Skip to main content
Cybersecurity Awareness Month: New videos, games, and ready-to-use resources
Blog
Agentic Email Security

Why BEC Bypasses Email Filters: A Practical Framework to Detect, Verify, and Stop Fraudulent Requests

OCTOBER 5, 202623 MIN READ
Adaptive TeamAdaptive Team

Read summarized version with

Why BEC Bypasses Email Filters: A Practical Framework to Detect, Verify, and Stop Fraudulent Requests

Key takeaways

  • Understanding why BEC bypasses email filters begins with a simple mismatch: gateways inspect files, links, and sender infrastructure, while business email compromise delivers a plausible request and nothing else;
  • Authentication explains much of why BEC bypasses email filters: passing SPF, DKIM, and DMARC confirms that a message travelled through an authorized domain, and it never confirms that the person named in the signature approved the payment;
  • Lookalike domains, hijacked email threads, and compromised supplier mailboxes give a fraudulent instruction the reputation and conversation history of a legitimate business relationship;
  • Voice cloning, synthetic video, and generative writing tools remove the grammar errors and awkward phrasing that once separated a fraudulent request from an authentic one;
  • Independent callbacks, dual approval, and prevalidated beneficiary accounts convert why BEC bypasses email filters from an unsolved detection problem into a controlled payment decision;
  • Continuous cybersecurity awareness training aimed at finance, payroll, procurement, legal, and executive workflows builds the verification habit that a clean inbound message is engineered to skip;
  • Reporting rates, verification adherence, and containment speed measure whether cybersecurity awareness training holds under deadline pressure, while course completion percentages measure attendance only.

A finance manager opens a short message from a supplier that has invoiced the company for six years. The note references the correct project, sits inside an existing email thread, and asks that this month's payment go to an updated bank account. Nothing in the message can be scanned, because there is no attachment, no link, and no malicious code anywhere in it.

That is the operational shape of business email compromise (BEC), and it explains why BEC bypasses email filters with unsettling regularity. The gateway completes its inspection, finds no payload, and delivers a message whose entire purpose is to move money to a cyberattacker.

Business email compromise succeeds by bypassing technical controls through legitimate-looking requests in existing threads with no payloads to scan

According to the FBI's 2025 Internet Crime Report (released April 2026), business email compromise (BEC) remains the persistent risk at the costly center, accounting for $3.046 billion in losses (24,768 incidents, averaging $123,000 per case).

A control gap that costs an average organization six figures per incident calls for a framework in place of a warning poster. This guide covers:

  • The detection mechanics behind why BEC bypasses email filters, from signature matching to sender reputation;
  • The identity techniques that make a fraudulent sender look authentic, including lookalike domains, account takeover, and vendor thread compromise;
  • The persuasion and AI tradecraft that turns a plain-text request into an authorized transaction;
  • The technical telemetry, payment controls, and cybersecurity awareness training that close the gap gateways leave open;
  • The verification steps, incident response sequence, and behavioral metrics that prove the defense works.

Filters clear the message, and the fraudulent payment leaves through an approved workflow minutes later. Adaptive Security applies intent analysis and behavioral signals to catch what native inbox filters deliver.

Explore the platform

What Is Business Email Compromise, and Why Does BEC Bypass Email Filters?

Business email compromise is a social engineering fraud in which a cyberattacker impersonates a trusted person, or takes over a legitimate mailbox, to trigger an unauthorized business action. The fraud reaches the inbox because conventional controls prioritize technical indicators, while the fraudulent request exploits trust, plausible business context, and normal workflows. Email account compromise (EAC) is the account-takeover path that makes such a request appear genuine, although a BEC attempt can also arrive from a lookalike address or a compromised partner account.

The scale of that exposure is a workforce problem before it is a mail-routing problem. According to Verizon's 2026 Data Breach Investigations Report, 62% of confirmed breaches involve a human element. Every one of those decisions happened after a technical control had already allowed the message through.

How Is BEC Different From Traditional Phishing?

Traditional phishing usually presents a technical signal that security tools can inspect, such as a suspicious domain, a malicious attachment, a credential-harvesting URL, or a file that behaves like malware. BEC removes those signals. A message may carry no attachment, link to no website, and contain nothing technically hostile, while asking an employee to change payment details, approve a transfer, share tax information, or send a confidential file.

That design changes the detection problem. An email filter can compare sender reputation, inspect headers, scan attachments, and analyze links, but it cannot reliably determine whether a request from a familiar executive fits the company's current deal, whether a supplier truly changed its bank account, or whether a lawyer urgently needs a document. Those judgments require business context and human verification.

BEC also borrows the vocabulary of ordinary work. Requests such as "please process this invoice," "send the employee roster," or "I am in a meeting, so do not call" may arrive during a legitimate payment cycle and sit inside an email thread copied from a real conversation. Employees are not failing because they lack intelligence; they are being asked to resolve identity and workflow deception that technical controls were never built to settle.

The response is procedural and behavioral. Independent verification should be mandatory for payment changes, payroll updates, sensitive-data requests, and unusual executive instructions, using a known phone number or an approved collaboration channel instead of contact details supplied in the suspicious message. Phishing simulations for BEC and other social engineering scenarios give employees controlled practice in recognizing and reporting these requests before a real transaction is at stake.

What Are the Common BEC Variants and Requests?

BEC describes a family of fraud patterns rather than one fixed email format. Each variant targets a different workflow, and each has a corresponding control that removes email as the sole authorization channel. Common variants include:

  • Executive impersonation: A cyberattacker poses as a CEO, CFO, or department leader and requests a wire transfer, confidential information, or an urgent purchase. Verification should run through a separate channel, supported by approval controls that do not depend on email alone.
  • Invoice fraud: A criminal impersonates a supplier or alters payment instructions so that an approved invoice sends funds to a fraudulent account. Account changes should be confirmed with the vendor through a previously verified contact and require dual authorization.
  • Payroll diversion: A cyberattacker requests a change to an employee's direct-deposit details, often through a compromised employee account or a forged message from human resources. Changes belong in an authenticated payroll system and should be confirmed with the employee through an established channel.
  • Attorney impersonation: A criminal poses as legal counsel handling a confidential acquisition, settlement, or regulatory matter. Secrecy and urgency trigger verification; they never justify skipping it.
  • Gift-card fraud: A cyberattacker impersonates an executive and asks an employee to buy gift cards or send redemption codes. Gift-card purchases belong under a documented policy that executives and finance staff cannot override by email.
  • Data theft: A fraudulent request seeks tax forms, customer records, employee data, credentials, or intellectual property in place of money. The requester's identity, business need, and approved transfer method should be confirmed before anything is shared.

The FBI Internet Crime Complaint Center's 2024 BEC guidance defines BEC and EAC as schemes that target people performing legitimate transfer-of-funds requests, and it warns that criminals also solicit personally identifiable information to compromise related accounts. Financial verification therefore operates as a security control, and it deserves the same rigor as one.

Which Roles Face the Greatest BEC Exposure?

BEC concentrates on roles with authority, payment access, sensitive data, or the ability to move a request through the organization. Executives attract impersonation attempts because their names carry weight, whereas finance, payroll, procurement, and accounts-payable teams can release money or modify vendor records. Legal teams handle confidential transactions that a criminal can cite to justify secrecy, and human resources teams control employee records and payroll workflows.

New employees face additional exposure because they have not yet learned internal approval habits, reporting routes, or the communication patterns of senior colleagues. Risk-based preparation therefore starts with the workflow a criminal would actually target.

Finance and procurement teams need invoice-change phishing simulations, payroll staff need practice verifying direct-deposit updates, and executives and their assistants need impersonation scenarios that rehearse the pressure they will actually face. Onboarding should give new employees concrete examples of legitimate escalation paths, and leaders should understand that their own authority is what makes their identity valuable to a cyberattacker.

The strongest control is a shared expectation that urgent requests receive more scrutiny than routine ones. When employees can pause, verify, and report without blame, they become an active detection layer, and disciplined verification turns the judgment BEC targets into a dependable control.

Executive impersonation and invoice fraud target specific workflows, while generic annual courses rehearse none of them. Rehearse the requests each team actually receives with Adaptive Security's role-specific phishing simulations.

Take a self-guided tour

Why BEC Bypasses Email Filters: What Secure Email Gateways Actually Inspect

Answering why BEC bypasses email filters requires a clear picture of what a gateway measures before delivery. Secure email gateways evaluate infrastructure, files, links, and traffic patterns, and they perform that work well. Their inspection pipeline was built to answer whether a message carries something dangerous, which is a different question from whether a request should be authorized by the person receiving it.

