Skip to main content
AI Everywhere: See and Control the Risk with Adaptive AI Governance, September 23
Blog
Email Security

Who Is Targeted by BEC? Roles, Industries, and Warning Signs That Strengthen Fraud-Resistant Workflows

SEPTEMBER 17, 202625 MIN READ
Adaptive TeamAdaptive Team
Who Is Targeted by BEC? Roles, Industries, and Warning Signs That Strengthen Fraud-Resistant Workflows

Key takeaways

  • Who is targeted by BEC depends on authority and access far more than seniority. Any employee able to approve payments, change bank details, or release sensitive data becomes a candidate.
  • Finance, payroll, HR, IT administration, executive support, and vendor management concentrate the highest exposure because each role can move money or unlock accounts.
  • Vendor email compromise and conversation hijacking succeed because the fraudulent request arrives inside a legitimate transaction that employees already expect.
  • AI-enabled impersonation through voice cloning, deepfake video, smishing, and quishing removes the spelling and formatting errors employees were trained to spot.
  • Out-of-band verification, dual approval, and fast blame-free reporting convert trusted employees into an active control at the point where trust becomes money.

Who is targeted by BEC? Business email compromise (BEC) uses spoofed, compromised, or impersonated business communications to redirect money, expose data, or gain account access through trusted relationships. Protection must extend well beyond executives and finance teams.

Accounts payable, payroll, HR, IT, executive assistants, vendors, customers, and employees who approve payments or handle sensitive information all carry distinct exposure. This guide explains how BEC attackers select targets through public business information, relationship context, authority pressure, and high-stakes timing.

It also explains how remote work, voice cloning, fake video meetings, vishing, smishing, and QR-based messages expand the channels used for social engineering. The FBI’s Internet Crime Complaint Center (IC3) recorded roughly $3.04 billion in reported BEC losses in its 2025 annual report, showing why payment verification and clear reporting routes matter.

Managing these risks takes a practical human risk management program: role-based simulations, stronger approval controls, targeted training, and metrics that show whether behavior actually changed. Security leaders finish this guide able to prioritize the highest-risk BEC targets and match each role to measurable protection.

Security teams ready to rehearse those decisions can explore Adaptive Security’s role-based phishing simulations across email, voice, SMS, and deepfake video.

Who is targeted by BEC: finance employee reviewing a payment request before approving an invoice.

Who Is Targeted by BEC? A Precise Definition

Business email compromise (BEC) targets executives, finance and payment authorities, HR staff, IT administrators, vendors, customers, and employees with access to sensitive information. Who is targeted by BEC depends on positioning inside a business process.

Anyone able to approve money, release data, change access, or influence a trusted transaction can become the point of attack. BEC is targeted fraud or data theft conducted through spoofed, compromised, or impersonated business communications. A fuller breakdown of how BEC attacks work covers the mechanics behind each variant.

Who Do BEC Attackers Target?

BEC attackers select targets based on authority, access, timing, and trust. A chief executive can pressure employees to move money quickly. A payroll manager can redirect salaries.

An IT administrator can reset credentials or grant access, while a vendor can make a fraudulent payment or account-change request appear routine. In every case the true objective is the business process that person controls.

The main business email compromise targets include:

  • Executives and senior leaders: CEOs, CFOs, department heads, and board members whose names and authority can pressure others into acting quickly.
  • Finance and payment authorities: Accounts-payable staff, controllers, treasury teams, procurement managers, and anyone who can approve invoices, wire transfers, refunds, or bank-account changes.
  • HR and payroll staff: Employees who manage salary data, tax records, benefits, identity documents, or new-hire information.
  • IT administrators: Personnel who control password resets, privileged accounts, software access, cloud systems, and multifactor authentication settings.
  • Vendors and customers: External partners whose identities, invoices, payment details, and ongoing relationships make fraudulent requests appear routine.
  • Employees with sensitive access: Legal, sales, research, operations, and executive-assistant roles that handle contracts, intellectual property, personal data, credentials, or confidential business plans.

Job title alone does not determine exposure. An executive assistant with authority to schedule payments can face more immediate BEC risk than a senior manager who cannot approve a transaction.

A customer-service representative with access to account records can become a data-theft target without holding financial authority. Security leaders should map approval rights, data access, business processes, and external relationships, then rehearse the requests each role must verify.

The financial impact reflects the size of the target pool. The FBI Internet Crime Complaint Center’s 2025 annual report recorded roughly $3.04 billion in reported BEC losses, while noting that complaint data does not capture every unreported incident.

Organizations should respond with role-specific practice, clear callback procedures, and a culture that allows employees to pause suspicious requests without penalty for delaying an urgent transaction.

What Do BEC Attackers Want?

BEC attackers typically seek money, data, credentials, or control over a business relationship. The request often appears ordinary because the criminal copies the language, timing, signatures, and approval sequence employees already use.

Direct payment fraud is the most recognizable objective. A cybercriminal impersonates an executive, supplier, attorney, or customer and requests a wire transfer, invoice payment, refund, or bank-account update.

The message does not need malware or a dramatic warning. It only needs to arrive when a payment is due and fit the organization’s normal workflow.

Payroll diversion targets HR and payroll processes. The cyberattacker asks to change an employee’s direct-deposit details, tax information, or benefits account. Payroll teams handle legitimate changes under time pressure, so a well-timed request can pass through routine processing unless staff verify it through a known channel.

Credential theft gives cybercriminals access to email, cloud applications, financial systems, and internal conversations. A fake password-reset notice or account-verification request can capture credentials and multifactor authentication codes.

After entering a real mailbox, the intruder can monitor conversations, learn approval patterns, and send messages from a compromised account instead of a spoofed address.

Sensitive-data theft targets W-2 forms, customer records, contracts, acquisition plans, intellectual property, and payment data. The request may be framed as an audit, legal review, new-client onboarding task, or executive briefing.

Employees should treat unusual data requests with the same care as payment requests because disclosure can create regulatory, contractual, and competitive damage.

Relationship manipulation supports every other objective. A BEC actor may observe a conversation for days before inserting a request that matches its context. That preparation makes the fraudulent message feel like a continuation of work already underway.

Training should teach employees to verify changes in payment instructions, access permissions, and data destinations, extending the check well past the sender address.

How Does BEC Differ From Ordinary Phishing?

BEC differs from broad phishing through target selection and intent. Ordinary phishing often distributes the same lure to a large audience, such as a fake shipping notice, password alert, or subscription invoice.

Spear phishing and BEC are more deliberate. The cyberattacker identifies a person, business relationship, or transaction, then builds a message around that specific context. A closer comparison of BEC and email account compromise shows where the two overlap.

Broad phishing tries to create a reaction at scale. BEC tries to create compliance inside a real process. The message might reference a genuine supplier, actual invoice number, current project, or known executive.

It can use a spoofed domain, compromised mailbox, lookalike account, or phone call that reinforces the email. The more accurately it fits the organization’s workflow, the less it resembles a conventional phishing message.

That distinction changes the defense. Employees are often taught to look for poor spelling, unfamiliar senders, suspicious attachments, or strange links. Those signals still matter, yet they do not expose a request from a compromised account written in flawless business language.

BEC defense must add process verification. Employees need permission to contact the requester through a known phone number, confirm bank changes with an established vendor contact, and require dual approval for high-value or unusual transactions.

BEC also extends beyond email. A fraudulent SMS, phone call, collaboration message, or video meeting can reinforce an email and create false confirmation.

Security awareness programs should rehearse the full interaction, including the moment an employee feels pressure to act. Limiting practice to spotting suspicious messages in an inbox leaves the hardest decision untrained.

Phishing simulations covering email, voice, SMS, and impersonation give teams a controlled way to practice those decisions without risking a real payment or disclosure.

Why Is the Target Usually a Trusted Business Process?

The target is usually a trusted business process because trust reduces the questions required before action. Employees do not approve every invoice from first principles, call every executive before responding, or independently authenticate every routine request.

They rely on established relationships, recurring schedules, familiar systems, and delegated authority to keep the organization moving.

BEC exploits that efficiency. The cyberattacker does not need to make an impossible story seem true. The objective is to make a plausible request appear to belong inside an existing process.

A fake supplier-account change works because supplier updates are legitimate. A request for employee records works because HR regularly shares information with authorized parties. An urgent executive payment works because executives sometimes need rapid action.

This design makes employees a critical defensive asset. The person closest to a payment, account change, or data request often has the context needed to notice that something does not fit.

Training should build recognition around deviations, including new bank details, unusual urgency, secrecy demands, after-hours requests, altered reply addresses, and instructions to bypass normal approval.

