TL;DR: Business email compromise caused over $3 billion in reported losses in 2025, and attackers increasingly rely on executive impersonation, vendor spoofing, and conversation hijacking rather than malware, according to the FBI and Abnormal AI. Legacy secure email gateways are being outmaneuvered by identity-driven attacks that require behavioral context, not just payload scanning.
At a glance
What this is: This webinar argues that business email compromise is outpacing legacy email controls because attackers now rely on identity and conversation manipulation rather than obvious malicious payloads.
Why it matters: It matters because IAM, security operations, and email security teams need detection that understands sender identity, behavioral context, and trusted communication patterns, not just domains and attachments.
Context
Business email compromise has become an identity problem as much as an email problem. The core gap is that many controls still evaluate messages by indicators of malicious content, while modern attackers increasingly operate through impersonation and social engineering that looks normal in transit.
For identity and access teams, that changes the detection model. If a control cannot distinguish routine communication from compromised trust relationships, it will miss the attacks that matter most in finance, procurement, and executive workflows.
Key questions
Q: Why do legacy SEG controls miss business email compromise in distributed organisations?
A: Legacy SEG controls are often tuned to content, reputation, and perimeter filtering, but BEC frequently uses legitimate-looking communication and trusted relationships. In distributed organisations, that creates a gap between what the gateway can see and how attackers actually abuse trust. When the ecosystem is large, the filter is not enough.
Q: Why do business email compromise attacks create more financial risk than generic phishing?
A: BEC creates more financial risk because the attacker’s goal is usually direct monetary loss, not just credential theft. The email is often personalized, tied to real business context, and designed to trigger wire transfers, payroll diversion, or changes to payment details. That combination makes BEC harder to dismiss and more likely to succeed when controls and approvals are weak.
Q: What are the signs that email-based impersonation is getting through detection?
A: Look for requests that deviate from normal thread behaviour, unusual urgency, changes in bank details, or messages that appear to fit the conversation but subtly alter the expected process. Those are signs that the control is detecting content but missing identity manipulation and context drift.
Q: How should organisations verify high-risk requests that arrive by email?
A: Use an independent confirmation step outside the email thread for payments, vendor changes, payroll updates, and other high-impact actions. Verification should check the requester through a separate trusted channel and confirm the business event before any action is taken.
Background and context
Why payload scanning misses modern business email compromise
Legacy secure email gateways were designed to inspect messages for known-bad domains, attachments, and payload indicators. That works when the attack depends on malware or links, but it breaks when the adversary uses legitimate-looking content and a believable sender pattern. Modern BEC abuses trust rather than code, so the message itself can be clean while the intent is malicious. The control failure is not just false negatives, but the wrong detection model: content-only inspection cannot reason over identity, relationship history, or communication cadence.
Practical implication: treat content filtering as one layer, not the detection strategy for BEC.
Behavioral baselines for sender identity and conversation context
Behavioral detection looks at how communication normally occurs across people, domains, and business relationships. That includes who usually emails whom, when vendor requests arrive, how reply chains evolve, and whether language or routing patterns deviate from established norms. For BEC, this is useful because the adversary often blends into existing workflows rather than forcing a new one. The baseline does not need to prove every message is malicious; it only needs to identify when the communication context no longer matches ordinary business behavior.
Practical implication: build baselines around relationships, not just message headers and content signatures.
Why human trust abuse is now the primary attack surface
BEC is less about email delivery mechanics and more about exploiting decision-making in human workflows. The attacker succeeds when a trusted identity, such as an executive or supplier, persuades the recipient to bypass verification. That makes the attack adjacent to IAM, because the protected asset is the trust decision itself. Once an email channel becomes a proxy for authority, email security controls must account for identity signals, not simply spam-like characteristics. The vulnerability is social legitimacy, not just technical delivery.
Practical implication: align email security with identity verification steps in payment, payroll, and vendor-change processes.
NHI Mgmt Group analysis
Business email compromise is now a trust-manipulation problem, not a spam problem. The article shows attackers succeeding without malware by impersonating executives and vendors inside normal business threads. That means the decisive control is not message blocking alone, but the ability to verify whether the communication context matches expected authority. Practitioners should treat trust validation as part of the email security stack.
