BEC is the scam where criminals get inside a business mailbox and redirect real payments. Here's how it works, what it looks like, and why the warning signs sit unread in your audit logs.
Section 01
Business email compromise (BEC) is a scam where a criminal gains access to — or convincingly impersonates — a business email account, then uses it to redirect payments, steal data, or defraud customers and vendors.
Section 02
BEC techniques vary. One possible sequence is:
Section 03
Examples include changed bank details sent from a compromised vendor account, fraudulent wire instructions sent during a real-estate closing, or an impersonated executive requesting an urgent payment. These examples illustrate possible techniques, not the frequency or loss size of a typical incident.
Section 04
Some BEC activity may produce supported audit records, such as an unusual sign-in, forwarding change, inbox-rule change, or app grant. Record availability differs by provider, workload, license, configuration, retention, and API coverage.
InboxGuards checks supported records at roughly 5-minute intervals and alerts when a configured indicator matches. It does not block activity or guarantee that a provider will expose an event before fraud occurs.
Section 05
InboxGuards monitoring is $4 per user per month with no minimum — $480 a year for a 10-person business, or $400 billed annually. The subscription covers monitoring, alerts, reports, and general response guidance. It does not provide hands-on incident response, prevent every loss, or determine insurance outcomes.
FAQ