The strongest control is a defined verification gate attached to the process itself. Finance can require confirmation through a known vendor contact before changing payment instructions. HR can verify payroll changes through an established internal channel.

IT can require an independent identity check before resetting privileged access. Executives can make clear that no request to bypass controls is valid solely because it appears to come from them.

Business email compromise targets an organization’s trust architecture. The practical response is to identify who can authorize money, data, access, and relationship changes, then give each person realistic practice and a simple way to stop and verify unusual requests.

Protecting that process starts with recognizing the signals employees encounter when a routine request no longer fits.

Which Finance Employees Are Targeted by BEC?

Business email compromise (BEC) targets employees based on access to money, payment instructions, credentials, or financial data. Job title matters far less than authority. Accounts payable staff, controllers, and treasury teams can initiate, verify, or release payments.

Procurement staff, bookkeepers, and finance managers manage vendor relationships, invoices, and approval authority. The strongest defense maps payment authority across the organization and rehearses verification and reporting behaviors for every employee who can influence a transaction.

Which Employees Have Payment Authority?

Payment authority makes an employee a high-value BEC target because one trusted action can move money without requiring a cyberattacker to breach a bank or accounting platform. Who is targeted by BEC inside finance follows the approval chain.

Accounts payable employees receive invoices, manage payment queues, and communicate with vendors, which makes them attractive targets for invoice fraud and payment redirection.

Controllers and finance managers can approve exceptions, release payments, or override routine controls. Treasury teams can initiate high-value wires, manage banking portals, and coordinate cash movement across subsidiaries or jurisdictions.

Federal fraud reporting describes BEC as a scam aimed at organizations that work with suppliers or perform wire transfers. The criminal does not need to deceive an entire company. A convincing request aimed at the person who can change a beneficiary, release a payment, or confirm an account can be enough.

Payment types create different incentives and consequences:

  • Wire transfers: High-value and often difficult to reverse, wires attract executive impersonation, urgent acquisition requests, and fake closing instructions. Treasury and controller teams should require independent confirmation before releasing them.
  • ACH changes: Cybercriminals target employees who can alter account and routing details because a small change can redirect recurring payroll, supplier, or customer payments. Every change should be verified using a known phone number or established portal, never contact information supplied in the request.
  • Payroll changes: Payroll administrators and HR staff can be pressured to update direct-deposit details. The fraud can remain hidden until payday, so changes need employee confirmation and an audit trail.
  • Gift cards: These requests seek quick, low-friction purchases instead of bank transfers. They often target executive assistants, office managers, and administrative staff who can buy cards or distribute redemption codes.
  • Cryptocurrency payments: Crypto transfers are difficult to recover and can be framed as urgent settlement, investment, or vendor payments. Employees should treat every new wallet address as a high-risk payment change.
  • Vendor banking updates: A request to replace a supplier’s bank account can appear routine during a renewal or invoice dispute. Vendor email compromise occurs when a cyberattacker gains access to, impersonates, or hijacks a supplier’s email account to manipulate a customer’s payment or purchase process.
  • Product orders on credit: Procurement employees can be tricked into placing large orders with approved vendors or shipping goods to an attacker-controlled location. The organization can lose inventory, incur debt, and discover the fraud only when the invoice arrives.

Removing employees from payment workflows solves nothing. Give them clear authority boundaries, reliable verification routes, and realistic practice with the pressure tactics that make fraudulent requests feel legitimate.

How Do Payment-Change Workflows Create BEC Exposure?

Payment-change workflows are exposed when one email can alter where money goes without a second channel, independent review, or documented approval.

Cybercriminals study public information and compromised mailboxes to identify invoice cycles, approval thresholds, supplier names, travel schedules, and language used by finance leaders. They insert themselves into existing conversations or create new ones that look ordinary enough to pass through a busy queue.

The most dangerous workflow is often the quietest. A message from a known supplier asking to update bank details can outperform a dramatic CEO request because it fits an expected business process.

A cyberattacker can monitor a real invoice thread, copy the vendor’s signature, and send a replacement document with altered account information. If the employee replies to the compromised mailbox, the criminal can continue the conversation and reinforce the false instructions.

Finance leaders should separate requesting, verifying, and approving a payment. The employee who receives a banking change should not be the only person who validates it, and the approver should see the original supplier record instead of a forwarded email.

Verification should use a trusted contact stored in the enterprise resource planning system, a previously used telephone number, or a supplier portal reached through a known bookmark.

Decentralized approval processes increase exposure when departments use different rules. A regional office might approve invoices locally, while headquarters controls treasury payments and procurement manages purchase orders.

Cybercriminals exploit those seams by presenting a request as already approved elsewhere. A common policy, shared escalation route, and visible exception log close the gaps without forcing every payment through one central team.

High transaction volumes create another advantage. Employees processing hundreds of invoices, refunds, or payroll records each day cannot investigate every message as though it were a major incident.

Controls must make the safe action faster than the unsafe action. A payment-change form with mandatory callback verification, a visible hold status, and automatic escalation for new beneficiaries gives employees a practical way to stop suspicious activity without guessing.

Employees should also recognize mismatched urgency. A request that demands secrecy, bypasses normal approval, changes a familiar account, or arrives immediately before a deadline deserves additional scrutiny.

Pausing and reporting these signals protects the transaction and gives security teams time to examine related messages, accounts, and recipients.

Why Are Nonfinance Employees With Financial Access Targeted?

Nonfinance employees become BEC targets when their operational role grants financial access without a finance title. Executive assistants may arrange travel, purchase gift cards, or coordinate urgent requests from senior leaders.

Office managers can order equipment, approve invoices, or manage corporate cards. Sales operations staff may issue refunds, alter customer payment records, or share sensitive account information. HR employees can change payroll details, and project managers may approve contractors, purchase orders, or milestone payments.

These employees are valuable because their financial responsibilities are less obvious to the organization and to the individuals themselves. Someone who does not identify as a finance professional may overlook that updating a supplier, approving a refund, or confirming a direct deposit carries the same fraud risk as a wire transfer.

Role-based training should follow access and behavior instead of department labels. Employees who can influence money need payment-fraud scenarios even when their primary work involves administration, operations, HR, or customer service.

The same principle applies to credentials and financial data. A cybercriminal who cannot induce an immediate payment can seek access to an accounting platform, payroll system, procurement mailbox, or executive account.

Stolen credentials can support a later payment fraud campaign, expose tax records and supplier data, or allow the intruder to observe transactions before choosing the most profitable moment to act.

Security teams should inventory who can approve, edit, view, or initiate financial activity across business applications. The inventory should include delegated access, temporary permissions, shared mailboxes, mobile approval tools, and employees who can create purchase orders on credit.

Read-only access to supplier records can help a cyberattacker craft a credible impersonation, while purchase approval without bank-detail access still creates exposure to fraudulent orders and altered invoices.

Do Attackers Prefer Direct Payment Fraud or Financial-Data Theft?

Direct payment fraud is the fastest path to revenue, so cybercriminals choose it when they can reach an employee with authority and create a believable transaction.

A fake wire request, altered ACH instruction, or cryptocurrency wallet change aims to move funds before the organization detects the deception. The attack succeeds when the employee treats the message as a routine business decision and the workflow lacks independent verification.

Credential or financial-data theft supports a longer campaign. Cyberattackers may target a controller’s mailbox to read invoices, a bookkeeper’s accounting credentials to understand payment schedules, or a procurement employee’s files to identify suppliers and credit limits.

That intelligence supports later impersonation, enables fraud against business partners, and creates additional exposure even when no payment occurs immediately.

Payment controls alone do not address account takeover. Finance employees need practice identifying suspicious login prompts, unexpected document-sharing requests, and messages that ask them to move conversations to personal email or messaging apps.

They also need a rapid reporting path so security teams can revoke sessions, reset credentials, and review mailbox rules before an intruder changes payment instructions.

A human-risk program should connect these signals. Someone who clicks a credential lure, approves an unusual payment, and fails to report a suspicious message requires targeted coaching in place of public blame.

Phishing simulations for BEC and vendor impersonation can safely rehearse those decisions across accounts payable, treasury, procurement, HR, and executive-support roles.

BEC prevention depends on treating every payment-capable employee as part of the financial control environment. Map authority, require trusted-channel verification for changes, separate approval duties, and rehearse the requests employees handle under deadline pressure.

Those controls protect the organization whether a cybercriminal wants an immediate transfer, a payroll diversion, a fraudulent order, or the credentials needed to return later.

Are CEOs, CFOs, and Executive Assistants Targeted by BEC?

Who is targeted by business email compromise (BEC)? CEOs, CFOs, executive assistants, and employees positioned near payment, legal, or confidential-information workflows.