According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, phishing and spoofing generated 191,561 complaints, the highest number of reports. Volume at that scale is exactly what signature and reputation systems were designed to absorb, and absorbing it is why the small number of clean, targeted messages matters so much.

What Technical Indicators Are Email Filters Built to Detect?

Email filters evaluate measurable signals at the message, sender, domain, and traffic levels. Each control has a defined scope, and each scope has an edge that a plain-language payment request can step around. The main inspection layers include:

  • Signature-based matching: This layer compares message content, file characteristics, and known cyberattack patterns against previously identified samples. A recognized malware hash, familiar phishing template, or known malicious phrase can be blocked within seconds. The approach depends on reuse, and a BEC operator can write a new sentence for every target.
  • Sender reputation: Filters weigh the history of the sending domain, IP address, mailbox, and authentication results, checking whether the sender has delivered legitimate mail and whether the domain was registered recently. Reputation is effective against disposable infrastructure. It becomes far less decisive once a criminal controls a legitimate supplier mailbox or a clean lookalike domain.
  • Blocklists: These rely on known bad indicators, including suspicious IP addresses, domains, URLs, file hashes, and sender identities. A blocklist stops a campaign that has already been reported. It cannot stop an address that no one has yet had a reason to classify as dangerous.
  • Malware scanning: Attachments, and sometimes message bodies, are inspected for executable code, scripts, weaponized documents, and exploit behavior. A fraudulent invoice carrying a malicious spreadsheet creates a clear detection opportunity. A text-only request removes it, because there is nothing to detonate, quarantine, or match against a signature.
  • URL reputation: Links are checked against databases of known malicious websites and analyzed for redirection. The control matters against credential phishing, where a suspicious or shortened domain exposes the scheme. A message that simply asks for confirmation once payment is sent contains no link to evaluate.
  • Attachment analysis: File type, origin, macros, embedded objects, and unusual content reveal fake invoices, weaponized payroll spreadsheets, and documents that attempt to execute code. A request that includes the fraudulent bank details in the message body itself gives that control nothing to examine.
  • Volume and policy analysis: Filters watch for spikes in outbound messages, unusual recipient patterns, sensitive data leaving the organization, and communications that breach rules for regulated information. Policy engines can flag a bulk transfer of payroll records. They are far weaker when one cyberattacker asks one employee to perform one action inside normal business volume.

Which Signals Are Most Likely to Miss Clean BEC?

Clean BEC stays inside the boundaries of ordinary email behavior. It does not need to defeat every control; it only needs to avoid enough indicators to reach a person with authority, access, or payment responsibility. The hardest signals for an automated system to evaluate are:

  • Intent: A filter can spot words such as urgent, wire, or confidential, and it cannot determine whether a genuine executive or an impostor wants the recipient to move money;
  • Business context: The message may cite a real vendor, an active project, or a normal payroll cycle, while the filter lacks the decision history to judge whether the request fits current operations;
  • Authority: A request from a CFO, a manager, or a long-standing supplier reads as legitimate even when the sender address is subtly altered or the mailbox has been taken over;
  • Conversation continuity: A reply placed inside an existing thread inherits the tone of prior messages, so thread history raises trust where it should raise an alert;
  • Reasonableness: Asking to update the account for the next payment is not inherently malicious, and the danger sits in the changed destination rather than in grammar or file structure;
  • Human pressure: A gateway can score technical risk, and it cannot measure the effect of a deadline, executive authority, fear of delaying payroll, or reluctance to appear unhelpful.

BEC is therefore an intent-driven fraud with the payload removed entirely. The message delivers a decision, because the criminal wants an employee to authorize a transfer, disclose sensitive data, or purchase gift cards.

That pattern now dominates the wider breach picture. According to Verizon's 2026 Data Breach Investigations Report, system intrusion accounted for 61% of breaches analyzed, with social engineering ranking as the third most common breach pattern in the dataset.

Why Can a Suspicious Financial Request Still Be Allowed?

Secure email gateways operate under a false-positive tradeoff. Quarantining every message containing words such as payment, bank, payroll, invoice, or urgent would block legitimate work across finance, procurement, human resources, and executive operations. Organizations then lose business hours or weaken the rules until essential correspondence flows again.

The same tradeoff applies to behavioral policy rules. A gateway can demand extra scrutiny when an external sender requests a bank-account change, but the rule still has to accommodate genuine vendor updates and routine finance activity. A narrow rule misses fraud, whereas a broad rule generates constant alerts that teach employees and analysts to dismiss warnings.

This boundary is not a failure of email security controls. Gateways remain valuable for filtering malicious infrastructure, dangerous files, deceptive links, and known cyberattack patterns, and they were never built to decide whether a plain-language request suits a specific employee at a specific moment. Consider four messages:

  • Please change the bank details for the next invoice;
  • Release the payment before the end of the day;
  • Send the updated payroll file to this personal address;
  • Buy 10 gift cards and send the redemption codes.

None of the four requires a malicious link or attachment, and none breaches a universal policy rule. Each becomes dangerous because of the requested action, the recipient's authority, and the surrounding business context, which means a control that blocks only technical cyber threats will deliver all four to the inbox.

The practical answer is a second control layer that evaluates human decisions rather than message artifacts. Second-channel confirmation through a previously verified phone number, a known collaboration account, or an established approval workflow should be mandatory for high-impact requests, even when the email looks familiar. The goal of that habit is not distrust of every message; it is a clear separation between the appearance of a request and the authority to approve it.

Plain-language payment requests reach the inbox because no gateway rule weighs business context at delivery time. Add LLM reasoning and intent analysis over Microsoft and Google with Adaptive Security.

Book a demo

Why BEC Bypasses Email Filters With Clean, Text-Only Messages

The tradecraft behind a clean message is deliberate, patient, and rehearsed. A cyberattacker who has read months of correspondence knows the payment calendar, the approval chain, and the phrasing each participant uses, and that knowledge does the work a malicious attachment used to do. Understanding why BEC bypasses email filters at this level means examining how trust is manufactured before any money is requested.

According to Verizon's 2026 Data Breach Investigations Report, pretexting entered the report as a separately tracked initial access vector at 6% of breaches, alongside phishing at 16%, after a run of high-profile intrusions that opened with a fabricated scenario instead of a malicious link.

How Does BEC Build Conversational Trust Before the Fraud?

Conversational trust is difficult to classify because the opening message asks for nothing sensitive. A compromised executive, supplier, attorney, or employee account sends a harmless reply, promising to review a document or suggesting a conversation tomorrow. That message establishes presence inside a legitimate exchange and buys time to study names, responsibilities, writing habits, signatures, and approval patterns.

The criminal then mirrors the organization's correspondence cadence. If a finance manager typically sends two short replies before approving an invoice, the fraudulent account follows that rhythm, and if a department head writes brief mobile responses while travelling, the imitation does the same. Perfect technical imitation is unnecessary, because a familiar interaction simply does not trigger the recipient's expectation of danger.

Delay is part of the method. A harmless exchange about an invoice, a payroll correction, an acquisition document, or vendor onboarding creates a commitment to keep responding, so that refusing the eventual request feels less like blocking a stranger and more like interrupting an established business process.

Security teams should treat that progression as a behavioral signal in its own right. A message that looks benign in isolation becomes high risk the moment it introduces a new payment destination, requests secrecy, changes an approval path, or manufactures urgency after a stretch of ordinary conversation. Phishing simulations that reproduce realistic business context let employees practice spotting those shifts without being blamed for having answered a convincing exchange.

Why Do Thread Hijacking and Cloud Collaboration Abuse Defeat Filters?

Thread hijacking defeats content-based detection because the fraudulent instruction arrives inside a conversation with a legitimate history. After gaining access to a mailbox, the criminal searches for open invoices, vendor negotiations, legal discussions, payroll changes, and executive requests, then replies within the existing thread, preserving the subject line, quoting prior messages, and keeping the original participants and formatting.

That activity erases the warning signs associated with a new phishing email. The sender address is valid, authentication checks pass because the message genuinely comes from a real account, and the content can be plain text while the earlier messages supply the credibility.

Cloud collaboration abuse extends the deception beyond the inbox. A compromised file-sharing account can expose acquisition files, payment schedules, legal correspondence, and internal contact lists that help a criminal construct a credible request, delivered through a familiar shared document or a legitimate collaboration notification. The channel changes, and the objective holds steady: make the request appear to originate from a trusted identity operating inside a real workflow.

Unusual formatting techniques sometimes accompany these cyberattacks. Reverse text, bidirectional scripts, manipulated CSS, malformed archives, and nested archives can interfere with scanners or hide a payload, and personal email providers add further ambiguity. Analysts should recognize these techniques, though they remain secondary, because most BEC needs no encoding trick when identity deception and a plausible request already produce compliance.

