Fake Boss, Real Fraud

Understanding Business Email Compromise
BEC comes in many flavours. Sometimes attackers gain access to a real email account and use it to send malicious requests (like “change bank account details” or “pay this invoice now”). Other times, they spoof a domain or send a lookalike message pretending to be a trusted supplier, executive or client. Visit cyber.gov.au for more insights.
Why BEC works so well
- We’re busy. A sense of urgency or authority can override healthy suspicion.
- Familiarity helps attackers blend in, knowing names, roles and payment practices.
- Many businesses have weak email guardrails (lack of multifactor protection, missing domain spoofing controls).
What to watch for
- Emails requesting a sudden change in bank account or payment details
- Requests to act quickly, bypassing normal checks
- Messages from internal addresses but with odd phrasing or mistakes
🛡️ Want to reduce your risk? In our upcoming webinar, we’ll dive into how BEC works at a technical and human level, and how to build defences into your workflows.
Register here for our upcoming webinar
Meanwhile, check out our IT Security Assessments page to see how we evaluate exposure in your environment.



