Definition · DNS & Email Spoofing
What is BEC?
Business email compromise is a social engineering attack carried out over email. There is usually no malware and no exploited vulnerability; the payload is a plausible instruction from someone the recipient trusts. Typical scenarios include a supplier notifying a change of bank details, an executive requesting an urgent transfer outside normal process, and a payroll change request for an employee’s account.
How the impersonation is achieved
- Domain spoofing — forging the From header on a domain with no enforcing DMARC policy
- Look-alike domains — typosquatting or homoglyph registrations that pass a glance but are attacker-controlled
- Display name abuse — a correct-looking name with an unrelated address, which mobile clients often hide
- Account takeover — sending from a genuinely compromised mailbox, the hardest variant to detect because every authentication check passes
- Thread hijacking — replying within a real conversation obtained from a compromised party
The external exposure angle
Two exposures matter. The first is your own domains: any domain without an enforcing DMARC policy, including parked brands, redirect domains, and subsidiaries, can be spoofed outright. The second is what public information makes the pretext credible — staff names and roles, finance contacts, supplier relationships, and out-of-office patterns are all discoverable through OSINT.
Controls that help
Email authentication is the technical floor: SPF, DKIM, and DMARC at p=reject across every domain you own, not just the one you send from. BIMI can make legitimate mail visually distinguishable once DMARC enforcement is in place. Beyond email, the effective controls are procedural — out-of-band verification of payment changes, dual authorisation for transfers, and a culture where questioning an urgent request is safe.
Related concepts
BEC is an attack vector favoured by financially motivated threat actors, and it depends on gaps in DNS and email security configuration that are visible from outside the organisation.