Business Email Compromise (BEC)
Business Email Compromise
A category of wire-fraud attack where the attacker impersonates a trusted party (executive, vendor, advisor) over email to redirect a payment to a fraudulent account.
Business Email Compromise (BEC) is the highest-loss cybercrime category tracked by the FBI Internet Crime Complaint Center (IC3), responsible for over $2.9 billion in reported US losses in 2023. BEC attacks typically start with reconnaissance on a target organization (leadership, vendor relationships, wire-transfer cadence) and end with a spoofed or hijacked email instructing a finance team, family-office bookkeeper, or advisor to redirect a legitimate payment. BEC does not require malware or system compromise; most successful BEC losses trace to weak sender authentication (SPF, DKIM, DMARC), poor wire-verification protocols, or hijacked advisor tenant mailboxes. Prevention requires both technical controls (DMARC enforcement, mailbox hygiene) and process controls (out-of-band verification on wire instructions).
Family offices and wealth manager firms sit on precisely the profile BEC operators target: high transaction values, distributed advisor networks, and often loose wire-verification norms. LeakTrace surveys BEC precursor conditions (DMARC posture, credential exposure, lookalike domain registration) across the advisor tenant network as a core part of the family-office and wealth-manager engagements.