{"id":1217,"date":"2026-09-13T19:53:21","date_gmt":"2026-09-13T19:53:21","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1217"},"modified":"2026-09-13T19:53:21","modified_gmt":"2026-09-13T19:53:21","slug":"bec","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/bec\/","title":{"rendered":"BEC (Business Email Compromise)"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: BEC (BUSINESS EMAIL COMPROMISE)\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Business email compromise carries no malicious link and no attachment. There is nothing for a scanner to find, which is exactly why it works.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Email<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Business email compromise, or BEC, is a fraud in which an attacker impersonates someone trusted and asks a person to move money or send data. There is usually no malware involved. The message is plain text, it references a real transaction, and it arrives at a plausible moment. The target is a business process, not a system.<\/p>\n<\/div>\n\n<p>That distinction decides which defences matter, because most of the email security stack is built to find things this attack does not contain.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#evades\">Why BEC evades email security<\/a><\/li>\n    <li><a href=\"#variants\">The five BEC variants<\/a><\/li>\n    <li><a href=\"#impersonation\">Three ways they impersonate<\/a><\/li>\n    <li><a href=\"#stops\">What actually stops it<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"evades\">Why BEC evades email security<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 200\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"A conventional email attack carries a payload that scanners detect, while a BEC email carries none and passes inspection.\">\n  <defs><marker id=\"be\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <text x=\"14\" y=\"22\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#6b7086\">CONVENTIONAL ATTACK<\/text>\n  <rect x=\"14\" y=\"30\" width=\"196\" height=\"52\" rx=\"12\" fill=\"#e3f0e9\"\/>\n  <text x=\"112\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#3a6f5d\">Link or attachment<\/text>\n  <text x=\"112\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Something to analyse<\/text>\n  <line x1=\"214\" y1=\"56\" x2=\"240\" y2=\"56\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#be)\"\/>\n  <rect x=\"248\" y=\"30\" width=\"180\" height=\"52\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"338\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#2f6f96\">Scanner inspects<\/text>\n  <text x=\"338\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Sandbox, reputation, signature<\/text>\n  <line x1=\"432\" y1=\"56\" x2=\"458\" y2=\"56\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#be)\"\/>\n  <rect x=\"466\" y=\"30\" width=\"280\" height=\"52\" rx=\"12\" fill=\"#cfd5f2\"\/>\n  <text x=\"606\" y=\"60\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">Blocked<\/text>\n\n  <text x=\"14\" y=\"112\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#6b7086\">BUSINESS EMAIL COMPROMISE<\/text>\n  <rect x=\"14\" y=\"120\" width=\"196\" height=\"52\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"112\" y=\"142\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#a2603a\">Plain text request<\/text>\n  <text x=\"112\" y=\"160\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Nothing to analyse<\/text>\n  <line x1=\"214\" y1=\"146\" x2=\"240\" y2=\"146\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#be)\"\/>\n  <rect x=\"248\" y=\"120\" width=\"180\" height=\"52\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"338\" y=\"142\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#2f6f96\">Scanner inspects<\/text>\n  <text x=\"338\" y=\"160\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Finds no payload<\/text>\n  <line x1=\"432\" y1=\"146\" x2=\"458\" y2=\"146\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#be)\"\/>\n  <rect x=\"466\" y=\"120\" width=\"280\" height=\"52\" rx=\"12\" fill=\"#efe4f0\"\/>\n  <text x=\"606\" y=\"143\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">Delivered, and read as routine<\/text>\n  <text x=\"606\" y=\"161\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#6b4576\">The decision now sits with a person<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>What is missing<\/th><th>Why it matters<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>No malicious attachment<\/td><td>Sandboxing has nothing to detonate<\/td><\/tr>\n    <tr><td>No link to a fake login page<\/td><td>Reputation and rewriting have no destination to check<\/td><\/tr>\n    <tr><td>No malware<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">Endpoint protection<\/a> is never engaged, because nothing is executed<\/td><\/tr>\n    <tr><td>Low volume<\/td><td>A handful of messages to named individuals, not a campaign that trips volume analysis<\/td><\/tr>\n    <tr><td>Genuine context<\/td><td>Real invoice numbers, real project names and correct timing, often taken from prior reconnaissance<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"variants\" class=\"c-sage\">The five BEC variants<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Variant<\/th><th>How it runs<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Executive fraud<\/td><td>A message appearing to come from a founder or finance lead requesting an urgent transfer, usually while they are known to be travelling<\/td><\/tr>\n    <tr><td>Supplier invoice fraud<\/td><td>A real supplier relationship is used to request that bank details be updated on the next invoice. The costliest variant, because the amount is expected and the payment is routine<\/td><\/tr>\n    <tr><td>Payroll diversion<\/td><td>A request to human resources to change an employee&#8217;s salary account, timed just before a pay run<\/td><\/tr>\n    <tr><td>Legal or acquisition pretext<\/td><td>Confidentiality is used to prevent the target from verifying with anyone else, often framed around a deal or an audit<\/td><\/tr>\n    <tr><td>Data request<\/td><td>No money at all. Tax records, employee details or customer data are requested, which is then used to make a later fraud far more convincing<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Supplier fraud is the one to plan for<\/p>\n  <p>Executive fraud gets the attention, but a request from a founder to move money is unusual enough that a careful employee may pause. A supplier asking to update bank details is not unusual at all. The invoice is genuine, the amount matches an existing order, the sender knows the history of the account, and paying it is somebody&#8217;s routine job. Companies that train staff only to be suspicious of the chief executive remain exposed to the variant that empties more accounts.