Business email compromise, or BEC, doesn't involve malware, ransomware, or breaking into a network. It's simpler than that, and precisely because it's simple, it's consistently one of the costliest categories of cybercrime by total dollars lost — because the "attack" is just a convincing email arriving at exactly the right moment.
How it actually plays out
The classic version: an attacker either compromises or closely spoofs an executive's email account, then emails someone in finance or accounts payable with an urgent, plausible request — a wire transfer to close a deal, payment to a "new" vendor, or a change to an existing vendor's payment details. The tone matches how that executive actually writes, the timing often coincides with the executive being genuinely unreachable (traveling, in back-to-back meetings), and the request is framed as confidential or time-sensitive enough to discourage double-checking through normal channels.
The controls that actually stop it
If you suspect a BEC attempt has succeeded
Contact your bank immediately — wire transfers can sometimes be recalled or frozen within a narrow window if reported fast enough. File a report with your national fraud or cybercrime reporting authority, since coordinated law enforcement action has recovered funds in some cases. Then review how the request bypassed your process, and close that specific gap.
The takeaway
BEC succeeds by exploiting process, not technology — which means the fix is also procedural, not technical. A callback requirement for any payment change, enforced without exception regardless of who's asking or how urgent it sounds, closes the gap this entire scam depends on.