Cybercriminals choose these roles because authority accelerates compliance, while access and proximity shorten the path to money or sensitive data. Seniority still does not determine exposure. A nonexecutive employee with mailbox, calendar, or payment access can be as valuable as the executive being impersonated.

Who is targeted by BEC includes executive assistants verifying an urgent leadership request by phone.

Why Are Executives Prime Impersonation Targets?

Executives carry authority that can override hesitation. CEO fraud typically presents as an urgent request to transfer funds, purchase gift cards, release confidential documents, or bypass an approval step.

CFO fraud focuses on wires, vendor payments, banking changes, financial forecasts, and other actions associated with financial authority.

The attack does not require access to the real executive’s mailbox. A cybercriminal can use a lookalike domain, personal account, spoofed display name, or compromised colleague’s account to create the appearance of executive direction.

Accurate project names, invoice amounts, and internal terminology gathered through open-source intelligence (OSINT) make the request feel operational.

Authority pressure works because employees are trained to respond quickly to senior leaders, particularly when a request involves a closing, acquisition, legal matter, or financial deadline.

"Please handle this before the board meeting" sounds plausible. "I am traveling and cannot take a call" appears to explain why the normal process is changing. "Keep this confidential" discourages the recipient from asking another person to verify the instruction.

Travel and absence create useful attack conditions. Cybercriminals can monitor public posts, conference schedules, investor events, and out-of-office messages to identify when an executive is away.

The fraudulent request arrives when colleagues expect delayed replies, mobile communication, and unusual time pressure. A message sent from an airport, hotel, or personal phone can seem normal even when it requests an abnormal payment.

Counterfeit letterhead and fake legal documents strengthen the pretext. A BEC actor might attach a fabricated law firm letter, settlement agreement, purchase order, or bank instruction with a familiar logo and signature block.

Employees should verify the requested action, document origin, and underlying business event through known contacts. Professional formatting proves nothing on its own.

CFO fraud also exploits the separation between financial authority and execution. The CFO may authorize a payment, while a controller, treasury analyst, or accounts-payable employee enters the beneficiary details.

Cyberattackers can impersonate the executive who approves the transfer or compromise the employee who executes it. A safe process requires independent confirmation of payment details before release.

A pre-agreed verification protocol gives employees a clear action under pressure. Executives should tell their teams that urgent requests still require a callback through a known number, confirmation in an established internal channel, or approval through the normal payment workflow.

Security leaders should ensure employees can pause a request without being treated as obstructive. Verification protects the executive, the employee, and the organization’s cash.

How Do Executive Assistants Become Access Points?

Executive assistants are targeted because they sit close to authority, information, and timing. They often manage calendars, travel, confidential communications, meeting logistics, invoices, visitors, and urgent requests.

That position provides the context needed to make an impersonation credible and the operational access needed to move it forward.

An assistant may lack authority to approve a wire while still coordinating the person who holds it. A fraudulent request can ask the assistant to schedule a call, forward a document, confirm a travel itinerary, purchase gift cards, release a contact list, or prepare a payment for executive approval.

Each action reveals information or creates another opportunity to pressure an employee.

Calendar access is especially valuable. A compromised assistant account can expose executive travel, private meetings, board sessions, legal consultations, and vendor negotiations.

A cybercriminal can use that information to send a request at the right moment. An email that references a real flight, client meeting, or attorney appears authentic because the impersonator has mapped the executive’s schedule.

Assistants also manage communication gaps. When an executive is in transit, in a closed meeting, or overseas, colleagues expect the assistant to relay instructions.

A BEC attacker can exploit that expectation with a message claiming the executive needs immediate help. The request may arrive by email, text, or phone before shifting channels to reinforce the story.

A supposed CEO might email, follow up by SMS, and instruct the assistant to keep the matter private until the executive returns.

The defense must protect assistants from authority pressure and avoid placing the burden on personal suspicion. Requests involving money, credentials, confidential files, gift cards, or unusual secrecy should require confirmation through an independent channel.

The assistant can call the executive using a number stored in the corporate directory, contact the finance owner through a known account, or use a documented delegate workflow. Replying to the original message is never verification when that account is compromised.

Role-specific Phishing Simulations can rehearse these decisions with executive assistants, chiefs of staff, and administrative teams. An exercise might begin with a request from a traveling CEO, add counterfeit letterhead from outside counsel, and end with a phone call demanding immediate action.

The objective is to make pausing, verifying, and reporting faster than compliance, without shaming the employee.

Assistants should also know which information they must never disclose. Calendar details, executive mobile numbers, travel plans, board materials, and legal correspondence can help a cyberattacker construct the next stage of a campaign.

Access should follow job requirements, forwarding rules should be monitored, and delegated mailbox permissions should be reviewed regularly. An unusual request should trigger investigation of related messages, sign-ins, and mailbox rules.

Can a Compromised Nonexecutive Account Lead to Executive or Finance Fraud?

A compromised nonexecutive account can become a stepping stone to executive or finance fraud because it provides authenticity, relationships, and internal context.

BEC attackers do not always begin with the CEO or CFO. They may compromise an employee whose mailbox contains supplier conversations, payment schedules, organizational details, or direct access to executive staff.

A legitimate employee account can send messages that pass normal trust checks. The intruder can read existing threads, copy the organization’s writing style, identify payment approvers, and wait for an appropriate business event.

The first request may be low risk, such as confirming an invoice or asking whether a colleague is available. Later, the criminal introduces a new bank account, urgent transfer, or confidential document request.

Nonexecutive accounts can also provide lateral access. An employee may have delegated calendar permissions, shared-drive access, vendor contacts, or an active conversation with the CFO’s office.

A cybercriminal who controls that account can impersonate the employee while approaching an executive assistant, finance analyst, or procurement manager. The recipient sees a familiar colleague and responds accordingly.

BEC defense therefore cannot focus only on executive mailboxes. Security teams should monitor unusual sign-ins, new forwarding rules, unexpected delegates, abnormal sending patterns, and messages to unfamiliar external domains.

When account takeover is suspected, they should revoke active sessions, reset credentials, and inspect connected applications. Employees who notice signs of a compromised email account, such as missing messages, unfamiliar sent mail, or unexpected password alerts, should report them immediately.

The same stepping-stone pattern affects finance accounts. A compromised employee may gather vendor records and payment history before targeting accounts payable.

The cyberattacker can impersonate a supplier, manager, or executive using information from legitimate correspondence. Finance employees should compare every payment request with the vendor record, purchase order, and established approval path.

Federal fraud guidance distinguishes BEC from ordinary malicious-email activity because the fraud targets legitimate business processes and transfer-of-funds workflows. That distinction matters operationally.

Email controls can identify suspicious messages, yet employees and process owners must recognize when a familiar communication asks them to change payment details, disclose data, or bypass review.

Every high-risk request needs an independent check. Confirm an executive’s instruction through a known number, validate a legal document with the law firm’s established switchboard, and verify vendor banking changes against a trusted supplier record.

Contact information supplied in the suspicious message is never a safe route, and a reply within the same thread proves nothing.

The risk extends beyond email. In the 2024 Arup fraud in Hong Kong, a finance employee transferred approximately $25 million after a video call populated with deepfake participants, according to CNN’s 2024 reporting.

A familiar face, voice, document, or account establishes context without establishing identity. Independent verification must control the transaction before authority pressure turns deception into an irreversible action.

Why Are HR, Payroll, and IT Employees Targeted by BEC?

HR, payroll, and IT employees are targeted by business email compromise (BEC) because their routine responsibilities connect cybercriminals to money, personally identifiable information, credentials, and privileged systems.

The objective changes by role. Cyberattackers targeting HR seek records or payroll changes, while those targeting IT seek the access needed to control accounts and expand the fraud. Who is targeted by BEC in these teams follows the permissions each role holds, so every group needs role-specific verification procedures.

Why Does BEC Target HR and Payroll Employees for Money and Payroll Data?

HR and payroll teams sit directly between employee identity and compensation, which makes them attractive targets for payroll diversion and data theft.

A cyberattacker impersonating an employee may request a direct-deposit change, while one impersonating an executive or HR leader may demand an urgent payroll-file export before a stated deadline.

Payroll diversion is usually a money-first attack. The criminal wants wages redirected to a controlled account, often by changing bank details shortly before payroll processing.

The request may appear to come from a compromised mailbox, a personal email address, or a spoofed identity. Payroll systems also contain tax forms, salary details, home addresses, bank-account information, employee identification numbers, and benefits records that can support identity fraud and more convincing spear phishing.

Personally identifiable information, or PII, is information that can identify a specific person, either alone or when combined with other data.