<\/p>\n<\/div>\n\n<h2 id=\"impersonation\" class=\"c-plum\">Three ways they impersonate<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Method<\/th><th>What it looks like<\/th><th>What limits it<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Lookalike domain<\/td><td>A registered domain one character away from the real one, or a different top-level extension<\/td><td>Detection of newly registered and visually similar domains, plus external sender tagging<\/td><\/tr>\n    <tr><td>Display name spoof<\/td><td>The name shown reads correctly while the underlying address is a free mail account. Effective because mobile clients hide the address<\/td><td>Header analysis and warning banners on mismatch<\/td><\/tr>\n    <tr><td>Compromised real account<\/td><td>The attacker is signed in to a genuine mailbox, often a supplier&#8217;s, and replies inside an existing thread<\/td><td>Nothing in the mail itself. Only <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a>, sign-in anomaly detection and out-of-band verification<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The third method passes every authentication check<\/p>\n  <p>Domain authentication protects your domain from being forged. It cannot help when the mail is genuinely sent from the account it claims, because the attacker has the password. Every signature validates, alignment passes, the message arrives inside a thread the recipient started, and the reply quotes the conversation above it. This is why account takeover and BEC are the same problem viewed from two ends, and why enforcing multi-factor authentication across suppliers matters as much as enforcing it internally.<\/p>\n<\/div>\n\n<h2 id=\"stops\" class=\"c-sky\">What actually stops it<\/h2>\n\n<p>Because a BEC message is technically legitimate, the controls that work are procedural. They are cheap, and they are the part most companies skip.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Control<\/th><th>How it works<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Out-of-band verification<\/td><td>Any bank detail change or unusual payment confirmed by phone, on a number already on file, never one supplied in the email<\/td><\/tr>\n    <tr><td>Dual authorisation<\/td><td>A second person approves payments above a threshold, so no single compromised mailbox completes a transfer<\/td><\/tr>\n    <tr><td>A written bank change process<\/td><td>Updates to supplier account details follow a fixed procedure regardless of who asks or how urgent it sounds<\/td><\/tr>\n    <tr><td>Removing urgency as an override<\/td><td>Staff are told explicitly that no real executive will penalise them for verifying. Urgency is the pressure the whole attack depends on<\/td><\/tr>\n    <tr><td>External sender tagging<\/td><td>A visible banner on mail from outside the organisation, which defeats most display name spoofing at a glance<\/td><\/tr>\n    <tr><td>MFA everywhere<\/td><td>Prevents the account takeover that makes the hardest variant possible<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Osto reduces the two impersonation methods that live in the mail itself. Inbound email security flags lookalike domains and display name mismatches before delivery, and content filtering limits reach to the credential harvesting pages that lead to account takeover in the first place.<\/p>\n\n<p>The harder variant is addressed from the identity side. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">Multi-factor authentication<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">identity and access management<\/a> make a mailbox takeover materially harder, and because sign-in events and mail events land in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">the same SIEM<\/a>, an unfamiliar login followed by mailbox rule changes reads as one pattern rather than two unrelated entries in separate tools. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/security-awareness-training\/\">Security awareness training<\/a> covers the recognition side, and the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">incident response<\/a> plan covers what to do in the hour after a payment goes out, when recovery is still possible.<\/p>\n\n<p>What no security platform provides is the payment control. Out-of-band verification and dual authorisation are decisions your finance function makes, and they stop more BEC than any product does. Documented alongside the technical controls, they also satisfy what <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> expect around authorisation and segregation of duties.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Catch the login, not just the email<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Inbound email security, enforced MFA and identity events correlated in one SIEM, so a mailbox takeover shows up as a pattern instead of a surprise.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is BEC?<\/summary>\n  <p>Business email compromise is a fraud in which an attacker impersonates a trusted party, usually an executive or a supplier, and asks someone to transfer money, change bank details or send sensitive data. It generally carries no malware.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between BEC and phishing?<\/summary>\n  <p>Phishing typically wants a credential and uses a link to a fake login page. BEC wants an action, most often a payment, and often contains no link at all. Phishing is frequently sent in volume, while BEC targets a named individual with real business context.<\/p>\n<\/details>\n\n<details>\n  <summary>Does email authentication stop BEC?<\/summary>\n  <p>Partly. Domain authentication stops attackers forging your own domain, which removes one method. It does nothing against lookalike domains, display name spoofing or mail sent from a genuinely compromised account.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the single most effective control?<\/summary>\n  <p>Verifying bank detail changes by phone, using a number already held on file rather than one given in the message. It is free, and it defeats every variant including the one sent from a real compromised mailbox.<\/p>\n<\/details>\n\n<details>\n  <summary>What should you do after a fraudulent payment?<\/summary>\n  <p>Contact the bank immediately and request a recall, because the first hours matter most. Preserve the mail headers, check the mailbox for forwarding rules the attacker may have created, reset credentials, and report it to the relevant authority. Your <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">incident response<\/a> plan should already name who does each of these.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/email-security\/\">Email Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sso\/\">SSO<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/security-awareness-training\/\">Security Awareness Training<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident Response<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Business email compromise carries no malicious link and no attachment. There is nothing for a scanner to find, which is\u2026<\/p>\n","protected":false},"author":8,"featured_media":1218,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[618,619,620,258],"class_list":["post-1217","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-bec","tag-bec-attack","tag-bec-vs-phishing","tag-business-email-compromise"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1217","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1217"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1217\/revisions"}],"predecessor-version":[{"id":1219,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1217\/revisions\/1219"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1218"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1217"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1217"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1217"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}