Identity describes who the attacker is pretending to be, such as an executive or employee. Deception describes how the fraud is carried out, including impersonation, mailbox compromise, or no impersonation at all. Theme describes the goal or storyline of the email fraud, such as payment diversion or other business-relevant pretexts. Together, the three layers make BEC easier to classify and act on.
How the Three Layers Separate BEC Classification
The cleanest way to read a BEC taxonomy is to treat identity, deception, and theme as different questions. Identity answers who the message is meant to look like. Deception answers the fraud mechanism behind that appearance. Theme answers the business story being exploited, which is often the strongest clue for triage and response.
That separation matters because the same email can share one layer while varying in the others. An executive impersonation, a mailbox-compromise lure, and a payment-diversion pretext can appear together, but they do not mean the same thing. A taxonomy that keeps the layers distinct gives analysts a better way to compare incidents without collapsing different attack patterns into one label.
Why Identity Is the “Who” Layer, Not the Attack Method
Identity is the target persona the attacker is borrowing, such as a CEO, vendor contact, payroll manager, or internal colleague. It is about the social role the email is trying to occupy, not the technique used to send or stage the message. That makes identity useful for spotting repeated impersonation patterns across campaigns.
In practice, identity often influences urgency and authority. Messages that appear to come from finance, leadership, or a trusted supplier tend to get faster action because the recipient assumes the sender already has standing. A good taxonomy keeps that signal separate from how the attacker gained the channel, because the same identity can be spoofed, hijacked, or never impersonated at all.
How Deception and Theme Capture Different Parts of the Fraud Story
Deception describes the operational method. It can include direct impersonation, look-alike sending infrastructure, mailbox compromise, internal account abuse, or a completely different setup where the sender does not pretend to be a person at all. This layer tells investigators how trust was manipulated, which is often more important than the name on the display line.
Theme describes the storyline or objective of the email fraud. Common themes include payment diversion, gift card fraud, payroll redirection, invoice rerouting, or changes to bank details. A theme is not the same as identity because the same pretext can be used with different personas, and it is not the same as deception because the business objective can stay constant even when the delivery method changes.
For this reason, the three layers work best together. Identity gives the persona, deception gives the delivery method, and theme gives the intended fraud outcome. That combination helps security teams cluster cases, compare campaigns, and decide whether they are seeing a recurring social-engineering pattern or a more technical account-compromise problem.
Risk and Threat Considerations
BEC taxonomy becomes materially more useful when the layers are kept separate, because analysts can misread a mailbox-compromise case as simple impersonation, or miss that a payment-diversion theme is recurring across different personas. The main risk is classification drift, which weakens detection, case handling, and post-incident analysis.
Failure mechanism: When identity, deception, and theme are merged into one bucket, defenders lose the ability to distinguish impersonation from account takeover, or fraud pretext from access method. That can lead to the wrong control response, such as focusing only on sender verification when the real issue is compromised mailbox authority.
Impact: Misclassification can delay containment, distort metrics, and hide campaign reuse across multiple brands, executives, or payment scenarios. It also makes it harder to route cases to the right owners, because the response for spoofing, mailbox compromise, and payment fraud is not identical.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP API Security Top 10 | API6 — Unrestricted Access to Sensitive Business Flows | BEC themes often target business payment flows. |
| Recommendation — Protect payment and approval flows with step-up checks and explicit authorization. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Mailbox takeover and impersonation hinge on credential handling and account control. |
| Recommendation — Enforce credential lifecycle controls and rapid revocation for suspected compromise. | ||
| CIS Controls v8 | CIS-5 — Account Management | BEC classification helps distinguish account abuse from spoofing and guides control focus. |
| Recommendation — Review and harden accounts that can approve, redirect, or alter payments. | ||
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Mailbox compromise and fraudulent access often follow secret or token exposure. |
| Recommendation — Rotate exposed secrets and invalidate compromised access paths immediately. | ||
Practitioner Guidance
What to verify: Build your triage around three separate fields, who was being imitated, how the email obtained trust, and what business action it tried to trigger. If those fields are not separable in the case record, the taxonomy is too blunt to support reliable trend analysis.
What good looks like: Analysts can say “same identity, different deception” or “same theme, different persona” without rewriting the case. That is the sign the taxonomy is actually helping investigation instead of just renaming the same event.
Common mistake: Treating payment diversion as the whole incident and ignoring whether the message was spoofed, replayed from a compromised mailbox, or sent without impersonation. The method matters because it changes both the control you verify and the likelihood of repeat compromise.
Practitioner takeaway: Use identity to classify the impersonated persona, deception to classify the fraud method, and theme to classify the business pretext. If you keep those three dimensions distinct, BEC reporting becomes much more actionable for both detection and response.
Related resources from NHI Mgmt Group
- What is the difference between prompt injection risk and identity abuse in agents?
- What is the difference between SAST and DAST for security teams?
- What is the difference between deception coverage and identity governance?
- What is the difference between cloud deception and identity deception in proactive defence?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org