Names, home addresses, Social Security numbers, tax forms, employee IDs, account details, and health or benefits information can all become valuable after a BEC incident. The FBI’s 2024 BEC public service announcement identifies PII as a target because stolen records can enable follow-on fraud and account compromise.

HR should treat every request involving payroll, tax forms, benefits data, employee rosters, or changes to personal information as a controlled transaction.

Confirm direct-deposit changes with the employee through a known phone number or established HR portal, setting aside any contact details supplied in the message. Require documented approval for bulk data exports and share only the fields necessary for the stated business purpose.

Why Are Sensitive-Data Teams Targeted?

Legal, compliance, security, and executive operations staff are targeted because they handle information that can create financial, regulatory, or strategic consequences.

A fake executive may request a confidential acquisition file. A supposed attorney may ask for a settlement document or privileged correspondence. A criminal posing as a compliance officer may seek audit records, customer files, or evidence of internal controls.

The objective in these cyberattacks is access to information and authority, and an immediate transfer often matters less. Employee records, contracts, litigation materials, investigation notes, customer data, and regulatory submissions can reveal who approves payments, which vendors are trusted, and how the organization responds to incidents.

That information makes later impersonation more credible and helps cybercriminals identify exceptions worth exploiting.

Sensitive-data requests should trigger three checks:

  • Identity: Confirm the requester through a separate, established channel.
  • Purpose: Verify the business reason for the request with the relevant manager or process owner.
  • Scope: Limit the information released to the minimum necessary fields.

Legal and compliance teams should maintain approved repositories and access groups so employees stop treating email attachments or personal file-sharing accounts as normal destinations for confidential material.

Clear processes give employees a safe way to challenge unusual requests without slowing legitimate work.

Why Does BEC Target IT and Identity Administrators for Account or Systems Access?

IT administrators and identity or cloud administrators are targeted for a different reason. HR-focused cyberattackers want records or payroll changes. IT-focused cyberattackers want control.

A successful credential reset, MFA change, mailbox-rule creation, or privileged-account takeover can give criminals the authority to impersonate other employees and disable safeguards that would expose the fraud.

A typical request may claim that an executive is locked out, a contractor needs urgent access, or a security incident requires MFA to be temporarily removed.

If an administrator accepts the request, the intruder can reset passwords, register a new authentication device, add forwarding rules, create OAuth access, alter conditional-access policies, or reach privileged systems.

The mailbox can then become a trusted platform for follow-on BEC against finance, HR, vendors, and executives.

Administrators should never approve high-risk identity changes from an email request alone. Require a verified service ticket, confirmation from the account owner through an established channel, phishing-resistant MFA for privileged access, and two-person approval for emergency changes.

After any unusual reset or exception, review sign-in activity, new MFA registrations, delegated permissions, mailbox rules, and cloud-role assignments.

Role-based Phishing Simulations can rehearse these distinct objectives without blaming employees. HR teams can practice payroll diversion and PII requests, while IT teams can practice fake password resets and MFA-change requests.

The strongest defense is a practiced pause that matches each employee’s responsibility to the cyberattacker’s goal.

Are Vendors, Suppliers, Business Partners, and Customers BEC Targets?

Vendors, suppliers, business partners, and customers are all targets of business email compromise (BEC) because cybercriminals exploit established trust between organizations as readily as weaknesses inside one company.

The immediate consequence can be a fraudulent payment, shipment, account change, or disclosure request that appears routine because it uses a familiar contact, active transaction, and realistic conversation history.

Who is targeted by BEC therefore extends across the entire commercial relationship. The FBI’s 2024 BEC public service announcement describes scams targeting businesses and individuals handling legitimate transfer-of-funds requests, with losses that can spread across multiple organizations before anyone recognizes the deception.

BEC targets vendor payment workflows as a procurement manager verifies supplier bank details.

How Are Vendor and Supplier Relationships Used in BEC?

Vendor and supplier relationships are attractive BEC targets because payment instructions change during ordinary business activity.

A cyberattacker who compromises a supplier’s mailbox, imitates its domain, or takes over a partner account can reply inside an existing invoice thread. The request asks only that future payments go to a new bank account. The message needs no new story. It only needs to change one operational detail.

Common requests include:

  • Changing the bank account for an upcoming invoice
  • Sending payment to a temporary account during an audit or merger
  • Updating a supplier’s shipping address or delivery instructions
  • Reissuing a refund to a different account
  • Confirming tax, payroll, or remittance information through an attachment
  • Paying an urgent invoice before a contract, shipment, or service deadline

Cybercriminals strengthen the deception with conversation context. They copy the supplier’s writing style, reference the correct purchase order, mention the right account manager, and preserve the original email thread.

Vendor email compromise can bypass normal suspicion because the request fits the transaction already in progress. Reviewing the full range of business email compromise types helps teams recognize which variant they are facing.

The safest response is procedural. Treat every banking, shipping, or payment-detail change as a high-risk request that requires verification through a known phone number, an established vendor portal, or a second trusted contact.

Contact information supplied in the change request should never be used, and approval should come from someone outside the original conversation.

Why Are Customers and Downstream Partners BEC Targets?

Customers become BEC targets when cybercriminals impersonate a buyer, account holder, retailer, distributor, or downstream partner that employees already expect to hear from.

A fraudulent customer message can request a refund, redirect a payment, alter delivery details, release confidential information, or persuade an account manager to bypass an approval step. The advantage comes from making the request look like the next action in a legitimate business relationship.

Compromised retailer and partner accounts create the same risk in the opposite direction. A genuine account can send a malicious request from a trusted address, which makes sender authentication alone insufficient.

Cybercriminals also exploit delays between sales, procurement, logistics, accounts receivable, and customer service teams. When no single employee sees the full transaction, a small change can pass through several departments without triggering a challenge.

Organizations should separate relationship management from payment authorization. A customer success manager can confirm that a request is genuine, yet that confirmation should never replace independent payment verification.

Finance, sales, procurement, and logistics teams need a shared escalation path for unusual refunds, urgent credits, new delivery destinations, and changes to customer or partner account details.

Employees are trainable defenders who need clear authority to pause a transaction without being penalized for caution.

Which Third Parties in the Payment Chain Can Be Impersonated?

Third parties in the payment chain are BEC targets because they sit between the organization sending money and the organization expecting it.

Attorneys can appear to request confidential settlement payments or wire transfers. Outsourced accounting providers can be impersonated to change payroll, tax, or vendor instructions. Payment processors, banks, and cryptocurrency exchanges can serve as believable destinations or intermediaries for fraudulent funds.

The FBI’s 2024 guidance identified growth in BEC funds sent to financial institutions holding custodial accounts for third-party payment processors, peer-to-peer payment processors, and cryptocurrency exchanges.

The same guidance reported a 9% increase in identified global exposed losses between December 2022 and December 2023, showing how cybercriminals are extending the payment chain instead of relying on one direct transfer.

The advisory recommends secondary-channel verification for account-information changes and immediate contact with the financial institution after a fraudulent transfer.

Payment-chain controls should define who can request, approve, and execute a change. Banks and processors should be treated as verification points, and their involvement is never automatic proof that an instruction is legitimate.

A request that arrives through an attorney, accounting firm, customer, or payment provider still requires confirmation against independently maintained records.

A continuous phishing simulation program can rehearse vendor impersonation, customer fraud, BEC, and multi-channel follow-up requests so employees practice stopping the transaction before money moves.

Those controls become most important where payment authority and account access converge.

Are Small Businesses and Certain Industries More Likely to Be Targeted by BEC?

Business email compromise (BEC) targets organizations of every size, from small businesses and nonprofits to multinational enterprises and government agencies.

In smaller organizations, cybercriminals pursue accessible payment processes. In enterprises, they pursue larger transfers, complex access, and supply-chain relationships. Who is targeted by BEC depends more on industry, transaction volume, international relationships, and approval discipline than on headcount alone.

How Does Organization Size Change BEC Risk?

Organization size changes the cyberattacker’s economics while leaving every organization exposed. Small businesses are attractive because one compromised mailbox can reveal invoices, payroll details, customer relationships, and payment instructions.

A business owner or office manager may control several stages of a transaction. Separate those duties so the person who receives or changes payment instructions cannot independently approve and release funds.

Mid-market organizations often combine higher transaction values with developing processes. Cybercriminals can impersonate executives, vendors, outside counsel, or customers while exploiting rapid growth, acquisitions, remote work, and newly formed finance teams.

A written callback procedure, independent verification for bank-account changes, and mandatory dual approval reduce the value of a stolen mailbox.

Enterprises offer larger targets, and their complexity creates different openings. Cyberattackers can pursue accounts-payable staff, regional offices, procurement teams, treasury personnel, or executives with authority across business units.

