Common signs include unusual payment instructions, sudden changes in bank details, messages that pressure staff to bypass normal approval steps, and login or mailbox activity that does not match the user’s normal pattern. Security teams should also watch for compromised accounts sending convincing internal emails, since business email compromise often depends on trusted relationships to move money or sensitive data.
How to Tell a BEC Campaign Is Working
When business email compromise is succeeding, the first sign is usually that the attacker is changing behaviour around money, approvals, or trust. The campaign is no longer just a login attempt or spoofed message, it is influencing real decisions, steering staff away from normal checks, and creating an opening for payment diversion or data exposure.
Look for the moment the attacker starts getting responses that validate the fraud path. That can include staff replying to a fake executive request, finance teams accepting revised bank details, or an account holder continuing a conversation after the attacker has gained enough trust to keep the thread alive.
Behavioural and Account Activity Signals
Successful BEC often leaves traces in mailbox and identity activity before the final loss occurs. A logon from an unfamiliar location, a mailbox rule that hides replies, a sudden forwarding change, or access at unusual hours can show that an attacker is actively using the account rather than merely probing it. The 52 NHI Breaches Report is useful background on how compromised credentials and lateral movement often appear before broader abuse becomes visible.
Another warning sign is communication style drift. If a trusted sender begins pressing urgency, asking for secrecy, or avoiding the usual approval chain, that is often a sign the attacker is trying to convert access into action. The compromise is more convincing when the message thread uses the right names, tone, and timing, so teams should treat unusually persuasive internal email as a control failure, not just a phishing nuisance.
Payment Diversion and Trust Abuse Patterns
The clearest business signal is a payment process that starts to bend. New bank details, last-minute beneficiary changes, invoice edits, or requests to bypass dual approval are all signs that the campaign is succeeding at its real objective: making a legitimate workflow accept fraudulent instructions. TruffleNet BEC Attack, Stolen AWS Credentials shows how stolen credentials can support that kind of downstream abuse.
At the same time, do not narrow the lens to payment only. BEC campaigns often aim at payroll, vendor records, gift-card requests, or sensitive document extraction. If the attacker is getting timely replies, account resets, or confidential files, the campaign is already succeeding even if no funds have moved yet. That is usually the point where incident response should begin treating the case as active fraud, not just suspicious email.
Risk and Threat Considerations
Successful BEC is dangerous because it exploits trust relationships that normal controls often assume are safe. Once an attacker can steer an employee into approving a transfer, changing banking details, or sharing information, the fraud can progress without malware, noisy exploitation, or obvious technical disruption.
Failure mechanism: The attacker gains enough credibility through spoofing, mailbox compromise, or executive impersonation to override usual verification steps and move the victim into an unprotected workflow.
Impact: Funds can be diverted, sensitive records can be exposed, and the compromise can spread through internal trust channels before anyone realises the email thread is malicious.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1566 — Phishing | BEC commonly starts with deceptive email to obtain trust or access. |
| T1078 — Valid Accounts | Account compromise and stolen credentials are a common BEC success condition. | |
| Recommendation — Map suspicious email patterns to T1566 and increase verification on external sender interactions. Hunt for valid-account misuse and review mailbox sign-ins from unusual locations or times. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Mailbox and payment anomalies are detected through log review and analysis. |
| IA-5 — Authenticator Management | Compromised credentials often underpin successful BEC campaigns. | |
| Recommendation — Correlate authentication, mailbox-rule, and payment-change logs for suspicious activity. Rotate exposed credentials and enforce strong authenticator lifecycle controls. | ||
| CIS Controls v8 | CIS-5 — Account Management | BEC depends on abused accounts, forwarding changes, and weak approval ownership. |
| Recommendation — Review account ownership, forwarding rules, and privileged access on a fixed cadence. | ||
Practitioner Guidance
What to verify: Treat any payment change, urgent exception, or “same-day” instruction as untrusted until confirmed through an out-of-band channel that is already established and independently known. The key test is whether the request would still stand if the email thread disappeared.
What to prioritise: Finance, accounts payable, and executive support teams should be the first lines of defence because they are the most common pressure points. If a suspected BEC message also involves mailbox takeover, rotate credentials and review inbox rules before debating whether the request itself was authentic.
Practitioner takeaway: BEC is succeeding when it stops looking like an email problem and starts changing business behaviour. The most useful indicator is not just that a message arrived, but that someone acted on it without the normal verification path.
Related resources from NHI Mgmt Group
- What are the signs that a credential phishing campaign is being used as a precursor to business email compromise?
- What are the signs that supplier account compromise is being used to drive business email compromise?
- What are the signs that a business email compromise attempt is likely to be fraudulent?
- What are the signs that security awareness training is not enough to stop business email compromise?