. They're mostly bulk emails with malicious links or attachments aimed at harvesting credentials. BEC is targeted and carries no payload, making it invisible to link scanners and attachment sandboxes. It relies entirely on social engineering rather than malware, which is why it's harder to catch with conventional filters.

