Join our Newsletter — 33% off our NHI Course

Business email compromise in 2025: are email controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Business email compromise caused over $3 billion in reported losses in 2025, and attackers increasingly rely on executive impersonation, vendor spoofing, and conversation hijacking rather than malware, according to the FBI and Abnormal AI. Legacy secure email gateways are being outmaneuvered by identity-driven attacks that require behavioral context, not just payload scanning.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The Detection Gap: Why AI-Powered Attacks Are Winning Against Legacy Email Security”.

Key questions

Q: Why do legacy SEG controls miss business email compromise in distributed organisations?

A: Legacy SEG controls are often tuned to content, reputation, and perimeter filtering, but BEC frequently uses legitimate-looking communication and trusted relationships.

Q: Why do business email compromise attacks create more financial risk than generic phishing?

A: BEC creates more financial risk because the attacker’s goal is usually direct monetary loss, not just credential theft.

Practitioner guidance

  • Harden vendor-change verification Require a second channel for bank detail changes, payment requests, and payroll updates so email cannot by itself authorise financial action.
  • Baseline normal communication patterns Map typical sender-recipient relationships, thread cadence, and request types for finance and executive workflows to create a usable trust baseline.
  • Add identity signals to email detection Prioritise sender reputation, relationship history, and conversation continuity alongside domain and attachment checks in the detection pipeline.

Bottom line: Business email compromise now succeeds by abusing trust relationships and normal business communication, not by depending on malware alone.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21474
 

Business email compromise is now a trust-manipulation problem, not a spam problem. The article shows attackers succeeding without malware by impersonating executives and vendors inside normal business threads. That means the decisive control is not message blocking alone, but the ability to verify whether the communication context matches expected authority. Practitioners should treat trust validation as part of the email security stack.

A question worth separating out:

Q: How should organisations verify high-risk requests that arrive by email?

A: Use an independent confirmation step outside the email thread for payments, vendor changes, payroll updates, and other high-impact actions. Verification should check the requester through a separate trusted channel and confirm the business event before any action is taken.

👉 Read our full editorial: AI-powered business email compromise is outpacing legacy email controls


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.