By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “The Devastating Impact of Business Email Compromise” (June 26, 2026)

TL;DR: Business email compromise remains a high-loss attack pattern, with nearly 20,000 attacks averaging $120,000 each, as attackers exploit urgency, fear, and hybrid work conditions to bypass existing controls, according to Abnormal AI. The governance problem is not awareness, but identity and process design that still leaves human decision-making too exposed.


At a glance

What this is: This is a webinar on why business email compromise is still effective in hybrid work, with the key finding that awareness has not closed the control gap.

Why it matters: It matters because IAM and security teams must design for human error, mailbox abuse and identity-driven fraud paths that traditional awareness and perimeter controls do not stop.


Context

Business email compromise is a fraud pattern in which attackers manipulate people into approving payments, sharing information or changing account details. The article argues that hybrid work makes those social-engineering paths easier because trust cues are weaker and decision-making is more dispersed.

The core governance problem is not simply employee awareness. It is that approval processes, communication norms and identity verification steps still leave too much room for urgency-driven human decisions, especially when work happens outside a tightly controlled office environment.


Key questions

Q: What should teams do when a compromised email account is detected?

A: Teams should move immediately from detection to containment. That usually means logging the user out, terminating active sessions, forcing password resets, and adding the user to watchlists that can trigger endpoint containment or reauthentication. The response should be coordinated across identity, email, and endpoint controls so the attacker loses both access and persistence.

Q: Why does hybrid work make business email compromise easier to pull off?

A: Hybrid work reduces the informal confirmation cues people rely on in an office, such as quick in-person checks and immediate peer validation. Attackers use that gap to create urgency, impersonate trusted senders, and push decisions through before the target has a second way to verify the request.

Q: What are the signs that a business email compromise defence is failing?

A: Warning signs include unexpected payment requests, subtle changes in writing style, urgent language, new bank details, and messages that bypass normal approval chains. A failing defence also shows up as employees not reporting suspicious emails, inconsistent use of certificate-based validation, and weak monitoring of login anomalies or unusual sender behaviour. When these signals appear together, the organisation is relying on trust instead of verification.

Q: How should security teams balance awareness training and process controls for BEC?

A: Use awareness training to reduce mistakes, but rely on process controls to stop the loss path. The practical answer is layered verification, segregation of duties, and callback rules for high-risk requests, because trained users can still be bypassed when attackers exploit urgency and fear.


Background and context

How business email compromise bypasses existing controls

BEC often succeeds without malware or a technical intrusion because the attacker targets the decision path rather than the endpoint. A convincing message, spoofed identity, compromised mailbox, or manipulated conversation can be enough to trigger payment, credential sharing, or sensitive data disclosure. Existing controls focused only on spam filtering, endpoint protection, or user awareness miss the fact that the fraud is often executed through legitimate collaboration channels. The security failure is not just message delivery. It is trust abuse inside normal business workflows.

Practical implication: model BEC as an identity and workflow abuse problem, not only an email security problem.

Why hybrid work expands the trust gap

Hybrid work weakens the informal verification steps people use in office settings. When employees are remote, they are more likely to rely on written requests, delayed callbacks, and fragmented context, which gives attackers more room to impersonate executives, vendors, or coworkers. The result is a widened gap between who appears to be authorised and who is actually making the request. That gap is especially dangerous when approval authority is spread across inboxes, chat tools, and shared documents.

Practical implication: require stronger identity verification for financial and sensitive requests that arrive outside face-to-face channels.

Why awareness training alone does not close the fraud path

Training can reduce mistakes, but it does not remove the structural conditions that make BEC profitable. Attackers exploit urgency, fear, and ambiguity, which means even well-trained users can be placed under time pressure at the exact moment a decision must be made. In identity terms, the problem is a weak trust boundary around human approvals. The organisation needs controls that constrain how requests are validated, not just reminders that people should be cautious.

Practical implication: pair awareness with payment verification, callback controls, and approval segregation.