They can also use compromised supplier or client accounts to make a fraudulent request look routine.

The FBI’s 2025 Internet Crime Report recorded more than $20 billion in reported cybercrime losses overall. That figure makes every payment-change request a verification event deserving the same scrutiny as any financial control.

Which Industries Face High-Value BEC Exposure?

Industry risk follows money movement and trust relationships more closely than any fixed ranking. Law firms handle client-fund transfers, settlement payments, and confidential deal information.

Real estate and construction organizations process deposits, closings, progress payments, and subcontractor invoices, creating repeated opportunities to alter account details.

Manufacturing and engineering companies often depend on international suppliers, long purchasing cycles, and technical projects where a familiar contact can request an urgent exception.

Technology companies and professional-services firms hold valuable customer data and maintain broad access across cloud applications. Retail organizations manage distributed locations, vendors, and seasonal payment volume.

Healthcare organizations combine insurance reimbursements, medical suppliers, payroll, and regulated information. A compromised finance or administrative account can therefore create both financial and privacy consequences.

Each industry needs payment controls that reflect its actual approval paths, vendor relationships, and transaction types.

International suppliers and complex supply chains increase the number of legitimate payment relationships employees must distinguish. That complexity gives cybercriminals cover because a new bank account, changed remittance address, or urgent invoice can appear consistent with normal business activity.

Maintain verified supplier contact records outside email and require a second channel for any change involving account ownership, routing details, or payment timing.

Teams can reinforce those controls through Phishing Simulations that rehearse vendor impersonation, invoice fraud, and executive requests across the roles that approve or release money.

Employees are not being tested for perfection. They are practicing the verification behavior that interrupts fraud.

Are Public-Sector, Nonprofit, and Education Organizations Targeted?

Public-sector agencies, nonprofits, schools, and universities are targeted because they manage funds, grants, payroll, procurement, and donor or student relationships.

Government agencies also operate through contractors and interagency partners, allowing a fraudulent request to hide inside a legitimate chain of approvals. A documented approval path and independent callback process give staff a clear way to challenge suspicious requests.

Nonprofits can face concentrated risk when a small finance team manages donations, grants, and vendor payments with limited backup capacity. Assigning a second approver and maintaining current contact records reduces dependence on one mailbox or employee.

Schools and universities have broad access structures. Finance offices, research administrators, athletics departments, housing teams, and individual faculties can maintain separate payment processes, while international research and student programs create cross-border transactions.

A consistent verification standard across departments is safer than allowing each unit to create its own safeguards.

What Should Organizations Do Regardless of Size?

Every organization should identify high-impact payment workflows, map who can request and approve changes, and rehearse the moments when urgency is most likely to override judgment.

Leaders should require out-of-band confirmation using a trusted number, prohibit approval based solely on a reply thread, and train employees to pause without fear of delaying legitimate work.

Regular simulations should reflect the organization’s actual vendors, roles, and payment language. Reporting behavior and verification decisions should guide follow-up training, and shaming employees who make mistakes only suppresses reports.

BEC reaches every sector and company size. A repeatable process that makes independent verification faster than fraudulent payment turns employees into an active control at the point where trust becomes money.

How Do BEC Attackers Choose Their Targets?

Business email compromise (BEC) attackers target people whose decisions move money, disclose sensitive information, or change trusted instructions.

They collect public clues, map authority and relationships, then choose employees whose messages can trigger action quickly. Understanding who is targeted by BEC begins with understanding that selection process.

Organizations can disrupt it by limiting exposed details, enforcing independent verification, and training employees to challenge unusual requests without fear of blame.

1. Collect Public Information

Information collection gives cybercriminals the context to make BEC messages sound routine.

They review company websites, LinkedIn profiles, social media posts, job postings, regulatory filings, press coverage, and conference announcements to identify executives, finance staff, assistants, legal teams, and employees responsible for suppliers or customers.

Vendor references, procurement announcements, and hiring descriptions can also reveal internal systems, payment platforms, and approval responsibilities.

Separate details become more dangerous when combined. A company website might identify the chief financial officer, a job posting might mention accounts-payable software, and a social media post might show that the finance director is attending an overseas event.

None of those details proves a security failure, yet together they help a cyberattacker construct a credible request.

Treat public exposure as a human-risk signal. Review which roles, systems, and processes are visible, and remove unnecessary operational detail from public pages and social posts.

Organizations should also ensure that temporary coverage and delegated approval rights are communicated through trusted internal channels, keeping them out of public updates.

Cybercriminals look for personal context that increases credibility, including vacation announcements, executive travel, office closures, industry events, and visible working hours.

Employees should avoid publishing real-time travel details, while security leaders should include open-source intelligence (OSINT) exposure in human-risk reviews.

2. Score Targets by Authority and Access

Cyberattackers prioritize people who can approve payments, alter bank details, release sensitive files, authorize vendors, or influence someone with that authority.

They examine reporting lines and organizational charts to determine who reports to whom, which executive can pressure a finance employee, and which assistant can schedule a meeting or forward a request.

Business relationships provide another credibility signal. A supplier, law firm, customer, or acquisition partner gives a cybercriminal a legitimate reason to make contact.

The impersonator can imitate a known relationship, insert a payment change into an existing conversation, or pose as an executive coordinating a transaction.

The highest-risk target is often a junior employee. An accounts-payable specialist may have direct invoice access, while an executive assistant may control calendars and internal routing.

Security leaders should map roles by action authority and treat job title as a weak signal. Finance, procurement, executive support, and vendor-management teams then need scenario-based practice for payment changes, urgent requests, and confidential-data transfers.

Phishing simulations can rehearse these decisions across email, voice, and SMS without exposing real funds or information.

3. Identify Signs of Pre-Attack Surveillance

Active surveillance often appears as small deviations from normal communication. An unusually specific message might reference a recent meeting, a vendor name, a transaction amount, or a colleague’s travel schedule.

Timing aligned with a real invoice, acquisition, payroll run, or executive absence increases pressure because the request appears within an expected business event.

Conversation hijacking is a stronger warning sign. A compromised email account allows a cyberattacker to read an existing thread and reply with the correct names, signatures, and project history.

The message may contain no obvious spelling errors because the criminal is continuing a legitimate conversation.

Employees should verify any change to payment instructions, account numbers, delivery details, or approval routes through a known phone number or separate trusted channel.

Requests to skip a second approver, avoid a ticket, keep a transaction confidential, use a personal account, or act before a deadline indicate that the cyberattacker is testing whether authority can replace controls.

A compromised mailbox, unusual login notice, or unexpected contact method raises the risk further. Employees who notice these signals should pause, report the message, and preserve the thread for investigation.

A fast report protects the organization even when the employee did not initially recognize the attempt, giving security teams the signal they need to contain human-layer risk.

Which BEC Channels and Situations Put Employees at Risk?

Business email compromise (BEC) targets employees through trusted communication channels, and spoofed email and compromised accounts create different forms of pressure.

Spoofed email fabricates the sender’s identity while the cyberattacker controls neither the real account nor its history. A compromised account provides an authentic mailbox, existing contacts, and active conversations, which makes the request harder to question.

Spoofing is easier to detect when domain details or message context look wrong, while conversation hijacking can appear to continue a legitimate business discussion. Who is targeted by BEC through each channel depends on the pressure that channel can create.

Both cyberattacks succeed when urgency, authority, and routine business activity overpower an employee’s normal verification habits. Clear approval rules and realistic practice give employees a reliable way to interrupt that pressure.

Which Communication Channels Do BEC Attackers Use?

BEC moves across email, voice, video, text, and QR codes because each channel can reinforce the others.

The FBI’s business email compromise guidance describes the crime as an attempt to deceive organizations into sending money or sensitive information through trusted business communications.

Common channels include:

  • Spoofed email: A forged executive, vendor, or attorney address requests a payment, password reset, or confidential file.
  • Compromised email accounts: A cyberattacker takes over a real mailbox and sends messages from an address employees already trust.
  • Conversation hijacking: The criminal inserts a reply into an existing invoice, acquisition, or legal discussion, often within the same thread.
  • AI-generated phishing emails: Generative tools produce fluent, personalized messages that remove the spelling errors and awkward phrasing employees once used as warning signs.
  • AI voice cloning and vishing: A cloned executive voice on a phone call pressures an employee to approve a transfer or reveal a code.
  • Fake video meetings: A deepfake executive or finance leader appears on a video call and confirms a payment instruction, as the 2024 Arup case in Hong Kong demonstrated.
  • Smishing: A text message impersonates an executive, bank, courier, or supplier and directs the recipient to respond quickly.
  • Quishing: A QR code in an email, invoice, or printed notice sends the employee to a fake login page or payment workflow.