The practical response examines account behavior and business context together. New forwarding rules, unfamiliar sign-ins, unusual mailbox searches, changed reply patterns, and access to sensitive threads matter more than whether the final message contains malware. Employees need a correspondingly simple rule: verify payment changes, confidential requests, and unusual instructions through a known channel instead of replying inside the same conversation.

How Does Business-Process Pressure Turn a Clean Message Into Fraud?

Business-process pressure supplies timing and force. Criminals target predictable moments when employees already expect urgent requests, including quarter-end close, invoice deadlines, payroll processing, acquisitions, tax payments, and supplier payment cycles. A message does not have to invent a crisis when the corporate calendar provides one.

The fraud sharpens when urgency is paired with a restriction on verification. A fabricated legal matter can invoke attorney-client confidentiality to discourage forwarding, a supposed acquisition can be labelled confidential so that employees hesitate to involve colleagues, and a payroll correction can be framed as time-sensitive because missing the processing window would delay wages. These requests exploit legitimate duties, and careless behavior plays no part in them.

Procedural friction at the point of financial or data release is the most reliable counterweight. An independent callback should be mandatory for bank-detail changes, executive requests should be confirmed through a known phone number, and employees need explicit permission to pause a confidential request that conflicts with standard approval controls.

Analysts must also separate payload analysis from business-context analysis. Payload analysis asks whether the message contains a malicious file, dangerous link, obfuscated script, or suspicious archive. Business-context analysis asks whether the sender's identity, request, timing, confidentiality demand, payment destination, and approval path fit normal operations.

A message can pass the first test and fail the second.

That distinction prevents a common investigative error, which is closing a clean email as safe because it contains no malware. The accurate conclusion is narrower: the message is malware-free, and its requested action may still be fraudulent.

A conversation that ran for weeks before the payment request reads as ordinary relationship management. Score tone shifts and behavioral anomalies inside email threads with Adaptive Security's Cloud Email Security.

Explore the platform

How Cyberattackers Impersonate Executives, Vendors, and Trusted Contacts to Bypass Email Filters

Business email compromise sender spoofing methods leave different evidence

Sender identity and business legitimacy are separate properties, and confusing the two is a large part of why BEC bypasses email filters. Display-name spoofing changes what recipients notice, address spoofing attempts to falsify the sender used for delivery, lookalike domains create new addresses that resemble trusted ones, and compromised accounts send from an infrastructure the organization already recognizes. Each method reaches the inbox, and each leaves different evidence to inspect before a payment, credential change, or data release proceeds.

How Does Sender-Identity Deception Work?

Sender-identity deception works because the visible From name is only one layer of an email's identity. A criminal can write "Jane Smith, CFO" in the display-name field while sending from an unrelated address, or register a lookalike domain such as jane.smith@acme-co.com when the real organization uses acme.com. In a mobile notification or a crowded inbox, the message reads as familiar even though the underlying address never matches the executive's actual account.

True address spoofing is a different technique. The criminal attempts to transmit a message that claims to originate from the real domain by exploiting weak authentication, misconfigured infrastructure, or a sending service permitted to use that domain. SPF checks whether the sending server is authorized for a domain, DKIM checks whether a cryptographic signature validates against a published key, and DMARC checks whether the authenticated domain aligns with the visible From domain before applying the recipient's policy.

Those controls answer a narrower question than employees assume. A passing result shows that a message was authorized by a domain or signed with a valid key, and it does not prove that the CFO wrote the request, that the supplier approved a bank-account change, or that the instruction fits normal business practice. When a cyberattacker controls the sending domain, SPF and DKIM pass, DMARC passes once alignment is satisfied, and the message is authenticated as having travelled through that domain without being validated as a legitimate business decision.

Lookalike and typosquatted domains exploit the gap between technical validation and human recognition. A newly registered domain carries no adverse history, leaving reputation systems with little evidence to weigh, and a criminal can substitute a visually similar character, add a geographic abbreviation, or insert a hyphen that disappears in a quick glance. Because the domain's DNS records and signing keys belong to the criminal, the message passes SPF, DKIM, and DMARC for its own infrastructure.

Defenders should therefore read authentication results alongside domain age, registration changes, executive relationships, payment history, and operational context. Employees do not need to distrust every authenticated message; they need one clear rule for high-impact requests, which is to verify through a separate, known channel. A finance employee should call a previously stored vendor number before changing payment instructions, and an executive assistant should confirm an urgent transfer through an established approval workflow, never by replying to the message.

What Is Legitimate-Account Compromise and Email Account Compromise?

Legitimate-account compromise, commonly called email account compromise or EAC, hands a criminal the authority and context that spoofing only imitates. Credentials may be obtained through phishing, an active session may be stolen, an OAuth grant may be abused, or an internal identity provider may be compromised. Once inside, the criminal can read conversations, learn approval habits, monitor invoice cycles, and pick the moment when a fraudulent request will look routine.

Stolen credentials remain the connective tissue of this entire pattern. According to Verizon's 2026 Data Breach Investigations Report, stolen credentials were involved in 39% of breaches across the full attack chain.

Account takeover also creates concealment options that an external spoof cannot easily reproduce. Inbox rules can copy selected messages to an outside address, replies can be moved into obscure folders, and mailbox delegations can preserve access after a password change. Unauthorized OAuth grants provide persistent access to mail and files without repeated password entry, and a compromised internal account is hard to spot because messages originate from a real employee, travel through expected services, and inherit an established reputation.

The key investigative question is not only whether the From address belongs to the organization. Analysts must establish whether the account was used by the authorized person, for an authorized purpose, at that time.

Identity and mailbox telemetry belong in that review alongside the message itself. Unfamiliar sign-in locations, impossible travel, new devices, authentication-method changes, newly approved applications, forwarding destinations, delegate additions, and unusual mailbox searches all carry weight. Suspicious sessions and OAuth grants should be revoked, unauthorized rules removed, credentials rotated, and evidence preserved before any message is deleted.

A strong control set separates authority from access. Phishing-resistant multifactor authentication belongs on privileged and finance-linked accounts, third-party application consent should be limited, external forwarding should raise an alert, and payment or payroll changes should require independent approval. Together these measures shorten the window in which a criminal can observe a conversation long enough to make a fraudulent request look ordinary.

How Does Vendor-Thread Compromise Change the Fraud?

Vendor-thread compromise shifts the fraud from imitation to insertion. Instead of opening a new conversation from a suspicious domain, the criminal compromises a supplier's mailbox, or an employee who corresponds with that supplier, and replies inside an existing thread. The message may carry accurate invoice numbers, project names, delivery dates, and the same signature block used in earlier correspondence, so the recipient evaluates continuity in place of identity.

The damaging moment usually arrives as a small operational change. A new bank account is requested, a tax form is solicited, a remittance address is updated, or an executive is said to have approved an exception. Because the request may come from the genuine vendor account, SPF, DKIM, and DMARC can all pass, and sender reputation offers little protection when the mailbox has a long history of legitimate communication.

Thread history is evidence, and it is not authorization. An analyst should compare the current message with earlier traffic, check whether the Reply-To address changed, and verify payment details against the vendor record maintained outside email. A phone number included in the suspicious message is not an independent channel, because its content is controlled by the criminal, so a preexisting contact, procurement portal, or documented callback procedure should be used instead.

The same method targets law firms, recruiters, payroll providers, construction subcontractors, and cloud-service partners. Vendors are trusted relationships that require verification rather than permanently trusted senders, and contractual security requirements, notification contacts, payment-change procedures, and shared incident channels all make it harder for a compromised supplier account to convert familiarity into a fraudulent transfer.

For organizations building phishing simulations for BEC and vendor impersonation, the scenarios should test the judgment these moments demand. Employees can practice separating a normal invoice from a payment-change request, reporting a suspicious thread without replying, and using an approved out-of-band verification path.

What Should Analysts Inspect in a Suspected BEC Message?

