What is business email compromise? Real examples and what it costs

BEC is the scam where criminals get inside a business mailbox and redirect real payments. Here's how it works, what it looks like, and why the warning signs sit unread in your audit logs.

N°001sectionthe short answer

Section 01

The short answer

Business email compromise (BEC) is a scam where a criminal gains access to — or convincingly impersonates — a business email account, then uses it to redirect payments, steal data, or defraud customers and vendors.

N°002sectionhow a bec attack can unfold

Section 02

How a BEC attack can unfold

BEC techniques vary. One possible sequence is:

  • Step 1 — Get in: a phishing email or leaked password gives the attacker access to a real mailbox, often at a small business with no monitoring.
  • Step 2 — Watch silently: the attacker sets up a hidden inbox rule or external forwarding rule so they receive copies of email without logging in again. They learn who pays whom, when, and how invoices look.
  • Step 3 — Strike: when a real payment is due, they send a perfectly-timed email — from the real account or a lookalike — with "updated" bank details. The money goes to the attacker's account.
  • Step 4 — Cover: they delete sent messages and filter replies so the victim doesn't notice until the real vendor asks where their payment is.
N°003sectionreal-world examples

Section 03

Real-world examples

Examples include changed bank details sent from a compromised vendor account, fraudulent wire instructions sent during a real-estate closing, or an impersonated executive requesting an urgent payment. These examples illustrate possible techniques, not the frequency or loss size of a typical incident.

N°004sectionwhy the warning signs are invisible without monitoring

Section 04

Why the warning signs are invisible without monitoring

Some BEC activity may produce supported audit records, such as an unusual sign-in, forwarding change, inbox-rule change, or app grant. Record availability differs by provider, workload, license, configuration, retention, and API coverage.

InboxGuards checks supported records at roughly 5-minute intervals and alerts when a configured indicator matches. It does not block activity or guarantee that a provider will expose an event before fraud occurs.

N°005sectionmonitoring price and boundary

Section 05

Monitoring price and boundary

InboxGuards monitoring is $4 per user per month with no minimum — $480 a year for a 10-person business, or $400 billed annually. The subscription covers monitoring, alerts, reports, and general response guidance. It does not provide hands-on incident response, prevent every loss, or determine insurance outcomes.

N°006faqcommon questions

FAQ

Common questions.

What is business email compromise in simple terms?
A scam where a criminal gets access to — or convincingly impersonates — a business email account and uses it to redirect payments, for example by sending changed bank details during a genuine invoice conversation.
How do attackers stay hidden inside a mailbox?
They may create inbox rules, forwarding, or app grants to conceal or extend access. Some related activity can appear in supported provider audit records, subject to provider and API limits.
How can a small business detect BEC early?
Review supported audit records for indicators such as unexpected-location sign-ins, forwarding changes, and inbox-rule changes. InboxGuards checks supported records roughly every 5 minutes and alerts when a configured rule matches, for $4 per user per month.

Put an alarm on my inbox

$4 per user / month · 30-day money-back guarantee