TL;DR: Business email compromise was absent from the FBI’s 2013 complaint report, became the second most financially devastating crime a year later, took the top spot in 2015, and drove $2.4 billion in losses last year, according to Abnormal AI. The pattern persists because trust, approval, and payment workflows remain easier to subvert than to harden.
At a glance
What this is: This webinar frames business email compromise as a continuing impersonation problem that outpaces enterprise defences and drove $2.4 billion in losses last year.
Why it matters: It matters because IAM, PAM, and finance workflows still rely on human trust signals and approval paths that BEC attackers can exploit faster than controls adapt.
Context
Business email compromise is an identity and trust problem, not just an email filtering problem. Attackers exploit impersonation, timing, and workflow pressure to get people to move money or share access under false pretences.
This webinar from Abnormal AI uses the FBI loss trend to show how BEC has become a durable enterprise control failure. The core issue is that approval chains and user trust still create a softer target than message inspection alone.
Key questions
Q: What breaks when email approval is treated as business approval?
A: When email approval is treated as business approval, attackers can impersonate trusted senders and push victims straight into payment, credential, or data-transfer actions. The control fails because inbox familiarity is not the same as verified authority. Security teams need a separate approval path that does not depend on message authenticity alone.
A: Phishing succeeds because attackers exploit timing, trust, and human judgment, not just technical gaps. The report shows many organisations still experience successful attacks, even while training exists, which suggests awareness alone is insufficient. Security teams need layered controls such as email filtering, user reporting, rapid response, and consequence models that make risky behavior visible and correctable.
Q: What are the signs that a business email compromise incident is already underway?
A: Common indicators include unrecognized payments, vendors asking about overdue invoices, phishing emails sent from a compromised mailbox, and unexpected mail rules that forward, delete, or hide messages. Detection is often delayed because these attacks can stay quiet for weeks or months, so by the time someone notices, logs may already have rolled over.
Q: How should teams respond when a payment request comes from a trusted mailbox?
A: Treat the request as unverified until a second channel confirms both the sender and the business need. The right response is to stop the workflow, validate the request against known records, and require a separate approver. Trusted mailboxes are still common fraud entry points.
Background and context
Why BEC keeps winning against email controls
Business email compromise often succeeds without malware or account takeover because the attacker only needs a believable message path and a convincing business context. Modern mail security can flag some malicious content, but it cannot fully verify whether a request matches normal organisational intent, payment cadence, or executive behaviour. That makes BEC fundamentally an identity-and-process abuse problem, not just a spam problem. When the attacker can impersonate a trusted sender, the control gap shifts from message filtering to trust verification and out-of-band validation.
Practical implication: treat payment approval and identity verification as separate controls, not as assumptions embedded in email.
How impersonation turns approval workflows into attack paths
BEC works because enterprises still collapse authentication, authorisation, and business approval into a single inbox interaction. A user may recognise a sender, but that recognition is not the same as verified authority to request a wire transfer, reset credentials, or redirect payment details. The attacker exploits that gap by moving the victim from message receipt to action before a second control is engaged. This is why BEC remains effective even as awareness improves: awareness without workflow separation still leaves the attacker room to manoeuvre.
Practical implication: insert independent approval checks for financial and identity-sensitive actions outside the email channel.
Why cross-channel fraud is the real escalation path
The article notes that threats are emerging across email and other vectors, which is important because BEC rarely stays confined to one channel. Once an attacker establishes credibility, they can pivot to phone calls, chat, or document workflows to reinforce the false request. That creates a multi-step social engineering chain where each channel reduces suspicion for the next. The defensive lesson is that organisations should model BEC as a cross-channel trust attack, not a single-inbox event.
Practical implication: monitor for escalation from email to voice or chat when a payment or credential request appears unusual.
NHI Mgmt Group analysis
Business email compromise is a governance failure in trust routing, not a mail-security problem alone. The attacker does not need to defeat every control if the organisation lets an inbox message stand in for verified authority. That is why BEC persists even as filtering and awareness improve. Practitioners should separate message delivery from business approval.
Identity-aware approval design is the missing control layer in BEC defence. A sender name or familiar thread is not an access decision, yet many payment and reset workflows still treat it that way. The result is a control plane built on social familiarity instead of verifiable authority. Finance, help desk, and IAM teams need to view approval routing as a shared governance problem.
Impersonation attacks exploit the weakest human decision point in a process chain. The attack surface is not just the mailbox, but the point where urgency compresses review and the user becomes the final authoriser. That means awareness campaigns help only when the workflow itself forces a second check. The practical conclusion is that process design must assume the message is already untrusted.
Cross-channel fraud is now the normal BEC escalation pattern. Email is often only the opening move, after which the attacker uses chat, phone, or document exchange to reinforce the false request. That makes channel isolation a false comfort. Organisations should govern BEC as a multi-channel trust problem that spans identity, communications, and payments.
What this signals
Identity-aware payment controls are now a baseline requirement. Organisations that still rely on message trust are exposing the exact gap BEC attackers look for: a human decision made too early in the process. The control must move from inbox confidence to independent authorisation.
Email security remains necessary, but it is no longer sufficient on its own. BEC resilience now depends on how finance, IAM, and help desk workflows validate requests before a user can convert them into action.
For practitioners
- Separate approval from message receipt Require an independent validation step for payments, bank detail changes, and sensitive account actions before any request is executed.
- Harden executive impersonation workflows Flag requests involving senior leaders, urgent transfers, or confidentiality pressure for mandatory out-of-band confirmation.
- Reduce trust in reply-thread requests Treat instructions that arrive inside an existing thread as untrusted until verified against a second channel or known workflow.
- Instrument help desk and finance handoffs Track where human approval moves from one team to another so phishing, BEC, and account-reset abuse can be detected as process abuse.
Key takeaways
- Business email compromise succeeds by abusing trust and approval flows, not only by bypassing inbox security.
- The article ties the problem to $2.4 billion in losses last year, which shows the scale of the control gap.
- The most effective defence is separating email delivery from independent verification before money or access moves.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001;TA0006;TA0009 — Initial Access; Credential Access; Collection | BEC is driven by impersonation entry, credential or trust abuse, and fraudulent collection. |
| Recommendation — Map BEC scenarios to initial access, credential abuse, and collection tactics in your detection and response playbooks. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | BEC exploits weak approval authority and poor separation between authentication and authorisation. |
| Recommendation — Separate request validation from execution authority and enforce independent approval checks. | ||
| CIS Controls v8 | CIS-5 — Account Management | BEC often leads to account misuse and downstream compromise of user or service access. |
| Recommendation — Review account change and reset workflows for abuse paths that start with a trusted message. | ||
| OWASP Non-Human Identity Top 10 | NHI-10 — Human Use of NHI | Impersonation often targets human-driven use of non-human or delegated access paths. |
| Recommendation — Restrict human initiation of sensitive actions that rely on delegated or non-human access paths. | ||
Key terms
- Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
- Impersonation: Impersonation is a controlled administrative action that lets an authorised operator assume a user context for debugging or support. In a well-governed setup it preserves audit logging, limits exposure of credentials, and keeps production authentication separate from local troubleshooting.
- Out-Of-Band Verification: A confirmation step that uses a different channel or method than the original request. It reduces the chance that a single spoofed email, voice call, or video session can authorize privileged activity or financial transfer.
- Approval Workflow: An approval workflow is the governed sequence that determines whether a request becomes active access. It usually combines routing, policy checks, and evidence capture. For identity teams, the important question is not how fast it runs, but whether each decision remains attributable and reviewable.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org