Legacy secure email gateways encode the wrong security assumption. They assume malicious email can be detected through payloads, suspicious domains, or attachments. That assumption fails when the attacker uses legitimate-looking conversation flows and socially credible identities. The implication is that email governance must move from content inspection to relationship-aware detection and verification.
Identity context is the missing detection layer in email security. BEC exploits who appears to be speaking, not just what is being said. This is why the article’s emphasis on behavioral baselines matters: defenders need signals tied to sender history, thread behavior, and business norms. Practitioners should measure email risk by trust deviation, not only by known-bad indicators.
Identity blast radius: BEC expands as soon as communication channels are treated as authority channels. Once a mailbox can persuade people to move money or alter vendor data, the identity problem extends beyond authentication into operational trust. That creates a governance issue across finance, procurement, and executive assistants. The practical conclusion is that email controls must be joined to business-process verification.
Behavioural AI is becoming a compensating control for weak human verification paths. The article indicates that legacy controls cannot distinguish legitimate from fraudulent conversation patterns on their own. That does not make AI the answer by itself, but it does signal that detection must interpret behaviour at runtime. Practitioners should evaluate where human approval steps still rely on unaudited email trust.
What this signals
Email security teams should stop treating business email compromise as a content-filtering problem. The attack succeeds when identity, authority, and workflow context all look believable at the same time, which is why verification has to move closer to the business action itself.
Identity-aware email control: the useful boundary is no longer whether a message is malicious in isolation, but whether it is consistent with how trusted business communication normally behaves. Practitioners should watch for request patterns that are valid linguistically but invalid procedurally.
For practitioners
- Harden vendor-change verification Require a second channel for bank detail changes, payment requests, and payroll updates so email cannot by itself authorise financial action.
- Baseline normal communication patterns Map typical sender-recipient relationships, thread cadence, and request types for finance and executive workflows to create a usable trust baseline.
- Add identity signals to email detection Prioritise sender reputation, relationship history, and conversation continuity alongside domain and attachment checks in the detection pipeline.
- Train approvers on impersonation patterns Focus user training on executive spoofing, vendor spoofing, and thread hijacking so staff can spot authority abuse rather than only malware indicators.
Key takeaways
- Business email compromise now succeeds by abusing trust relationships and normal business communication, not by depending on malware alone.
- Legacy secure email gateways are weak against attacks that look legitimate in content but fraudulent in intent, which leaves a gap in identity-aware detection.
- Practitioners should pair behavioural baselines with out-of-band verification for high-risk requests, especially in finance and vendor workflows.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001;TA0006;TA0040 — Initial Access; Credential Access; Impact | BEC uses impersonation and trust abuse to reach payment and data impact. |
| Recommendation — Map BEC playbooks to initial access, credential access, and impact patterns in detection content. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Email-driven authority abuse turns authorization into the key control boundary. |
| Recommendation — Tie high-risk email actions to authorization checks outside the inbox before approval. | ||
| CIS Controls v8 | CIS-5 — Account Management | BEC often targets account-change and payment workflows that depend on trust in identity claims. |
| Recommendation — Strengthen account-change verification around finance and vendor workflows. | ||
Key terms
- Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
- Behavior Baseline: A record of normal activity for a non-human identity, including typical consumers, resources, and actions over time. Baselines help security teams detect when an identity is being used in an unusual way and provide the context needed to enforce least privilege safely in dynamic environments.
- Conversation Hijacking: Conversation hijacking is the insertion of a fraudulent actor into an existing email thread so the request appears to continue a legitimate discussion. The attacker relies on prior message history, familiar tone, and trusted recipients to bypass human suspicion and complete the fraud path.
- Identity-aware detection: Identity-aware detection is security monitoring that evaluates alerts using identity context such as target role, privilege level, authentication state, and account type. It improves triage because the same suspicious action has different meaning depending on whether it involves a human user, service account, or machine credential.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org