The differences between vishing and smishing matter because each channel carries its own verification gap.

The 2024 impersonation of Ukraine’s former foreign minister Dmytro Kuleba in a video call with U.S. Sen. Ben Cardin shows why voice and video verification cannot stand alone, according to The Washington Post’s reporting.

Cyberattackers can make a conversation appear authentic while bypassing normal identity checks. Employees should verify unusual requests through a previously known phone number, a separate collaboration channel, or an approval process that does not depend on the message itself.

Phishing Simulations that rehearse email, voice, SMS, and video scenarios make that behavior familiar before a real request arrives.

Training should focus on the decision employees need to make. Punishing anyone who misses a simulation undermines that goal.

Which Business Moments Create the Most BEC Pressure?

High-pressure business moments give cybercriminals a credible reason to demand speed.

Fiscal year-end, payroll deadlines, tax periods, vacations, legal settlements, and major project launches all create legitimate time-sensitive work, so an unusual request can blend into a busy workflow.

Mergers and acquisitions are especially attractive because deal teams exchange sensitive documents, use outside advisers, and often limit internal disclosure.

A fake law firm, banker, or executive can exploit that confidentiality by asking an employee to change payment instructions or send restricted information. The same tactic works during a vendor transition, real estate closing, or emergency procurement event.

Managers are not automatically more likely than other employees to fall for BEC. They often control budgets and receive more executive correspondence, which increases their exposure and the financial consequence of a mistake.

Staff members may process invoices, update supplier records, or handle executive calendars. Risk depends on access, authority, workload, and the type of request, with job title playing a smaller part.

Organizations should test role-specific scenarios across finance, executive support, procurement, legal, IT, and operations.

That approach identifies where approval authority and sensitive data intersect without singling out managers or shaming employees who miss a simulation. The results show which workflows require stronger verification controls.

How Do Remote and Hybrid Work Change BEC Risk?

Remote and hybrid work change the context in which employees verify identity.

A worker at home may join a meeting from a personal device, receive an urgent text while traveling, or lack the nearby colleague who would normally question a strange request.

Vacations and distributed teams also create handoff gaps, making claims such as covering for the CFO or the usual approver being unavailable sound plausible.

Cyberattackers exploit those gaps with multi-channel sequences. An email starts an invoice request, a text confirms the urgency, a vishing call supplies reassurance, and a fake video meeting provides apparent executive approval.

Distracted employees are not careless employees. They are people operating with incomplete context under time pressure.

Give employees a clear pause-and-verify rule, require independent approval for payment or bank-detail changes, and make reporting suspicious messages quick and consequence-free.

Map those controls to the finance employees who handle approvals, accounts, and vendor relationships, because those access points determine how a convincing request becomes a costly transfer.

How Can an Organization Identify Its Highest-Risk BEC Targets?

To identify who is targeted by business email compromise (BEC), map the people who can authorize payments, access sensitive information, influence business relationships, or appear trustworthy to outsiders.

Rank those employees using role, authority, exposure, behavior, and current business context.

Assign controls such as stronger verification, targeted microlearning, executive protocols, or multi-channel simulations, and treat the register as a way to build employee skills instead of assigning blame.

Who is targeted by BEC risk mapping as a security team ranks high-risk payment and access roles.

1. Map Roles, Authority, and Access

Start with business processes ahead of job titles. A BEC risk register should show who can create, approve, change, or release a transaction, even when that person works outside accounting or treasury.

The FBI’s 2025 IC3 Annual Report identifies businesses and people who work with suppliers or regularly perform wire transfers as common BEC targets, making transaction authority a more useful signal than department labels.

Map each employee against four questions:

  • Can this person approve, initiate, or release a payment?
  • Can this person change vendor banking details or customer account information?
  • Can this person access payroll, invoices, contracts, tax records, or acquisition information?
  • Can this person influence someone who controls money or sensitive data?

Include executive assistants, project managers, procurement staff, sales leaders, HR specialists, legal teams, office managers, and operations personnel.

A project manager who approves construction invoices, an HR director who manages payroll changes, or an executive assistant who schedules urgent wire transfers can face the same BEC pressure as a controller.

Separate authority from access. A person who cannot send money can still provide a cybercriminal with an invoice number, vendor name, payment schedule, executive travel details, or internal approval language.

That information can make a later request credible. Assign a higher tier when authority and sensitive access overlap, while maintaining a separate tier for employees who provide valuable business context.

Public-facing roles require another review. Executives, sales leaders, recruiters, investor-relations staff, attorneys, and spokespersons often publish names, responsibilities, travel schedules, conference appearances, and contact details.

That material gives cyberattackers open-source intelligence (OSINT) for personalized spear phishing, vishing, and executive impersonation. Record what a criminal can learn about each role. The register maps exposure, and it should never read as a record of employee mistakes.

A practical human risk management framework can turn this mapping into a living register.

Review it when someone changes roles, receives new approval authority, joins a strategic project, becomes publicly visible, or gains access to a new financial or data system.

2. Add Exposure and Behavior Signals

Role mapping identifies who is attractive to a cyberattacker. Exposure and behavior signals show who is easiest to reach and which defenses require reinforcement.

Build the register around observable conditions, with a clear safeguard attached to every elevated signal.

Public exposure includes executive profiles, published email addresses, conference videos, podcasts, social media posts, press coverage, organizational charts, and references to vendors or customers.

Visibility is never misconduct. Public visibility often supports legitimate business goals, so the appropriate response is exposure-aware preparation in place of forced concealment.

Provide executives and public-facing teams with impersonation protocols, verified contact paths, and short training on voice, video, and email manipulation.

Behavioral signals should include simulation outcomes, reporting activity, verification behavior, and training engagement.

A missed phishing simulation is never a permanent risk label. It is a prompt to examine the scenario, timing, channel, and decision pressure.

An employee who reports suspicious messages quickly and follows an out-of-band verification process demonstrates protective behavior even when a message initially looked convincing.

Track signals such as:

  • Clicking or replying to a simulated BEC request
  • Failing to verify a payment change through a trusted channel
  • Reporting suspicious messages quickly and accurately
  • Completing targeted microlearning after a simulation
  • Repeated exposure to email, voice, SMS, or deepfake scenarios
  • Using personal contact details in public business profiles
  • Recent credential exposure or account recovery activity, where lawful and appropriate to monitor

Current business context can raise risk faster than any static score.

Increase review priority during acquisitions, layoffs, executive departures, product launches, tax deadlines, payroll cycles, vendor migrations, major capital purchases, mergers, international expansion, and periods when finance staff are absent.

Cybercriminals do not need a permanently high-risk employee. They need a trusted person at the right moment.

Tie each signal to an action so a score never stands alone. A payment approver who fails an invoice simulation should receive a short, scenario-specific lesson and a second simulation through a different channel.

An executive whose voice and video are widely available should follow a documented callback protocol. A newly promoted manager should receive training before gaining approval rights.

An employee who reports suspicious messages should receive positive feedback and remain part of the organization’s defensive network.

3. Build a Practical High-Risk Target Matrix

Use a three-tier model that security, finance, HR, and business leaders can understand. Keep the model focused on exposure and required controls, and avoid attaching labels to employees.

Review scores monthly for high-impact teams and whenever business context changes.

Risk Tier Typical Target Profile Signals That Raise Priority Required Action
Tier 1: Critical transaction risk CFO, controller, treasury staff, procurement approver, executive assistant, or nonfinance payment owner Payment authority, vendor-change access, public executive relationship, failed BEC or vishing simulation, active transaction event Require dual approval, independent callback, verified vendor records, and executive-specific protocols. Run email, voice, and SMS simulations.
Tier 2: Sensitive relationship risk Sales leader, account manager, attorney, HR or payroll staff, IT administrator, recruiter, or project manager Access to contracts, payroll, credentials, customer data, public exposure, frequent external communication, elevated business activity Assign targeted microlearning, role-based spear-phishing simulations, reporting practice, and mandatory verification for sensitive requests.
Tier 3: Contextual support risk Employees who know project details, travel schedules, internal terminology, or vendor contacts Involvement in an acquisition, new vendor, executive transition, remote-work change, or unusual access request Provide focused briefings, reinforce reporting routes, and include the group in relevant simulations during the event.

Payment approvers outside finance need explicit protection because they often lack treasury training while still holding authority.

Publish a short rule stating that no email, text, voice call, or video meeting alone authorizes a payment or bank-detail change.

Require the approver to use a known phone number or established system record, contact a second authorized person, and pause when a request combines urgency, secrecy, executive pressure, or changed instructions.

Make the protocol easy to follow under pressure. A finance policy buried in a handbook will not protect a facilities manager approving a supplier invoice at 4:55 p.m.

