Multilingual BEC is costly because it combines executive impersonation, social engineering, and payment diversion with no malware to trip traditional controls. Attackers can target finance and HR staff in local languages, making requests feel routine and legitimate. That combination increases response rates and lets fraudulent transfers proceed before teams notice the manipulation.
How multilingual BEC turns ordinary-looking requests into high-value fraud
Multilingual campaigns work because they narrow the gap between the attacker’s wording and the recipient’s day-to-day reality. When a message arrives in a local language and mirrors regional business etiquette, finance and HR staff are more likely to treat it as a routine exception rather than a security event. That lowers friction for payment diversion, payroll change, invoice substitution, and supplier-redirection schemes.
The risk is not just that the request looks believable, but that it arrives in a form that fits the organisation’s normal workflows. A well-timed request in the right language can bypass informal scepticism, especially when the sender appears to be an executive, a partner, or someone inside a familiar approval chain.
Why the lack of malware makes detection harder
Multilingual BEC is especially costly because it often leaves few technical indicators. There may be no malicious attachment, no payload to quarantine, and no obvious endpoint alert before the transfer is approved. That shifts detection away from malware scanning and toward behavioural, process, and verification controls.
In practice, this means traditional email security can miss the event even when the campaign is active and successful. The failure is often not in message delivery, but in the fact that the organisation’s verification model assumes authenticity based on tone, language, role, or urgency rather than on independently confirmed payment authority.
Why local-language targeting increases business impact
Attackers use local-language targeting to increase response rates and reduce the chance of immediate escalation. It also helps them tailor the fraud to regional payment practices, local management structure, and internal terminology, which makes the request harder to distinguish from legitimate business traffic. The more closely the message matches internal norms, the more likely it is to reach the point of no return before anyone questions it.
That is why the financial impact is often concentrated in accounts payable, treasury, payroll, and HR operations. Those teams handle frequent exceptions, urgent requests, and cross-border communication, which gives attackers multiple opportunities to blend in and exploit process shortcuts.
Risk and Threat Considerations
Multilingual BEC creates a compound risk: social engineering success is higher, review time is shorter, and the fraudulent instruction can cross language and function boundaries before suspicion rises. The threat is amplified when organisations rely on email text alone to authorise payments or changes to banking details.
Failure mechanism: Attackers exploit trust in language familiarity, role cues, and business urgency to bypass normal scepticism, then use that social trust to trigger an irreversible or hard-to-reverse financial action.
Impact: The result can be direct monetary loss, diverted payroll or vendor payments, downstream reconciliation work, and secondary exposure if the same impersonation path is reused against other teams or regions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and DORA and PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1566 — Phishing | BEC uses phishing-style social engineering to induce fraudulent action. |
| T1656 — Impersonation | Executive impersonation is central to BEC fraud and trust abuse. | |
| Recommendation — Map multilingual BEC lures to phishing detections and verify payment requests out of band. Hunt for impersonation patterns and challenge sender authority before approving transfers. | ||
| NIST SP 800-53 Rev 5 | AC-3 — Access Enforcement | Payment approval and banking changes need enforced authorization boundaries. |
| AU-6 — Audit Review, Analysis, and Reporting | Post-event review of BEC indicators depends on audit evidence and alert triage. | |
| Recommendation — Enforce separate approval controls for changes to payees and transfer instructions. Review payment and account-change logs for anomalies tied to multilingual fraud attempts. | ||
| CIS Controls v8 | CIS-9 — Email and Web Browser Protections | BEC campaigns commonly arrive through email and browser workflows. |
| Recommendation — Strengthen email protections and alerting for spoofed or high-risk business messages. | ||
| DORA | Article 9 — ICT Risk Management | Financial organisations must manage operational and communication-driven fraud risk. |
| Recommendation — Embed payment-fraud scenarios into ICT risk management and resilience testing. | ||
| PCI DSS v4.0 | 8 — Identify Users and Authenticate Access to System Components | Fraudulent payment changes often succeed where approval identity is weakly verified. |
| Recommendation — Require strong identity checks before authorising sensitive payment or account changes. | ||
Practitioner Guidance
What to verify: Treat any cross-border, multilingual, or urgency-driven payment change as untrusted until verified through a separate channel that is already established for that counterparty or executive. The key decision is not whether the message sounds plausible, but whether the instruction survives out-of-band confirmation and dual approval.
Decision rule: If the request changes payment destination, bank details, beneficiary identity, or payroll routing, require verification before processing, even when the sender language and tone match normal business communication. If the request also arrives under time pressure, escalate rather than accelerate the approval path.
Practitioner takeaway: The highest-value control is not better translation detection, it is making financial authority independent of email authenticity so that a convincing multilingual message cannot move money on its own.
Related resources from NHI Mgmt Group
- Why do negligence and carelessness create as much insider threat risk as malicious intent?
- Why do non-human identities create more risk than many human accounts?
- Why do non-human identities create more remediation risk than many human accounts?
- Why do DNS failures create identity security risk for financial organisations?