An analyst checklist should connect the visible message to the underlying delivery path and to recent account activity. Reviewing any field in isolation invites a false verdict, because a single passing check tells only part of the story. The following fields and events should be read together:

  • From: Compare the display name, full address, domain, Unicode characters, and domain age with the known executive or vendor record;
  • Reply-To: Identify whether replies route to a different domain, a personal mailbox, a newly created address, or an external ticketing service;
  • Return-Path: Compare the envelope sender with the visible From address and investigate unexpected infrastructure or forwarding services;
  • Received: Read the server chain from the earliest hop forward, checking timestamps, originating IP addresses, geography, relay hosts, and unusual routing;
  • Authentication-Results: Record SPF, DKIM, and DMARC outcomes, then confirm which domains were evaluated, because three passing results do not establish business legitimacy;
  • Message-ID: Compare its format and originating domain with prior messages from the same contact, since a sudden change can indicate a different sending platform or a compromised account;
  • DKIM signing domain: Confirm the d= domain and selector, then determine whether they align with the visible From domain under the organization's DMARC policy;
  • DMARC alignment: Check identifier alignment and the policy applied, remembering that a pass confirms alignment rather than sender intent or request safety;
  • Mailbox changes: Search for new forwarding rules, hidden-folder rules, mailbox delegations, unauthorized OAuth grants, unfamiliar applications, and internal-account sign-ins;
  • Conversation context: Compare payment details, approval language, writing patterns, attachments, and recent thread participants with records held outside email.

The checklist should close with an action decision, never with a verdict drawn from one header. Quarantine the message when evidence conflicts, contact the alleged sender through a known channel, suspend suspicious access, and notify finance or procurement before funds move. When authentication, account telemetry, and human verification are weighed as separate signals, a technically clean message has far less power to become an unauthorized transaction.

Header analysis rarely scales when a compromised supplier mailbox passes every authentication check it faces. Adaptive Security correlates sender behavior, company context, and authentication data in one explainable verdict.

Book a demo

How Trust, Urgency, Secrecy, and AI Make BEC More Convincing

Persuasion is the operating mechanism of business email compromise, and it is the layer no gateway inspects. A cyberattacker does not need an employee to ignore every security warning; the employee only needs to read one request as ordinary, important, and safe enough to complete before checking it. That single interpretation is why BEC bypasses email filters stops being a technical question and becomes a workflow question.

How Do Persuasion Mechanics Make BEC Convincing?

BEC shapes human judgment around a familiar business task, using a small set of levers that appear in almost every documented case. Recognizing them by name gives employees something concrete to notice under pressure. The recurring mechanics are:

  • Authority: A message that appears to come from a chief financial officer, department head, attorney, or long-standing supplier carries institutional weight and feels preapproved. Unusual payment or data requests should be verified through a known phone number, an internal directory entry, or a separate conversation, never through contact details supplied inside the message.
  • Urgency: Instructions to send a wire before the bank cutoff, or to approve an invoice before a supplier pauses service, compress the time available for judgment and reframe verification as an obstacle. A standing pause rule resolves that, requiring second-channel confirmation for money, credentials, payroll changes, and confidential information regardless of the stated deadline.
  • Secrecy: Confidentiality is framed as executive privilege, deal sensitivity, or a wish to avoid confusing the team, which prevents the target from consulting a colleague. Employees need explicit permission to escalate confidential-looking requests to finance, security, or a manager through a documented path.
  • Fear of delay: Employees worry that questioning a request will disrupt a transaction, disappoint a senior leader, or cost the company a customer. Leaders counter that pressure by treating careful verification as successful behavior, since a delayed payment is recoverable while an unauthorized transfer often is not.
  • Reciprocity: A criminal may reference a recent favor, thank an employee for handling a prior invoice, or offer to handle the paperwork after a quick approval. Relationship maintenance and authorization are separate activities, and a familiar relationship explains why a request exists without replacing independent verification.
  • Routine: Invoice numbers, purchase orders, payroll dates, travel reimbursements, and monthly renewals give a dangerous request believable structure. Requests should be compared against the established workflow, including approved vendor records, expected amounts, purchase order requirements, and known payment instructions.
  • Confidence in an existing relationship: BEC often imitates a real conversation in preference to inventing an unfamiliar one, entering an existing email thread or referencing a project the target manages. Employees should verify the requested action itself, because a known contact can have a compromised account and a familiar writing style can be copied.

Framing these behaviors as the process removes the blame that keeps employees silent. The objective is not universal suspicion; it is a consistent verification habit that activates whenever a request carries financial or data consequences.

How Do Cyberattackers Use Reconnaissance and Automation?

Reconnaissance turns a generic scheme into a plausible organizational event. Public job titles, reporting lines, conference appearances, press releases, procurement notices, social media posts, and exposed contact details reveal who approves payments, who manages vendors, and when executives are travelling. Open-source intelligence also exposes employee interests, communication habits, time zones, and recent promotions that make a message feel personally relevant.

Those details are then combined with operational clues drawn from vendor relationships, billing cycles, invoice language, payment workflows, approval thresholds, and executive communication patterns. A finance employee may receive a request timed to the final day of a quarter, a procurement manager may see a message referencing a real renewal, and an executive assistant may get an instruction that matches the leader's travel schedule.

Generative AI accelerates the preparation stage. It produces polished spear phishing emails, imitates a leader's writing style, translates a message into the recipient's preferred language, and personalizes versions for different roles, which means grammar errors no longer serve as a dependable warning signal. Employees should inspect the requested action, destination account, timing, and approval path instead of relying on spelling, tone, or fluency.

That shift is now measurable in national reporting. According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, complaints involving artificial intelligence appeared as a distinct category for the first time, with 22,364 complaints and $893 million in associated losses.

Automation also lets criminals test variations at speed. One version may use a formal executive voice, another a friendly vendor tone, and a third a short mobile-style message, after which the most credible conversation is continued with whoever responded. Security teams should rehearse those variations through multi-channel phishing simulations that teach verification without penalizing a failed exercise.

How Does Multi-Channel Escalation Defeat Confidence?

Multi-channel escalation makes a fraudulent request feel independently confirmed. An email may be followed by a vishing call using a cloned voice and a smishing message repeating the same deadline, so that each channel appears to validate the others while all three originate from the same criminal operation.

Voice cloning and synthetic video raise the persuasive ceiling because employees hear a familiar voice or watch a familiar face instead of reading an unfamiliar message. In 2024, an employee at engineering firm Arup in Hong Kong reportedly authorized approximately $25 million after joining a video conference populated by deepfake participants, according to The Guardian's 2024 report on the incident.

Synthetic media has scaled well beyond that single case. According to Sumsub's 2025–2026 Identity Fraud Report, sophisticated fraud surged 180% YoY including deepfakes, synthetics, and telemetry tampering.

The same trust mechanism reaches senior decision-makers. In 2024, an individual posing as Ukraine's former foreign minister Dmytro Kuleba used an apparent deepfake call to reach U.S. Senator Ben Cardin, showing that authority-based impersonation can target people who understand geopolitical and security risk, according to The New York Times' 2024 account of the attempted call.

Email remains the primary carrier even as these channels multiply. According to IBM's Cost of a Data Breach Report 2026, phishing remained the top cyberattack vector for the fourth consecutive year, while voice and SMS phishing specifically appeared in 17% of attacks.

A second channel is not automatically a trusted channel. High-risk requests should be confirmed through a channel initiated from an independently verified directory or contact record, which rules out calling the number in the email, treating a meeting invitation as proof of identity, or accepting matching details across channels as independent evidence.

The strongest verification behavior is specific and repeatable: stop, identify the requested outcome, check it against the approved workflow, and confirm it with a trusted person or record. That sequence preserves speed for ordinary work while adding friction exactly where BEC creates financial consequences.

Voice cloning and synthetic video give a fraudulent instruction a face and a familiar tone. Rehearse deepfake, vishing, and smishing scenarios with Adaptive Security's cybersecurity awareness training program.

Take a self-guided tour

Can SPF, DKIM, DMARC, and MFA Stop BEC From Bypassing Email Filters?

Email authentication and MFA protect identity and access but not payment verification so BEC prevention requires employee judgment on unusual requests

Email authentication and multifactor authentication close specific routes into business email compromise, and neither one determines whether a payment request is fraudulent. CISA's 2025 guidance on email authentication recommends DMARC, SPF, and DKIM, while its 2025 #StopRansomware Guide recommends phishing-resistant MFA for email and critical accounts. These controls protect sender identity and account access, leaving payment verification and employee judgment to address the trust decision criminals ultimately exploit.

The financial trend line explains the urgency of getting that division of labor right. According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, internet crime drove $20.877 billion in reported losses, a 26% jump over the prior year ($16.6 billion in 2024).

How Email Authentication Helps Against Direct Domain Spoofing

SPF, DKIM, and DMARC make direct domain spoofing harder by testing whether a message is authorized to represent an organization's domain. That protection matters because a forged message appearing to come from cfo@example.com can survive a superficial visual inspection and trigger an urgent transfer.

SPF publishes the mail servers authorized to send messages for a domain, and the receiving system checks the sending server against that record. DKIM adds a cryptographic signature so the receiving system can verify that an authorized system signed the message and that key parts of the email were not altered in transit. Neither control establishes that the sender is trustworthy or that the request is legitimate.