Place callback steps in the procurement workflow, approval interface, and team communications. Practice them with realistic requests so verification becomes a normal part of completing the transaction.

For small businesses, the same method works with fewer people and less tooling. Create a spreadsheet with five columns: employee or role, payment and data authority, external exposure, current business context, and required control.

Mark the owner, bookkeeper, office manager, payroll contact, sales lead, and anyone who can instruct a bank or vendor. If one person performs several duties, raise the priority and separate initiation from approval wherever possible.

Small businesses should use compensating controls when staffing prevents full separation of duties.

The owner can confirm payment changes by calling a known number, the bookkeeper can require a second approval for new beneficiaries, and the team can maintain a single verified vendor directory.

A 15-minute monthly review can identify role changes, unusual transactions, public exposure, and recent simulation or reporting patterns without requiring a dedicated human-risk analyst.

4. Reassess the Register After Every Meaningful Change

A risk register becomes useful when it changes with the business. Recheck it after promotions, departures, acquisitions, new banking relationships, system migrations, public announcements, and suspicious events.

An annual training cycle arrives too late to protect a newly appointed executive or a temporary payment approver.

Measure whether controls produce safer decisions. Track verification completion, time to report, accuracy of reported messages, simulation performance by channel, and the number of high-risk roles covered by current protocols.

A rising risk score should trigger help and practice. A falling score should show that the assigned control is working, while continued exposure still warrants periodic rehearsal.

This approach keeps employees at the center of BEC defense. The objective is to identify situations where trusted employees need clearer authority boundaries, better verification habits, and practice recognizing pressure before a request reaches the payment workflow.

Finance teams face the greatest direct exposure when those pressures converge with transaction authority.

How Can Organizations Protect the Roles Targeted by BEC?

Business email compromise (BEC) targets employees based on access, authority, and timing, so protection must follow the role instead of relying on generic annual training.

Map payment, payroll, vendor, executive, HR, and IT workflows, then assign verification rules, approval limits, and reporting routes to each group. Knowing who is targeted by BEC turns those workflows into a defensible control set.

No urgent request should bypass an established process because it appears to come from a trusted person. A structured approach to preventing business email compromise starts there.

1. Build Process Controls Around High-Impact Requests

Payment and payroll changes require out-of-band verification using a trusted phone number or contact record. Details supplied in a suspicious email can never serve that purpose.

Require dual approval for new beneficiaries, bank account changes, wire transfers, payroll updates, and expedited invoices.

A callback procedure should confirm the request with the original vendor or employee through independently sourced contact details, while finance systems preserve approval records for review.

Vendor onboarding requires the same discipline. Confirm new suppliers through procurement, validate domain changes, and independently verify tax, banking, and ownership information before the first payment.

Executive travel protocols should prevent cybercriminals from exploiting urgency or assumed unavailability. If a leader requests a transfer while traveling, staff should use a prearranged verification channel and follow the same approval threshold as any other request.

Controls should scale without becoming impractical. Small businesses can use a shared payment-change checklist, a named secondary approver, and printed emergency contacts.

Mid-market organizations should separate vendor setup from payment release, enforce role-based access, and monitor mailbox forwarding rules.

Enterprises need centralized policy enforcement, treasury workflow controls, privileged-access reviews, and automated alerts for suspicious forwarding, inbox delegation, or authentication changes.

2. Train Each Target Group Across the Channels Attackers Use

Role-based training turns employees into active verification points. Finance teams should practice BEC and spear phishing simulations involving invoice changes, fake vendor domains, and urgent wire requests.

HR teams need exercises involving payroll redirection, tax forms, benefits data, and employee records. IT staff should rehearse MFA reset requests, privileged-account recovery, and suspicious mailbox-rule changes, while executives practice declining urgent requests until a second channel confirms them.

Email is only one route. A modern program should include vishing simulations for finance and executive assistants, smishing simulations for mobile-dependent teams, and deepfake awareness training for leaders whose voices, images, or travel schedules appear online.

AI-generated phishing simulations should combine open-source intelligence (OSINT) with realistic pressure, such as a voice message followed by a text and an email repeating the same fraudulent instruction.

Adaptive Security’s phishing simulations support role-specific exercises across email, voice, SMS, and deepfake video, so every employee practices the scenarios that match their actual authority.

Real cases show why multi-channel rehearsal matters. The Arup deepfake video call described earlier persuaded a finance employee to release funds, and an AI impersonator posing as Ukraine’s former foreign minister reached a sitting U.S. senator.

These incidents show why employees must verify identity and intent. Recognizing suspicious spelling or logos no longer covers the risk.

Every group also needs MFA, and MFA must support verification without replacing it. Train employees to reject unexpected prompts, report repeated authentication requests, and use phishing-resistant methods for privileged and financial accounts.

Provide one visible reporting route, such as a report-phishing button, security hotline, or dedicated mailbox, and explain what happens after a report. Fast, blame-free reporting produces earlier signals.

3. Contain and Investigate Suspected BEC Attempts

A suspected BEC attempt requires immediate containment. Debating whether the message looks real wastes the time that recovery depends on.

Employees should stop replying, avoid clicking additional links, report the message, preserve the conversation, and notify finance, security, or management according to a published escalation path.

Finance should contact the bank immediately for payment recall or account review, while IT checks sign-in history, mailbox rules, forwarding addresses, delegated access, MFA changes, and newly created inbox filters.

Incident responders should determine whether the cyberattacker attempted only impersonation or also obtained credentials.

Reset affected credentials, revoke active sessions, remove unauthorized rules, and review related accounts, vendors, and executives for similar activity. If payroll or personal data was exposed, involve legal, HR, and privacy teams quickly.

After containment, convert the incident into a targeted simulation and update the relevant approval or callback procedure.

Small businesses can assign one incident owner and maintain a bank, insurer, and law enforcement contact sheet.

Mid-market organizations should connect finance, HR, and IT through a documented playbook with response-time targets. Enterprises should use centralized logging, automated mailbox-rule alerts, privileged-access monitoring, and regional escalation teams.

In every organization the objective stays the same: make safe verification easier than rushed compliance, then use each reported attempt to strengthen the signals employees rely on under pressure.

How Can Organizations Measure BEC Resilience?

Organizations measure business email compromise (BEC) resilience by tracking decisions, reporting behavior, and control adherence. Training completion alone reveals very little.

Federal fraud reporting consistently identifies businesses and people who work with suppliers or regularly perform wire transfers as primary BEC targets, which makes role-specific testing essential.

A complete scorecard shows whether employees recognize pressure, verify payment changes, and report suspicious activity before money or data moves. Understanding who is targeted by BEC determines which roles that scorecard must cover.

Which Leading Indicators Show BEC Resilience?

Leading indicators reveal whether employees are building useful habits before an incident produces financial loss.

Track simulation susceptibility by role and department, reporting rate, median time to report, repeat-failure rate, and movement in individual or team risk scores.

An employee who stops clicking but never reports a suspicious invoice still leaves the organization exposed, because the security team loses the time it needs to investigate and contain the attempt.

Measure payment-change verification separately from general phishing performance.

Record whether the employee used an approved second channel, contacted a known vendor number instead of a number in the message, and obtained required approval before changing bank details.

This distinction shows whether written controls hold under urgency, authority pressure, and realistic workload.

Monitor coverage for high-risk roles, including executives, finance, HR, IT administrators, procurement staff, executive assistants, vendors, and nonfinance payment approvers.

Coverage should include active testing, recent training, remediation status, and risk-score movement. Employees who fail a scenario should receive targeted coaching and another opportunity to practice, without public blame or punitive labeling.

How Should Organizations Design Ethical BEC Simulations?

Simulation design should mirror cyberattacker methods while protecting employees from unnecessary embarrassment.

Test email, voice, SMS, QR phishing, and deepfake video scenarios around the same business request. A vendor bank-detail change can begin with an email, continue through a voice message from a supposed finance leader, and end with a QR code directing the employee to a payment portal.

Use role-specific objectives in place of identical tests for everyone. Executives should practice resisting urgent requests that appear to come from the CEO or board.

Finance and procurement teams should verify invoices, account changes, and payment exceptions. HR should handle payroll-change requests and employee-record requests.

IT should challenge credential resets and privileged-access requests. Vendors and nonfinance approvers should follow documented escalation paths before releasing funds.

Set ethical boundaries before launch:

  • Do not use real credentials, payment accounts, or confidential data.
  • Do not simulate termination, medical emergencies, or personal crises.
  • Restrict individual results to authorized managers and provide immediate feedback after a failure.
  • Use synthetic personas or approved recordings for deepfake and voice scenarios.
  • Give employees a clear escalation channel if a scenario causes concern.

