Join our Newsletter — 33% off our NHI Course

Why does business email compromise keep producing such large losses for enterprises?

BEC keeps producing large losses because attackers target people with access to money or sensitive data, then use urgency and impersonation to override normal caution. The FBI data also shows the average loss per attack remains high. When the fraud reaches the right employee at the right moment, a single mistake can create immediate financial damage.

Why BEC Produces Disproportionately Large Losses

business email compromise works because it attacks decision-making at the point of payment, data release, or approval. The fraud is usually low-noise, highly targeted, and timed to look routine. That means the attacker does not need broad access or a long dwell time to cause damage, only one believable message that reaches a person with authority.

The losses stay large because the scam often bypasses technical controls entirely. Instead of exploiting a system weakness first, the attacker exploits trust, urgency, and workflow gaps, then converts a single successful interaction into an immediate transfer, invoice change, or sensitive-data disclosure.

Why the Fraud Scales So Well Inside Enterprises

BEC scales because enterprises have many legitimate reasons for employees to move money, update payment instructions, or share sensitive records quickly. Those normal business processes create predictable windows where a convincing impersonation can fit in without appearing unusual. The larger and more distributed the organisation, the easier it is for a fraudster to find an exposed process with weak verification.

Impersonation is especially effective when approval chains are fragmented across email, chat, and finance systems. If the organisation relies on informal checks, reused wording, or a single person to validate a request, the attacker only has to mimic the expected style and timing. That is why small process weaknesses can produce outsized financial loss.

For teams that want a case-based view of how stolen credentials and account abuse can support this type of fraud, NHIMG’s The 52 NHI Breaches Report and TruffleNet BEC Attack, Stolen AWS Credentials show how credential abuse can extend the impact beyond a single inbox.

Why One Successful Message Can Trigger Major Financial Damage

The economics of BEC are asymmetric. The attacker’s cost is low, but the potential payout is high because the victim is often authorised to move funds or approve sensitive actions. Once a fraudulent request clears the first approval point, recovery gets harder because the transfer may already be in motion or the data may already have been disclosed.

Losses also increase when organisations lack friction on exceptional requests. If payment changes, vendor-bank updates, or urgent invoice approvals can happen outside normal verification paths, the attacker benefits from process exceptions rather than from technical stealth. In practice, the most expensive BEC cases are often the ones that fit just enough of the normal business pattern to avoid challenge.

Where a broader threat model is useful, MITRE ATT&CK helps teams map the supporting behaviours around credential access, impersonation, and follow-on movement, while MITRE ATT&CK Enterprise Matrix is a practical reference for that analysis. On the control side, NIST Cybersecurity Framework 2.0 remains useful for tying governance, detection, and response together when email fraud becomes a recurring business risk.

Risk and Threat Considerations

BEC is dangerous because it combines social engineering with business authority. The main exposure is not just a fraudulent email, but the fact that the email can trigger a real payment, credential reset, or disclosure before anyone confirms the request through a second trusted channel.

Failure mechanism: Attackers exploit urgency, impersonation, and weak out-of-band verification so a legitimate employee approves or executes an action that should have been challenged.

Impact: Organisations can lose money immediately, expose sensitive information, and face downstream recovery costs that exceed the original transfer.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1566 — Phishing BEC commonly begins with deceptive email delivery and impersonation.
T1078 — Valid Accounts BEC often abuses trusted accounts or impersonated identities to gain legitimacy.
Recommendation — Map suspicious email campaigns to T1566 and verify user-facing controls on payment and approval workflows. Hunt for valid-account abuse and tighten verification for any request that relies on trusted access.
CIS Controls v8 CIS-5 — Account Management Account and approval governance limits who can move money or disclose sensitive data.
Recommendation — Restrict and review who can approve high-risk business actions and payment changes.
NIST CSF 2.0 PR.AA-05 — Identity Management, Authentication, and Access Control BEC succeeds when requesters can bypass strong verification before action is taken.
DE.CM-03 — Personnel Activity is Monitored BEC detection improves when unusual approval or payment activity is monitored.
RS.CO-02 — Incidents are Reported Rapid reporting matters because BEC losses grow once payments leave the organisation.
Recommendation — Require strong identity verification before approving transfers or sensitive disclosures. Monitor for anomalous approval behavior and investigate unusual financial requests quickly. Escalate suspected BEC immediately so finance, security, and banks can act before settlement.

Practitioner Guidance

What to prioritise: Focus first on the workflows that can create irreversible loss, especially payment changes, vendor-bank updates, payroll changes, and executive requests. Those are the points where a single failed verification can become a large financial incident.

What to verify: Confirm that high-value requests require a second channel of validation that is difficult to spoof, and that employees know exactly when to pause rather than comply. If the process depends on recognising “suspicious tone” in an email, it is already too weak.

Practitioner takeaway: The most effective BEC control is not better email hygiene alone, but tighter verification around the business actions that convert a believable message into real financial or data loss.