DMARC connects those signals to the visible From address through alignment. The domain authenticated by SPF or DKIM must match, or align with, the domain shown to the recipient, and a DMARC policy tells receiving systems whether to monitor, quarantine, or reject a message that fails. CISA's 2025 guidance recommends these controls because they help external services authenticate email claiming to come from an organization.

That protection has a defined boundary. DMARC can reject a message falsely claiming to originate from a protected domain, and it cannot reject a message from example-security.com, examp1e.com, or a vendor domain a criminal legitimately controls. It also does nothing about a compromised employee mailbox sending an authenticated message, because a real account and a real domain are in use.

What MFA Protects and What It Cannot Validate

Multifactor authentication protects identity and access by requiring an additional factor beyond a password. When a password is stolen through phishing, MFA can block the login attempt if the criminal lacks the registered device, security key, or biometric factor, which is why CISA's 2025 #StopRansomware Guide recommends phishing-resistant MFA for email, VPN, and accounts that reach critical systems.

MFA does not authenticate the business purpose of an action once access is granted. An employee who signs in legitimately can still receive a fraudulent invoice, approve a changed bank account, or follow a fabricated executive instruction. The authentication event is valid; the payment request is not.

MFA also leaves several account-takeover paths open. Criminals can target session cookies, exploit a previously authenticated browser session, push a malicious approval prompt until a user accepts it, or compromise an endpoint where the session is already active. Phishing-resistant, hardware-backed authentication reduces credential theft, and it does not replace session monitoring, access reviews, or transaction controls.

Security leaders should treat MFA as a prevention control for unauthorized access, which is a separate job from fraud verification. High-risk actions still require independent confirmation through a known phone number, an established vendor contact, or a finance workflow outside the email thread.

Which BEC Gaps Require Process and Human Verification?

BEC succeeds when a criminal converts a trusted channel into a trusted decision. Email authentication and MFA improve the channel's security, and neither asks whether the request is unusual, whether the timing is suspicious, or whether the destination account has changed. That judgment requires process controls and a workforce trained to pause without fear of blame.

A practical BEC control set separates prevention, detection, and response:

  • Prevention: Enforce SPF, DKIM, and DMARC with a reject policy where operationally safe, require phishing-resistant MFA for privileged and finance accounts, limit mailbox forwarding, and require dual approval for wire transfers and bank-detail changes;
  • Detection: Monitor unusual login locations, new inbox rules, impossible travel, vendor-account changes, and messages that create pressure without matching normal business patterns, treating a valid authentication result as one signal rather than proof of safety;
  • Response: Give employees a direct reporting route, preserve the message and related login evidence, disable suspected sessions, contact the bank quickly, and notify affected vendors through trusted channels, because fast reporting limits the time available to redirect funds.

Employees remain the decision point in most BEC attempts, so verification has to be rehearsed as a professional safeguard, and never framed as suspicion. Finance teams should know that a changed payment instruction requires out-of-band confirmation even when the message passes DMARC and the executive's account uses MFA. Phishing simulations that include BEC and vendor impersonation give teams a controlled way to practice that decision across realistic scenarios.

These limits are the clearest short answer to why BEC bypasses email filters. The fraud typically travels through an authenticated account, a legitimate domain, or a trusted conversation, so technical controls reduce spoofing and account compromise while process discipline and practiced human verification address the fraudulent request itself.

Authentication records confirm the route a message took and never confirm who authorized the payment. Adaptive Security pairs email security detection with verification habits built through repeated practice.

Explore the platform

What Technical Controls Detect BEC That Traditional Filters Miss?

Detection improves when business context is evaluated alongside email content, combining mailbox telemetry, identity signals, behavioral analytics, payment workflows, and human reporting. Each layer should reflect how employees and vendors actually behave, and ambiguous events should reach an analyst instead of being treated as automatic proof of fraud. That layered approach is the practical counterweight to why BEC bypasses email filters at the gateway.

Speed determines how much of that telemetry is useful. According to the CrowdStrike 2026 Global Threat Report, the average adversary breakout time, the window between initial access and lateral movement, dropped to 29 minutes, with the fastest measured at just 27 seconds.

1. Establish the Email and Mailbox Baseline

Secure email gateways remain necessary, and they are only the starting point. Gateways inspect sender authentication, domain reputation, attachment behavior, malicious links, header anomalies, and known threat indicators, which works against malware and obvious spoofing while leaving a clean message from a compromised account largely unexamined.

Cloud mailbox telemetry supplies the missing context. Sign-in events, mailbox rule creation, forwarding changes, delegated access, OAuth grants, message deletion, and unusual search activity all belong under monitoring. A new rule forwarding finance correspondence to an external address, followed by deleted replies, describes a materially different risk picture from a single authenticated email.

Protective controls should also compare sender and recipient relationships against historical communication. A first-time contact, an unusual pairing, or a sudden shift from a long-standing vendor domain to a personal address deserves additional scrutiny, and employees need a clear reporting path plus an explanation of why a message was escalated.

2. Detect Behavioral Signals and Patterns of Life

Behavioral analytics identify BEC by testing whether a request matches the way a person, team, or supplier normally communicates. A technically clean message can still be suspicious when it arrives outside the sender's usual working hours, uses unfamiliar language, or introduces a financial instruction without the supporting documents that normally accompany one. Useful signals include:

  • Relationship change: A first-time contact, a new sender-recipient pairing, or a sudden executive-to-junior-employee request;
  • Conversation anomaly: A broken reply chain, a missing participant, a new subject line, or a reference to a prior discussion absent from the thread;
  • Language and cadence shift: Unusual urgency, shortened replies, unfamiliar phrasing, unexpected confidentiality demands, or a sudden change in response timing;
  • Workflow inconsistency: A request to bypass procurement, change a bank account, buy gift cards, share credentials, or approve an invoice through an unapproved route;
  • Account behavior: New forwarding rules, impossible travel, anomalous sign-ins, unfamiliar devices, suspicious mailbox searches, or a burst of outbound messages;
  • Privilege context: A request from an executive, finance approver, administrator, or vendor contact with authority to cause financial or operational harm.

Pattern-of-life analysis must accommodate legitimate exceptions, because executives travel, suppliers change banking details, and urgent payments occur during acquisitions or outages. Combinations of signals should be scored in place of blocking every isolated deviation. A late-night executive message is not automatically malicious, whereas a late-night message to a first-time recipient that changes a bank account and bypasses dual approval is a different event entirely.

Human reporting supplies context that automated controls cannot infer, because employees know the relationships, organizational dynamics, and recent business events that systems lack. Reporting should be available from the inbox, mobile device, and collaboration workflow, and each report should return a clear disposition so employees learn whether a message was safe, spam, or malicious.

3. Correlate Signals Across Systems

Cross-system correlation turns isolated anomalies into an investigative narrative. Secure email gateway events, cloud mailbox logs, identity telemetry, endpoint context, HR role data, vendor records, payment systems, and threat intelligence all contribute, and a suspicious email becomes far more actionable when it aligns with an unfamiliar sign-in, an inbox rule created minutes earlier, and a payment request that changes beneficiary details.

Threat intelligence adds external context such as newly registered domains, impersonation infrastructure, and exposed credentials. High-reputation cloud domains require careful handling, because criminals abuse trusted file-sharing services, collaboration tools, and legitimate email providers, which means domain reputation cannot function as a blanket allow signal.

The correlation layer should also model business entities, mapping executives, assistants, finance approvers, vendors, subsidiaries, bank accounts, projects, and normal approval paths. A relationship model of that kind can flag an unusual request even when the sender uses a valid account and the message contains no malicious link, and it can separate a routine invoice from a request that conflicts with an established vendor workflow.

The Cybersecurity and Infrastructure Security Agency's 2025 cloud-use guidance calls for detecting anomalous user activity in email services, and the principle extends well beyond government environments. Cloud telemetry has to be part of BEC detection because the fraud can unfold inside an authenticated mailbox, after a legitimate login, on a platform with a strong reputation.

Risk decisions should then reflect privilege and consequence. A low-risk anomaly on a general mailbox can create a review task, whereas the same anomaly on a chief financial officer's or payment approver's account should trigger stronger verification, temporary controls, or immediate analyst review.

4. Tune Detection With Analyst Review

Detection tuning starts from a documented baseline covering normal sender-recipient relationships, payment thresholds, approval chains, vendor domains, executive schedules, and mailbox activity for each business unit. Separate policies for finance, procurement, executives, legal teams, and operational staff prevent the noise that a single enterprise-wide threshold guarantees.

