Business email compromise (BEC)
Business email compromise (BEC) is a scam in which an attacker impersonates a trusted party — an executive, supplier, or colleague — to trick an organisation into transferring money or sensitive data.
How to recognise
BEC predates AI and has long been one of the costliest forms of corporate fraud, traditionally relying on a spoofed or compromised email account and a plausible, urgent request — a "change of bank details," a "confidential acquisition," an overdue invoice. Generative AI now supercharges it: flawless, personalised messages at scale, and increasingly a deepfake voice or video call to overcome any doubt the email alone leaves.
The defences are procedural and unglamorous, and they hold regardless of how convincing the impersonation is: independent callback verification on a known number, mandatory approval steps and delays for unusual payments, and segregation of duties so the person requesting a transfer is never the one approving it.
Related warrier.ai coverage
Everyone on the Call Was Fake but Him: The $25 Million Arup Deepfake Meeting · Fraud & Deception