NHI Mgmt Group analysis

Business email compromise is a human identity control problem disguised as an email problem. The article shows that attackers win by manipulating judgment inside ordinary approval flows, not by defeating every layer of technical security. That means the critical failure point is the trust boundary around human action, especially where finance, procurement, and executive communication intersect.

Hybrid work widens the verification gap that BEC depends on. When employees are distributed, organisations lose the incidental safeguards of proximity, overheard context, and quick in-person confirmation. The result is a longer path from request to validation, which gives attackers more time to steer the transaction. Practitioners should treat distributed work as a control-design issue, not a workplace preference issue.

Awareness is necessary but not sufficient because BEC exploits process latency. Training helps users recognise manipulation, but the article makes clear that urgency and fear still push people past caution. That is why the durable control question is how approvals are structured, who can confirm them, and how exceptions are handled under pressure. The practitioner conclusion is simple: design the process so one compromised conversation cannot authorise a loss.

Hybrid work BEC creates an identity verification gap that organisations must name directly. The issue is not just fraudulent email content. It is the missing second factor of human trust, where a request arrives through one channel and is validated through the same channel. That is a governance weakness, not a user mistake, and it should be treated as such in policy and control design.

What this signals

Business email compromise is increasingly a workflow integrity issue. The security question is not whether users can spot a suspicious message in theory. It is whether the organisation has designed approval paths that remain safe when the requester, the channel, and the urgency signal are all being manipulated at once.

Identity verification has to move closer to the transaction. Hybrid work makes it easier for attackers to exploit familiar names and routine processes, so teams need to validate the request at the moment of execution rather than assuming the sender relationship is enough.

Weak approval design is what keeps BEC profitable. If a request can travel from inbox to payment with no independent confirmation, the control environment is still optimised for convenience instead of fraud resistance. That trade-off now deserves explicit governance review.


For practitioners

  • Tighten payment verification paths Require out-of-band confirmation for wire changes, invoice updates, and urgent payment requests so a single email conversation cannot authorise funds movement.
  • Separate approval and execution duties Split request approval, payment release, and beneficiary maintenance across different people or systems to reduce the chance that one compromised inbox can complete the full transaction.
  • Harden executive impersonation checks Use callback procedures and known-contact validation for executive, finance, and vendor requests that arrive through email or chat, especially in hybrid work settings.
  • Review mailbox and collaboration trust paths Map where email, chat, and shared-document permissions can be used to initiate financial or sensitive-data requests, then restrict the routes that bypass secondary verification.

Key takeaways

  • Business email compromise remains effective because it exploits human approvals inside normal business workflows, not because awareness has failed on its own.
  • The article cites nearly 20,000 attacks, average losses of $120,000 per attack, and billions of dollars sent to cybercriminals each year.
  • Organisations need stronger verification, segregation of duties, and out-of-band confirmation so one compromised conversation cannot authorise a loss.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack surface, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0006; TA0040 — Credential Access; ImpactBEC uses trust abuse and financial loss rather than technical exploitation.
Recommendation — Map BEC patterns to TA0006 and TA0040 to improve detection and fraud response coverage.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsApproval and transaction authority are the core governance issues in BEC.
Recommendation — Apply PR.AA-05 to separate request validation from payment execution for high-risk actions.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementBEC resilience depends on reliable verification of who is requesting the action.
Recommendation — Use IA-5 to strengthen verification steps for payment and account-change requests.
ISO/IEC 27001:2022A.5.15 — Access controlAccess control needs to extend to approval paths and transaction authorisation.
Recommendation — Extend A.5.15 controls to cover who can request, approve, and execute sensitive transactions.

Key terms

  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Out-Of-Band Verification: A confirmation step that uses a different channel or method than the original request. It reduces the chance that a single spoofed email, voice call, or video session can authorize privileged activity or financial transfer.
  • Approval Segregation: Approval segregation means the person or system that routes a request is not the same authority that grants access. This separation reduces hidden privilege expansion and makes access decisions easier to audit, especially in high-volume ITSM environments.
  • Hybrid Work Trust Boundary: The practical edge of trust that shifts when employees work outside a controlled office network. In identity security, it describes how location, device ownership, and access context become part of the decision instead of being assumed safe.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org