Graduated responses work better than a binary allow-or-block rule. Low-confidence anomalies can enter an analyst queue or trigger an employee verification prompt, medium-confidence events can require out-of-band confirmation before a payment or account change proceeds, and high-confidence combinations such as a new forwarding rule paired with an anomalous sign-in and a payment instruction should trigger containment and investigation.

Analysts must review true positives and false positives with equal care, recording why a legitimate executive request was cleared, which signal raised the alert, and what context resolved it. Those decisions feed back into relationship models, approved vendor records, payment controls, and role-specific thresholds. Suppressing a noisy sender or a trusted domain is the wrong correction, because established relationships are precisely what criminals target.

Verification must use a trusted channel that does not depend on the message under review, such as a known number from the vendor record, an established procurement portal, or a second approver who took no part in the original request. A bank-account change should never be validated by replying to the email that requested it.

An AI-native cybersecurity awareness training platform can connect identity, message, mailbox, relationship, and human-reporting signals at machine speed. It can explain why a message is unusual, surface similar incidents, prioritize analyst queues, and recommend targeted practice after an employee reports or interacts with a suspicious request. Adaptive Security's Phish Triage capabilities classify reported messages and support reversible remediation workflows.

Automation produces a risk judgment rather than proof of fraud, and analysts and employees still validate that judgment against business context. The strongest control is a feedback loop in which telemetry detects the anomaly, a person confirms the intent, and the organization improves its verification workflow.

Reported messages sit in a queue while a fraudulent wire clears in minutes. Triage employee reports automatically with Adaptive Security and remediate matching messages across every affected inbox.

Take a self-guided tour

How Should Employees Verify a Suspected BEC Request?

A suspected BEC request calls for independent verification instead of a judgment based on how the email looks. The sequence is consistent across roles: pause, avoid replying in the same thread, confirm through a known-good channel, obtain a second authorized approval, and escalate anything that conflicts with established process. Urgency does not remove the checkpoint; it is the reason the checkpoint exists.

Verification also has to travel beyond the inbox. According to Verizon's 2026 Data Breach Investigations Report, 41% of social engineering breaches involved vectors other than email, with roughly a quarter arriving through social media or phone-based channels.

Follow the Employee Decision Path

The first move is to stop the transaction without signalling agreement to the sender. Links should stay unclicked, unexpected attachments unopened, and the thread unanswered, and contact details included in the message should be treated as untrustworthy. A compromised mailbox can hold authentic correspondence, familiar signatures, and accurate project details, so a legitimate-looking request still requires an independent check.

This decision path applies to finance, payroll, procurement, legal, executives, and anyone handling money, credentials, confidential data, or supplier records:

  • Pause: Do not transfer funds, change payroll details, release sensitive information, or approve a new beneficiary while the request remains unverified;
  • Separate: Start a new conversation through a known-good phone number, internal directory entry, corporate messaging account, or previously validated vendor record;
  • Confirm: Ask the supposed sender to restate the exact amount, recipient, deadline, and reason, since a simple agreement inside the original thread proves nothing;
  • Check: Compare bank details, payroll instructions, invoice information, and purchase orders against records held in approved organizational systems;
  • Escalate: Report the request to the security, finance, fraud, or incident-response team whenever a detail is inconsistent, unusually urgent, or difficult to verify.

A short verification delay operates as a business control, and the minutes it costs are trivial against an irreversible wire. Employees should receive credit for pausing and reporting a suspicious request even when it later proves legitimate. Programs that punish false alarms teach silence, which is the one outcome a cyberattacker can rely on.

Use Dual Approval and a Callback Procedure

Two-person approval must be a part of every high-risk action. One employee prepares the payment or account change, and a separate authorized person reviews the request against the original invoice, contract, purchase order, payroll record, or vendor profile. The approver must confirm the request independently instead of treating the preparer's check as evidence.

A callback procedure makes that separation practical. The employee should call the requester using a phone number held in the company directory or drawn from a prior, trusted relationship, and for a vendor that means the number on an existing contract, an invoice predating the suspicious request, or the vendor's independently verified official website. A number supplied in the email itself remains unusable even when someone answers and confirms every detail.

Verification must continue when the supposed sender's account may be compromised. Contact should move to a separate channel such as a direct phone call, an internal messaging platform, or an in-person confirmation, and a confirmation that arrives only inside the original email thread counts as unverified. For sensitive payments, the vendor should confirm the change through its established accounts-payable contact, and beneficiary information should be compared with records approved by procurement.

Add Payment-System Safeguards

Payment systems should separate duties limit transactions and require approval for new recipients so employees verify changes before unusual payments

Safe behavior should be the default inside payment and payroll systems. Human judgment remains essential, and employees should not carry the full burden of catching BEC under deadline pressure, so finance leaders need controls that slow unusual transactions and demand evidence before money moves.

Duties should be separated so that no single employee can create a beneficiary, approve a payment, and release funds. Transaction limits should follow roles, with additional approval required for new recipients, international transfers, urgent payroll changes, and payments that exceed normal patterns, and payments should be restricted to prevalidated beneficiary accounts while every bank-detail change runs through a documented review.

Out-of-band confirmation belongs on all account changes. A banking portal, payroll platform, or enterprise resource planning system should record who requested the change, who verified it, which channel was used, and who approved the final action, and an independent reviewer should be alerted when payment instructions change shortly before a scheduled transfer.

Those safeguards answer why BEC bypasses email filters at the only point that matters financially. The message may pass technical inspection because a legitimate account, a trusted conversation, or a newly created lookalike domain carried it, while a payment system requiring independent approval and verified beneficiary data evaluates the transaction on business context.

Test Defenses Without Teaching Employees to Ignore Urgency

Realistic, controlled exercises turn the procedure into a habit. Finance can be tested with a vendor bank-change request, payroll with a direct-deposit update, procurement with an altered invoice, legal with a confidential wire instruction, and executives with an urgent approval request. The measurement should cover whether employees paused, used the correct callback method, involved the required approver, and reported the event, rather than click rates alone.

Scenarios should preserve legitimate urgency while making the safe action obvious. A phishing simulation can state that a payment deadline is approaching without teaching employees that every urgent request is fraudulent, because the behavioral lesson is narrower and more useful: urgent requests still follow established authorization rules.

Exercises should run across email, phone, SMS, and collaboration tools, since criminals reinforce fraudulent requests across channels. Debriefs should follow immediately with the correct procedure, an explanation of which signals required verification, and targeted practice delivered without blame. Phishing simulations that rehearse BEC and vendor impersonation give security teams a way to measure reporting and verification behavior across those channels.

Employees who have never rehearsed a callback improvise one under deadline pressure and usually skip it. Adaptive Security rehearses the exact verification sequence across email, voice, and SMS scenarios.

Take a self-guided tour

What Should a BEC Incident Response Playbook Include After a Fraudulent Payment?

A BEC incident response playbook starts with the bank, evidence preservation, and containment, and an internal debate about which control failed can wait. The financial institution should be contacted immediately, the affected identity and mailbox secured, the transaction timeline preserved, and the people who can limit legal, operational, and reputational damage notified. Recovery also requires monitoring for follow-on vishing and smishing, because a compromised relationship stays useful to a criminal long after the first payment clears.

The reporting volume shows how routine these incidents have become. According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, IC3 logged 1,008,597 complaints during the year, the highest annual total in its history.

1. Stop the Transfer and Activate the Response Team

The first minutes determine whether a fraudulent payment can be recalled or frozen. Call the sending bank through a verified number, explain that the transfer resulted from business email compromise, request a recall or freeze, and ask for any required indemnification or hold-harmless documents. Ask the bank to contact the receiving institution directly, then record the case number, contact name, call time, and required follow-up.

The FBI Internet Crime Complaint Center's 2024 BEC guidance directs victims to contact their financial institution immediately, request a recall, and file an IC3 complaint regardless of the amount lost. The complaint should be submitted as soon as possible, because the FBI can assist financial institutions and law enforcement in freezing transferred funds, and waiting for a completed internal investigation costs recovery time.

Legal, finance, security, executives, and the incident-response lead should be convened through an out-of-band channel, never through the suspected mailbox. The affected vendor or customer should be notified through a verified phone number, told that payment instructions or communications may have been manipulated, and asked to pause related transfers until account details are independently confirmed.

2. Preserve Evidence Before Changing the Environment

Evidence preservation has to precede cleanup, because deleting fraudulent messages, forwarding rules, or authentication records destroys the timeline investigators need. Original emails should be preserved in their native format, including complete headers, message IDs, attachments, authentication results, and conversation history, with screenshots kept as supplemental records, never as substitutes.

