How it works
Business email compromise abuses a business communication to obtain a harmful action, often a payment or disclosure. The attacker may impersonate a familiar correspondent or use an actually compromised mailbox. The name describes the fraud scenario; it does not prove that every incident involves malware on the recipient’s computer.
A practical example
A supplier conversation could suddenly request payment to a different bank account. The message may look consistent with a real invoice and project, yet the change still needs separate authorization. A stolen mailbox can also give an attacker the context to write a more convincing request than an unrelated spam message.
What to check
Verify changed payment details through an established independently known contact, and follow the ordinary approval process even when the message says it is urgent. Review unexpected forwarding rules and sign-in activity if mailbox compromise is suspected. Protect email and recovery accounts with strong authentication, and keep records of the disputed instruction and payment.
Limits and safe use
Passing mail authentication checks or matching the sender’s usual writing style does not authorize a bank change. If a payment was sent, contact the financial provider promptly through a trusted channel and notify the responsible business person. Securing the mailbox and investigating the transfer are separate actions; changing a password alone does not recover money already sent.