Adaptive Security’s Phishing Simulations support multi-channel exercises that test email, voice, SMS, and deepfake recognition as connected behaviors instead of isolated compliance events.

What Belongs in Board-Ready BEC Reporting?

Board reporting should separate four categories so improvement remains visible and investment decisions are defensible.

  1. Exposure: Show the number and percentage of employees in high-risk roles, uncovered vendors, exposed executives, and departments with elevated risk signals.
  2. Behavior: Report susceptibility, reporting rate, time to report, and repeat-failure rate by department and role. Use quarterly trends in place of ranking individual employees.
  3. Control adoption: Show payment-change verification, second-channel verification, approval completion, and escalation usage.
  4. Business impact: Connect the program to remediation time, interrupted payment attempts, analyst hours saved, and unresolved high-risk cases.

Use medians and distributions when outliers could distort the picture. A high reporting rate is insufficient if payment approvers remain under-tested or bypass verification controls.

Pair every metric with an action, such as expanding finance coverage, assigning targeted coaching, or tightening approval workflows.

The strongest board narrative stays direct: exposure is falling, behavior is improving, controls are being followed, and response is becoming faster.

That view makes the remaining high-consequence roles visible, especially where payment authority and trusted relationships converge.

Why BEC Target Identification Belongs in an Information Security Awareness Program

Business email compromise (BEC) targets change as an organization’s people, responsibilities, access, and public exposure change.

An information security awareness program that relies on static annual training cannot show which employees currently approve payments, communicate with vendors, control sensitive data, or appear in executive impersonation material.

Answering who is targeted by BEC on a continuous basis makes human decisions an active risk signal instead of a completed training task. Mature email security awareness programs carry that work forward.

From Static Training to Continuous Risk Signals

Continuous BEC defense starts by identifying exposure where cybercriminals operate.

Finance staff with payment authority, executive assistants who manage calendars, procurement teams handling vendor changes, and leaders with publicly available voice or video content face different social-engineering paths.

Role, access, and external exposure determine which scenarios employees should rehearse.

Open-source intelligence (OSINT) adds another layer. Public job titles, conference appearances, organizational charts, social profiles, and exposed contact details can reveal whom a cyberattacker would impersonate and which employee is likely to trust the request.

OSINT-informed risk assessment does not label employees as liabilities. It gives security leaders a defensible way to prioritize coaching, reduce unnecessary exposure, and test the behaviors that matter most.

Behavioral signals complete the picture. A useful human-risk program tracks whether an employee reports a suspicious invoice, verifies an urgent payment through a separate channel, enters credentials into a simulated phishing page, or rejects a voice request that conflicts with policy.

Training completion proves only that content was opened. Behavioral change shows whether a person recognized pressure, challenged authority, and followed the correct process.

This approach connects BEC exposure to human risk management without replacing technical controls. Email authentication, identity protections, payment approvals, and access restrictions remain essential.

Human-risk visibility answers a different question: when a convincing message reaches a trusted employee, how likely is that person to pause, verify, and report?

Adapting to AI-Enabled Impersonation

AI-enabled social engineering expands BEC beyond email. Cyberattackers can combine a personalized spear phishing message with vishing, smishing, or a deepfake video call, creating several apparent confirmations for one fraudulent request.

The Arup transfer and the Cardin impersonation described earlier followed that pattern. Both show why visual and vocal familiarity cannot serve as proof of identity, and why deepfake phishing now demands its own verification step.

Employees do not need to become forensic analysts. They need a repeatable verification behavior.

When a request changes payment instructions, demands secrecy, or creates unusual urgency, employees should stop and confirm it through a known channel.

Personalized cybersecurity awareness training makes that behavior credible because employees practice decisions tied to their roles.

Finance teams rehearse invoice and account-change requests. Executives practice responding when their identity is used to pressure staff. Administrative teams question calendar invitations, document-sharing requests, and last-minute travel or payment demands.

Multi-channel phishing awareness training applies the same verification rule across email, text, phone, and video.

Integrating BEC Resilience Into an Information Security Awareness Program

BEC resilience belongs inside an information security awareness program, and a separate annual module cannot carry it.

A durable program establishes baseline exposure, delivers short role-specific lessons, runs realistic simulations across relevant channels, and measures reporting and verification behavior over time.

When an employee misses a test, the result should trigger targeted skill-building and a clear explanation of the decision point, without public blame.

The program also needs governance. Security leaders should report human-risk trends to the board in business terms, including departments with elevated payment exposure, the percentage of high-risk requests independently verified, reporting speed, repeat behavior, and changes in executive impersonation exposure.

Those measures show whether investment is reducing decision risk, and completion rates alone cannot answer that question.

NIST’s 2024 Advancing Human-Centered Cybersecurity workshop report centers cybersecurity on human needs, behavior, and context.

Applied to BEC, that principle produces a practical operating model. Technical controls block known cyberthreats, while trained employees interrupt deception delivered through trusted channels.

Continuous identification of BEC targets turns the human layer into a measurable defense and clarifies which finance and executive-facing roles require the most focused rehearsal.

Business Email Compromise Target FAQs

Who Is Targeted by BEC Most Often?

Who is targeted by BEC most often comes down to payment authority. Business email compromise most often reaches employees who can authorize payments, change account details, or access trusted business relationships.

The FBI’s BEC guidance identifies businesses, employees working with suppliers, and organizations that regularly perform wire transfers as common targets.

That makes accounts payable, treasury, procurement, payroll, executives, executive assistants, and nonfinance payment approvers important protection priorities. Cybercriminals also pursue HR and IT staff when their access exposes sensitive records or account controls.

Focus protection on authority and access ahead of job title. Map who can move money, alter payment instructions, release data, or influence a trusted transaction, and give those employees role-specific practice across the channels they use.

Are Small Businesses Common Targets of BEC Attacks?

Yes. Small businesses are common BEC targets because cybercriminals can pursue payment authority, supplier relationships, and sensitive information in organizations of any size.

Smaller teams often concentrate payment, payroll, and administrative authority in fewer people, which makes role-based safeguards essential.

Use a trusted callback process, dual approval for payment changes, multifactor authentication, and a clear reporting route. A small business can apply the same risk method as an enterprise by prioritizing authority, access, and relationship exposure.

What Makes an Employee a High-Risk BEC Target?

An employee is a high-risk BEC target when the role combines payment authority, sensitive-data access, trusted relationships, public exposure, or the ability to bypass verification.

The FBI describes BEC as targeting businesses and people involved in supplier relationships or wire transfers, so risk assessment should examine what a person can approve, change, release, or influence.

Review finance, payroll, HR, executive operations, procurement, IT administration, and nonfinance payment approvers. Add current context such as travel, a merger, a major transaction, or a public contact profile.

Treat simulation outcomes and reporting behavior as coaching signals. Pair each risk signal with stronger verification, targeted training, or multi-channel practice.

Can BEC Attacks Target Employees Through Voice Cloning or Fake Video Meetings?

Yes. BEC attacks can use voice cloning, synthetic video, vishing, and fake video meetings to impersonate executives, vendors, or colleagues.

In December 2024, the FBI warned that criminals were using generative AI and AI-generated audio to impersonate trusted people and solicit money. A familiar voice or face is never payment verification.

Require employees to confirm unusual requests through a known phone number or separate channel, especially when a request changes bank details, demands secrecy, or creates urgency.

Train high-authority roles with realistic email, voice, SMS, and video scenarios. Employees remain the strongest line of defense when policy gives them permission to pause and verify.

How Much Money Do Businesses Lose to Business Email Compromise Each Year?

The FBI’s Internet Crime Complaint Center recorded roughly $3.04 billion in reported BEC losses in its 2025 IC3 Annual Report.

That report records complaints and adjusted losses, so the figure does not represent every global loss or every attempted fraud.

The FBI’s separate 2024 BEC alert reported more than $20.08 billion in exposed U.S. losses accumulated across its covered period, showing why annual totals should be read alongside cumulative data.

Organizations can reduce exposure by identifying payment authority, enforcing independent verification, and measuring reporting behavior. A clear view of each role’s exposure turns that financial cyberthreat into a practical protection plan.

Assess High-Risk BEC Roles and Build Multi-Channel Resilience

BEC exploits trusted relationships, payment authority, and familiar communication channels to turn one urgent request into financial or data loss.

Assessing role-specific exposure and practicing across email, voice, SMS, and deepfake scenarios gives employees clearer decisions and stronger reporting habits. Knowing who is targeted by BEC is where that work begins.

Take a self-guided tour of multi-channel phishing simulations.

Adaptive Team

Adaptive Team

As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.

Get started with Adaptive Security

Human and agent security for the AI era.