Exports should cover mailbox audit logs, identity-provider logs, sign-in history, MFA events, session data, administrative changes, forwarding rules, OAuth grants, mailbox delegations, and endpoint alerts. The payment request, legitimate business process, first suspicious message, approvals, destination account, transfer amount, timestamps, and people who handled the request all belong in the written record, alongside a read-only copy of exported data noting who collected each item and when.

The U.S. Secret Service BEC response guidance directs compromised organizations to notify the bank, contact law enforcement through an out-of-band channel, change passwords, engage IT response teams, and preserve original digital evidence. Wiping devices, deleting accounts, purging mail, and reimaging endpoints should wait for security and legal approval, since containment that erases evidence weakens recovery and complicates insurance, regulatory, and litigation reviews.

3. Contain the Compromised Identity and Access Paths

Containment should remove access without destroying the account's investigative record. Reset the affected user's password from a clean device, revoke active sessions and refresh tokens, review MFA methods for unauthorized enrollments, and require fresh authentication. Mailbox delegates, inbox rules, transport rules, external forwarding, application passwords, connected applications, and OAuth grants all need inspection, and each configuration should be exported before unauthorized persistence is removed.

The user's endpoint and cloud account then need investigation for malicious browser sessions, infostealers, remote-access tools, suspicious applications, impossible-travel sign-ins, and other accounts that reused the same credentials. The review should widen to executives, finance staff, accounts-payable personnel, and everyone included in the fraudulent conversation. If a vendor or customer contact list was accessed, follow-on impersonation should be assumed and those contacts warned through trusted channels.

4. Report, Assess Impact, and Manage Obligations

Legal and compliance teams determine whether the incident triggers contractual notice, privacy reporting, financial-sector obligations, cyber-insurance notification, or law-enforcement coordination. Finance reconciles outgoing payments, pending invoices, vendor master-file changes, and altered bank details. Security establishes whether the event involved a mailbox takeover, credential theft, vendor impersonation, or a broader cloud-account intrusion.

The damage extends well beyond the initial payment. Operations may face delayed payroll, suspended vendor relationships, disrupted purchasing, or fraudulent invoices still circulating, and legal exposure can arise from missed notification duties or disputed authorization. A written impact assessment gives leaders one factual record in place of conflicting departmental accounts.

5. Recover Carefully and Monitor for the Second Cyberattack

Recovery is complete only once the organization confirms that no criminal controls the identity, mailbox, endpoint, or related cloud applications. Normal access should be re-enabled in stages, MFA enrollment confirmed with the user, approved forwarding and delegation settings restored, and sign-ins, message rules, sent mail, vendor changes, and payment requests monitored. Heightened review should stay in place for high-value transactions, with independent verification required for account changes.

Follow-on vishing and smishing should be expected. Stolen email threads, signatures, employee names, invoice details, and vendor relationships all make a subsequent phone call or text message convincing after the mailbox is secured, so affected employees and vendors need a briefing on the exact pretext, numbers, domains, and payment details involved. The incident should also strengthen phishing simulations that rehearse BEC and multi-channel scenarios, letting employees practice reporting and independent verification without being blamed for the original deception.

Close the incident with a timeline, root-cause analysis, evidence inventory, financial-loss assessment, control changes, and named owners for follow-up actions. Technical containment has to work alongside practiced human verification as BEC expands into voice, text, and collaboration channels.

Recovery windows close in hours while internal debate about the failure point runs for days. Shorten detection and reporting time with Adaptive Security so response begins before funds become unrecoverable.

Book a demo

How Can Organizations Measure BEC Defense Effectiveness When BEC Bypasses Email Filters?

Measurement should show whether employees verify unusual payment requests, report suspicious messages quickly, and stop unauthorized changes before money moves. Completion percentages cannot demonstrate any of that, because attendance and judgment are different variables. A useful framework combines behavioral signals, response speed, control adherence, and business outcomes without converting employees into punitive risk scores.

As NIST computer scientist Julie Haney and University of Maryland Associate Professor Wayne Lutters concluded in their peer-reviewed analysis published in Computer (October 2020), compliance metrics do not tell the whole story and fail to measure the effectiveness of the program in a sustained change in employee attitudes and behaviors.

What Leading Indicators Show Behavioral Change?

Leading indicators reveal whether employees recognize and interrupt a BEC attempt before it becomes an incident. The core set covers reporting rate, verification rate, unsafe-action rate, click or reply rate, and time to report. For payment-focused scenarios, an unsafe action includes replying with account details, approving an invoice, changing vendor banking information, or accepting a request without independent verification.

The same behavioral standards should apply across email, vishing, smishing, and deepfake phishing simulations. An email can request a vendor bank-account change, a vishing call can imitate a finance executive, an SMS can ask an employee to confirm a payment, and a synthetic video can reinforce the request, and the required behavior stays constant: pause, verify through a trusted channel, and report. Each measurement should be compared with the organization's own baseline:

  • Verification rate: The percentage of participants who confirm a high-risk request through an approved independent channel;
  • Unsafe-action rate: The percentage who click, reply, approve, disclose information, or follow an unverified instruction;
  • Reporting rate and time to report: The percentage who notify the security team, and the elapsed time between exposure and that notification;
  • Repeat-failure rate: The percentage who repeat the same unsafe behavior after targeted cybersecurity awareness training;
  • Role and department risk: Differences among finance, accounts payable, executive assistants, sales, IT, and other groups that handle sensitive requests.

An individual failure in a phishing simulation does not prove carelessness. It points to scenario design, workflow pressure, role exposure, or a missing verification habit, so results should be aggregated by role and department and answered with targeted practice for the behavior that actually failed.

Which Outcome and Response Metrics Matter Most?

Outcome metrics connect employee behavior to operational protection. Payment-change verification adherence, account-compromise detection time, forwarding-rule discovery time, time to contain, confirmed BEC incidents, and near misses together show whether the organization can stop a fraudulent request and limit damage after a mailbox is compromised.

Payment-change verification should be measured against actual policy, since course completion reveals nothing about it. The record should state whether an employee called a known vendor contact using a phone number already stored in the vendor master file, because a reply to the original email is not independent verification when the criminal controls that channel.

Account-compromise detection time measures how quickly suspicious login activity, mailbox access, or unauthorized message rules are identified. Forwarding-rule discovery time measures how long hidden inbox rules redirecting payment conversations go unnoticed. Both indicators belong on the same dashboard as employee reporting, since a fast report shortens investigation and containment.

Targeted-training impact is best assessed by comparing a group with its own earlier baseline. A finance team that reduces unsafe payment actions after a focused verification exercise has made meaningful progress even if its reporting rate moves only slightly, and confidence intervals or minimum sample sizes keep leaders from overreacting to small groups or isolated events.

How Should BEC Defense Results Reach the Board?

Board reporting translates human behavior into financial exposure, control performance, and trend direction. Four views carry that message: current exposure, behavioral change, response readiness, and business impact. Department and role risk, the percentage of high-risk payment requests independently verified, median time to report, median time to contain, repeat-failure rate, and confirmed incidents or near misses all belong in the pack.

Board engagement is itself a marker of resilience. According to the World Economic Forum's 2026 Global Cybersecurity Outlook, 52% of highly resilient organizations indicate that board members receive regular cybersecurity updates, and 48% report that board members are actively engaged with cybersecurity issues.

Employees should never be ranked publicly or labelled with a single composite score used for discipline. Coaching data belongs apart from personnel decisions, individual results should have restricted access, and executives should see aggregated trends. A board report answers three questions directly:

  • Are employees interrupting suspicious payment workflows;
  • Can security and finance teams detect and contain compromise quickly;
  • Is targeted practice reducing repeat failures in the roles most exposed to BEC.

Accountability at that level increasingly carries personal weight. According to the World Economic Forum's 2026 Global Cybersecurity Outlook, 30% of highly resilient organizations reported that board members hold personal liability in the event of cyber breaches, compared with 9% of organizations with insufficient resilience.

Linking phishing simulation data with human risk reporting and dashboards gives leaders a continuous view in place of an annual completion snapshot. The clearest measure of progress is whether employees verify intent when technical controls cannot separate a legitimate request from a carefully engineered one.

Completion percentages reassure a board while verification behavior goes unmeasured across the highest-risk finance workflows. Adaptive Security reports reporting rates, repeat failures, and role-level exposure in one dashboard.

Take a self-guided tour

Why BEC Bypasses Email Filters and Demands Continuous Cybersecurity Awareness Training

BEC defense belongs inside a human risk program because the fraud targets judgment, authority, and routine processes, leaving code untouched. The FBI's business email compromise guidance describes a trust-based fraud pattern that manipulates employees into sending money, credentials, or sensitive information. An annual course cannot build the repeated decision-making skills that those requests demand, which is why finance, executive assistants, procurement teams, and IT administrators need role-specific practice on a continuous cycle.

