// THREAT DETECTION AND DATA PRIVACY TERM

BEC

BEC, or Business Email Compromise, is a type of scam where criminals trick employees into transferring money or sensitive information by impersonating a trusted executive or vendor through email. These sophisticated phishing attacks exploit trust within an organization to commit financial fraud.

BEC — illustration from Wikipedia
Image via Wikipedia

TECHNICAL DEFINITION

Business Email Compromise (BEC) is a sophisticated cybercrime tactic where threat actors employ social engineering, often through email spoofing, to impersonate legitimate entities like executives or vendors, with the goal of defrauding organizations into making unauthorized wire transfers or divulging confidential data. This targeted phishing attack leverages trust relationships to exploit financial systems and data security.

BACKGROUND

Computer security is a subdiscipline within the field of information security. It focuses on protecting computer software, systems, and networks from threats that can lead to unauthorized information disclosure, theft, or damage to hardware, software, or data, as well as to the disruption or misdirection of the services they provide.

READ MORE ON WIKIPEDIA

SYNONYMS & ALIASES

  • Business Email Compromise
  • CEO Fraud
  • Email Account Compromise
  • Whaling Attack
  • Spear Phishing
  • Man-in-the-Email Attack

USAGE NOTE

BEC attacks frequently lead to substantial financial losses and data breaches, emphasizing the critical need for robust employee training and multi-factor authentication.

DEVELOPERS

Organizations developing technology related to BEC.

  • Proofpoint

    A leading cybersecurity company that provides advanced threat protection, information protection, and email security solutions specifically designed to detect and prevent Business Email Compromise (BEC) attacks.

  • Mimecast

    Offers cloud-based email management for security, archiving, and continuity, with robust capabilities for protecting against sophisticated email-borne threats like BEC.

  • Abnormal Security

    Specializes in an AI-native cloud-native security platform that focuses on stopping advanced email attacks, including BEC, spear phishing, and other socially engineered threats.

  • IRONSCALES

    Provides an AI-driven email security platform that helps organizations automatically detect, prevent, and respond to email threats such as BEC, phishing, and impersonation.

  • Microsoft

    Through Microsoft 365 Defender, it offers integrated email security capabilities including Microsoft Defender for Office 365, which uses machine learning and behavioral analysis to protect against BEC, phishing, and other advanced threats.

  • Cisco

    Offers Cisco Secure Email solutions (formerly Cisco Email Security) that provide advanced threat protection against phishing, impersonation, and BEC attacks, leveraging global threat intelligence.

  • Fortinet

    Provides FortiMail, an email security solution that offers multi-layered protection against spam, malware, and advanced email threats like BEC, using a combination of techniques including sandboxing and AI.

  • Trellix

    Formed from the merger of McAfee Enterprise and FireEye, Trellix provides extended detection and response (XDR) solutions that include email security features to identify and mitigate BEC and other sophisticated email threats.

RELATED TERMS IN THREATS & ATTACKS