What is BEC (Business Email Compromise)? A Real Story of a BEC Attack
March 21, 2026, 12:41 p.m.
# BEC Attacks: Anatomy of the Business Email Compromise Threat Causing Millions of Euros in Losses

One Monday morning, the finance director of an Istanbul-based foreign trade company arrived at the office to find an urgent email from the CEO. The message requested the immediate transfer of 250,000 Euros for a confidential acquisition deal. The email address was correct, the writing style was familiar, and written communication was preferred over a phone call due to the sensitivity of the matter. The finance director approved the transfer without any suspicion. Two days later, during a meeting with the real CEO, when he learned that no such instruction had ever been given, it was already too late. The company had become a victim of a Business Email Compromise (BEC) attack.

This true story is unfortunately just one example of a scenario that repeats itself every day in the global business world. According to the FBI's Internet Crime Complaint Center (IC3) data, BEC attacks caused losses exceeding $43 billion worldwide between 2013-2022. In 2022 alone, this figure reached $2.7 billion. These statistics clearly demonstrate why BEC is considered one of the most serious threats to modern cybersecurity.

What is BEC (Business Email Compromise)?

BEC, or Business Email Compromise attack, is a highly sophisticated type of cyberattack in which cybercriminals gain financial advantage by compromising or impersonating corporate email accounts using social engineering techniques. Unlike traditional phishing attacks, BEC attacks are targeted, personalized operations that require in-depth research.

Attackers conduct detailed intelligence work to deceive their victims, learn the internal company hierarchy, study business processes, and wait for the most opportune moment. Due to this characteristic, BEC is considered a more sophisticated and dangerous version of spear phishing. These attacks, which target human psychology and organizational trust mechanisms rather than technical vulnerabilities, cannot be detected by most security software.

Business email attack warning

Business email attack warning

Key Characteristics of BEC Attacks

  • Social Engineering-Focused: Targets human psychology and trust relationships rather than technical vulnerabilities
  • Targeted and Research-Driven: Attackers gather detailed intelligence about victims and the organization for weeks
  • High-Value Targets: C-level executives and finance department employees authorized for financial transactions are priority targets
  • Trust Exploitation: Corporate trust is exploited by impersonating senior executives, CEOs, CFOs, or trusted business partners
  • Urgency and Confidentiality: Emphasis on urgent situations and confidentiality that force victims to act without thinking
  • Low Detection Rate: Rarely detected by traditional security solutions as they are legitimate-looking emails without malware

How Do BEC Attacks Occur? Step-by-Step Anatomy

BEC attacks are typically carried out after a long-term, multi-stage planning process. For a successful BEC operation, attackers follow a systematic approach:

1. Reconnaissance and Intelligence Gathering Phase

Cybercriminals conduct comprehensive OSINT (Open Source Intelligence) research about the target company and its employees. They examine LinkedIn profiles, extract the organizational chart from the company website, scan social media accounts, and even learn vacation times from employees' social posts. They analyze in detail who the senior executives are, who they work with, which suppliers they do business with, and their communication styles.

2. Entry and Gaining Control

Using the intelligence gathered, attackers can proceed with three different techniques:

  • Email Account Compromise: Full access to a real executive account is gained through credential phishing, keyloggers, or password cracking
  • Email Spoofing: A fake address typographically very similar to the real email address is created (for example: [email protected] or [email protected] instead of [email protected])
  • Domain Impersonation: A domain name similar to the company domain is registered and a professional-looking email infrastructure is set up

3. Building Relationships and Establishing Trust

The attacker does not immediately demand money. First, they initiate normal business correspondence to build trust, reduce the victim's suspicion, and create a legitimate communication history. In some cases, they make detection more difficult by becoming part of a real email chain.

4. Manipulation and Persuasion

Once trust is established, a critical request comes emphasizing urgency and confidentiality. Usually, financial requests such as money transfers, invoice payments, bank account information updates, or sharing sensitive information are involved. Messages are professionally prepared, personalized to prevent the target's suspicion, and supported by justifications that "phone calls cannot be made."

5. Attack Execution and Cover-Up

When the victim complies with the instructions, attackers quickly distribute the money to different accounts and cover their tracks. Usually, a few days later, when the fraud is revealed through genuine communication, tracing the money has become nearly impossible.

Real Case 1: 250,000 Euro CEO Fraud in Istanbul

This real case that occurred in the fall of 2019 painfully demonstrates the impact of BEC attacks in Turkey. The finance director of a medium-sized international trade company based in Istanbul arrived at work on a Monday morning to find an urgent email from the CEO.

The email requested the immediate transfer of 250,000 Euros to a specified account for a "confidential acquisition deal." The message contained the following statements:

"I'm in an important meeting early in the morning and will be unreachable by phone. The payment must be made by this evening for the confidential acquisition deal we're working on, which is critically important. Please transfer 250,000 Euros to the following account. Only you and I know about this matter right now, do not share it with anyone else."

Everything seemed normal to the finance director: The email address belonged to the CEO, the

Similar Posts