Why Does BEC Require Continuous, Role-Specific Behavioral Change?

BEC succeeds when a plausible request lands at the exact moment an organization expects fast action. A finance employee might receive a vendor payment change, an executive assistant an urgent instruction to purchase gift cards, and a procurement manager a supplier impersonation attempt written with accurate contract language and familiar names.

A cybersecurity awareness training program should mirror those workflows instead of sending every employee the same generic phishing email. Employees practice pausing, checking requests through known channels, and reporting suspicious messages without fear of blame, and microlearning delivered immediately after a risky decision reinforces the specific behavior while the scenario is still vivid.

Annual cybersecurity awareness training falls short on its own because pretexts change quickly and move across email, phone calls, text messages, and collaboration tools. A modern program rotates scenarios and measures whether employees recognize and report each tactic over time.

Gaps in adjacent skills compound the problem. According to the National Cybersecurity Alliance's 2025–2026 Oh Behave! The Annual Cybersecurity Attitudes and Behaviors Report, 52% of employed participants reported they have not received any training on the security or privacy risks of AI tools, despite 65% now using AI and 43% admitting to sharing sensitive work information with AI tools.

How Do Multi-Channel Phishing Simulations Strengthen BEC Awareness?

BEC defense has to follow the fraud across channels. A multi-channel exercise can begin with an OSINT-informed spear phishing email, continue with a vishing call that appears to come from a manager, and close with a smishing message reinforcing the same deadline. Open-source intelligence here means publicly available information about job roles, reporting lines, vendors, and executive travel.

That material helps security teams build realistic scenarios while showing employees how ordinary public details raise a criminal's credibility. Vishing and smishing phishing simulations expose risk that email-only testing never touches, teaching employees that a familiar voice does not prove identity and that a text message confirming an urgent payment does not replace an approval process.

Deepfake awareness applies the same discipline to video meetings and synthetic executive impersonation. The objective is not to make employees distrust colleagues; it is to mark the point at which a request requires a second trusted channel.

A unified phishing simulation program connects those exercises to phish reporting. A reported message signals that an employee recognized risk, whereas a click, reply, attachment download, or silence identifies a skill gap for targeted follow-up, which keeps the process constructive for employees and informative for security leaders.

How Does Human Risk Management Turn Behavior Into Targeted Remediation?

Human risk management gives leaders a broader view than course completion. Employee risk scoring can combine phishing simulation behavior, phish reporting, cybersecurity awareness training outcomes, OSINT exposure, and other approved exposure signals to show where BEC susceptibility concentrates, and a high score should trigger automated remediation practice rather than punishment.

The remediation should match the behavior that created the exposure. A finance employee who falls for a payment-change scenario needs invoice-verification practice, though an executive assistant who misses an impersonation attempt needs scenarios built around authority and urgency.

Compliance training fits this model as a mapped control; a certification claim alone proves very little. Content mapped to NIST CSF, ISO 27001, HIPAA, or PCI DSS can document participation, relevant policies, and response practice, and those records become far more credible when paired with behavioral evidence.

Employees remain the strongest line of defense because they can read context that automated filters cannot fully interpret. That judgment matters most when a BEC message looks ordinary enough to pass through spam filters and secure email gateways untouched.

Generic annual courses rehearse a threat model that stopped matching how criminals operate several years ago. Rotate scenarios as pretexts change with Adaptive Security's role-specific cybersecurity awareness training.

Explore the platform

How Adaptive Security Closes the Gap Where BEC Bypasses Email Filters

Adaptive Security reduces BEC exposure through detection behavior change and remediation so finance teams call report and malicious mail is removed

Security leaders who reduce BEC exposure tend to report the same three outcomes: finance teams that call before they pay, reported messages that reach a queue in minutes, and fraudulent instructions that get pulled from every inbox they reached. Adaptive Security is built to produce those outcomes together, since detection without behavior change leaves the last decision unguarded, and behavior change without detection leaves too much traffic in front of employees.

Cloud Email Security supplies the detection half. It layers on Google and Microsoft through an API with no MX record changes, applies behavioral signals, intent analysis, and LLM reasoning to messages that carry no payload, and remediates confirmed cyberattacks across every affected mailbox with a reversible action and an explainable verdict. Each detection then feeds the employee's risk profile, so a lookalike-domain invoice aimed at accounts payable becomes the next scenario that team practices instead of an alert nobody revisits.

The behavior half runs on the same data. Phishing simulations rehearse vendor bank changes, executive impersonation, and payroll diversion across email, voice, and SMS; Phish Triage classifies what employees report and closes the loop back into detection; and Compliance Training documents policy and response practice against the frameworks auditors ask about, with AI Governance covering the shadow AI accounts where sensitive business context leaks out and fuels a convincing pretext.

Detection tools and awareness programs bought separately rarely share the signal that would make either one sharper. Adaptive Security unifies email security, phishing simulations, triage, and reporting on one platform.

Book a demo

Frequently Asked Questions About Why BEC Bypasses Email Filters

Why Do BEC Emails Bypass Email Filters Even When SPF, DKIM, and DMARC Pass?

BEC emails clear those checks because SPF, DKIM, and DMARC authenticate sending infrastructure rather than the legitimacy of the request. A criminal can send from a compromised legitimate mailbox, a lookalike domain with aligned authentication, or a domain they own outright. A clean message asking to change bank details or release an invoice also contains no malware, no suspicious link, and no known signature for a filter to inspect. CISA phishing guidance supports treating authentication as one layer instead of proof of intent. Independent callback verification, dual approval, and payment-change controls should therefore govern financial requests. Authentication reduces spoofing risk, while human verification addresses the business context filters cannot establish.

Can Multifactor Authentication Prevent BEC Attempts?

Multifactor authentication reduces account-takeover risk without preventing every BEC attempt. MFA can block a criminal using a stolen password, and it does not validate a legitimate-looking payment request, stop a compromised vendor account, or prevent fraud from a mailbox already under criminal control. CISA phishing guidance treats phishing-resistant identity controls as part of layered defense rather than a substitute for reporting and verification. MFA should be paired with phishing-resistant methods where practical, session and mailbox monitoring, forwarding-rule review, independent callbacks, and dual authorization for payment changes. Employees remain an empowered control when they pause, verify through a known-good channel, and report pressure or secrecy.

What Is the Fastest Way to Verify a Suspected BEC Payment Request?

The fastest safe method is to pause the payment and call the requester or vendor through a previously trusted phone number instead of a number or link inside the message. The amount, beneficiary, account details, and business purpose should be confirmed with the supposed sender and a second authorized employee. NIST business email compromise guidance recommends independent verification because the original mailbox or thread may be compromised. Replying in the same conversation, approving a bank-detail change from email alone, and letting urgency override segregation of duties are all unsafe shortcuts. The request and verification result should be recorded, and any mismatch reported to security, finance, and the bank before funds move.

What Should a Company Do Immediately After a Fraudulent BEC Transfer?

The bank should be contacted immediately to request a recall, freeze, or hold on the fraudulent transfer, while evidence is preserved and the incident-response process is activated. U.S. Secret Service BEC guidance emphasizes rapid contact with the financial institution because recovery options depend on timing. Preserve the original email, full headers, payment instructions, invoices, chat records, call details, and a precise timeline. Notify security, finance, legal, leadership, the insurer, affected vendors, and law enforcement as appropriate. Revoke sessions, reset credentials, review MFA, remove unauthorized forwarding rules and OAuth grants, and inspect mailbox access. Monitor for follow-on vishing or smishing, since fast containment turns a confusing loss into evidence-led recovery.

How Can Organizations Measure Whether BEC Training Reduces Risky Behavior?

Behavior should be tracked before and after targeted exercises rather than counted as course completions. Useful measures include phishing simulation reporting rate, unsafe-action rate, time to report, payment-change verification adherence, repeat-failure rate, and time to contain, all broken down by role and department. NIST business email compromise guidance supports measuring the controls around verification and payment processes. Realistic email, vishing, smishing, and deepfake scenarios work best when decisions are evaluated and individuals are never punished. Comparing baseline and follow-up results, documenting coaching, and reporting trends to leaders builds a defensible picture, with faster reporting, fewer unsafe approvals, and consistent independent verification as the strongest evidence.

Convincing pressure meets employees with no reliable way to confirm what a message asks for. Turn that moment into a measurable decision with Adaptive Security across email, voice, and SMS.

Take a self-guided tour

Adaptive Team

Adaptive Team

As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.

Get started with Adaptive Security

Human and Agent Security for the AI Era.