Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why do phishing campaigns that use business email…
Threats, Abuse & Incident Response

Why do phishing campaigns that use business email compromise and fake support accounts create outsized risk for organisations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Threats, Abuse & Incident Response

These campaigns work because they exploit trust relationships, urgency, and familiar business processes rather than malware alone. Fake support accounts and business email compromise messages can bypass casual suspicion, especially when they reference real people or current events. The result is higher chance of credential theft, fraudulent payment requests, and broader operational disruption across teams that rely on email for decisions.

Why these campaigns create outsized organisational risk

business email compromise and fake support accounts work because they attack the decision layer of the organisation, not just the inbox. They exploit trust in known names, familiar workflows, and urgent requests, so a single deceptive message can trigger credential theft, payment fraud, or a rushed exception that bypasses normal controls.

The risk scales because these attacks are designed to look operationally normal. Once an attacker enters a business process through email, the same message can reach finance, IT, legal, and leadership without needing malware, making the blast radius much larger than a simple spam event.

When those trust paths are abused, the issue becomes less about whether one message is convincing and more about whether the organisation has built its processes so email can safely act as an authority signal.

How fake support accounts and BEC messages bypass normal suspicion

Fake support accounts mimic help desk, vendor, or internal service communication, so the recipient is primed to cooperate rather than challenge the request. Business email compromise works the same way, but often with more precision: attackers may reference real colleagues, current projects, invoice timing, or a known supplier to make the request feel routine.

This is why the attack is effective even when the content is not technically sophisticated. The social engineering succeeds by matching the organisation's normal communication pattern closely enough that the recipient applies the wrong decision rule, trusting context instead of verifying authority.

The strongest campaigns also exploit role ambiguity. If a message appears to come from support, finance, or an executive, the recipient may assume someone else already validated it, which creates a gap between perceived legitimacy and actual legitimacy.

What makes the impact broader than a single stolen account

The immediate harm is often credential theft, account takeover, or fraudulent payment instruction, but the larger impact is process contamination. A compromised mailbox or convincing fake support channel can be used to reset passwords, intercept approvals, harvest further contacts, and create follow-on fraud opportunities across multiple teams.

That is why these campaigns often become operational incidents as well as security incidents. They can disrupt procurement, payment processing, ticket handling, customer support, and executive communications because those functions depend on email as a trusted coordination channel.

For organisations that rely on email for approvals, the practical risk is not just loss of confidentiality. It is also loss of decision integrity, because a forged request can cause a legitimate employee to take an action that the business will later treat as authorised.

Risk and Threat Considerations

These campaigns are especially dangerous where payment approval, password reset, or vendor-change workflows still trust email content too readily. A convincing impersonation can create a fast path from initial trust to financial loss, mailbox takeover, or wider internal compromise without any exploit chain beyond persuasion.

Failure mechanism: The attacker abuses a trusted communication channel and times the request to match normal work pressure, so the recipient substitutes familiarity for verification and approves an action that should have required stronger confirmation.

Impact: The result can include fraudulent transfer, credential compromise, business disruption, and secondary abuse of the same mailbox or relationship to reach additional systems or teams.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageBEC often aims to steal credentials or tokens through deceptive email workflows.
NHI-05 — Overprivileged NHICompromised non-human access amplifies the blast radius after phishing succeeds.
Recommendation — Harden recovery and alerting around secrets exposed through email-driven social engineering. Reduce privilege on service identities so a stolen credential cannot move broadly.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementPhishing campaigns frequently target credentials and authentication material.
IA-2 — Identification and Authentication (Organizational Users)BEC succeeds when user identity is accepted without stronger verification.
AC-3 — Access EnforcementEmail-based fraud becomes harmful when messages can authorise privileged actions.
Recommendation — Enforce rotation, revocation, and protected handling for authenticators and secrets. Require stronger authentication for sensitive access and high-risk actions. Bind critical actions to enforced access rules, not informal email approval.
CIS Controls v8CIS-5 — Account ManagementCompromised or abused accounts are the common endpoint of BEC campaigns.
Recommendation — Tighten account lifecycle control and remove unused access paths quickly.

Practitioner Guidance

What to prioritise: Focus first on the transactions that create the most damage when they are approved by email alone, especially payments, password resets, vendor changes, and executive requests. Those are the workflows where a believable message becomes a business event.

What to verify: Confirm that high-risk requests require a second channel or independent approval that is hard to spoof, and check whether support and finance teams have a shared, testable rule for rejecting urgency-driven exceptions.

Common mistake: Treating phishing only as a training problem. The better control is to reduce the number of decisions that an email can authorise on its own, because human suspicion will always vary under pressure.

Practitioner takeaway: The key question is not whether users can spot a fake message, but whether a fake message can still trigger a valuable action before the organisation re-verifies it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org