Business email compromise (BEC) is one of the biggest threats to cybersecurity for businesses of all sizes, costing around $2.7 billion annually. They exploit the fact that most individuals rely on email for personal and professional communications, targeting inboxes to bypass signature-based prevention mechanisms used by secure email gateways. Once inboxes are compromised, they become tools attackers use to hijack corporate software, including billing, software-as-a-service (SaaS), and payment systems. It is vital for companies to understand how BEC operates and to adopt key strategies to prevent and manage attacks.
Common BEC Methods
Attackers typically use one of four common methods to compromise a business email account. First, phishing may be used to trick victims into providing their credentials. Then there is credential stuffing, in which hackers use stolen username-password pairs—usually obtained from unrelated data breaches—to gain unauthorized access to user accounts on other websites. Third, there is the brute force attack, which involves trying common passwords. Lastly, there is consent phishing (or OAuth phishing), in which users are tricked into granting malicious third-party apps permission to access their cloud accounts (such as Microsoft 365 or Google Workspace). In the latter, attackers send an email or message containing a link that points to a legitimate OAuth consent page. Instead of a fake login page, the user is greeted by an OAuth consent screen. It asks the user to connect an app (disguised as a legitimate-sounding name like “Document Reader” or “HR Portal”) to their account. When the user approves, the attacker is granted permission to access their emails, contacts, or files. This token remains valid even if the user changes their password, granting the attacker access without requiring the user’s password or multi-factor authentication again.
How Attackers Hijack Corporate Software with Compromised Inboxes
After inboxes are compromised, attackers can execute various tactics. Once attackers gain access to an account—either directly or through a malicious OAuth application—they may create hidden inbox rules (approximately 50% of all compromises include malicious mail rules). They can scan all incoming email for keywords such as “payment,” “confidential,” or “invoice,” and forward the email to an external server controlled by the attacker, while deleting the original from the victim’s inbox. A second tactic involves emailing other employees while posing as an executive. For instance, the attacker may impersonate a manager and request an immediate wire transfer. A third involves lateral movement—expanding the breach from one email account to the organization’s entire digital ecosystem. For instance, the attacker may use a single compromised email account to trigger password resets on external corporate platforms. Finally, attackers can use a malicious app to continuously monitor inboxes to delete emails from IT and security teams or deploy a backup access method to stay ahead of the organization’s IT team.
Detecting and Preventing Inbox Compromise
To detect and prevent BEC, security teams must configure alerts whenever users create forwarding, deletion, or filtering rules, particularly those that send messages to external addresses. Users must also be trained to watch out for common indicators of compromise—including deleted emails from managers, or emails marked as “read” that they haven’t actually opened. These are signs that an attacker is attempting to hide their presence as they gain access to other systems. Some companies are restricting email forwarding to reduce risk. While this may not always be possible, forwarding activity should be monitored and limited to approved categories. Finally, organizations should continue to embrace strong credential practices, including unique passwords, multi-factor authentication, and the continual monitoring of all OAuth permissions. Access to suspicious or unnecessary SaaS applications must also be monitored and revoked if appropriate. If IT teams discover a malicious email rule, they must not only remove it but also investigate the incident, as email rules are often indicative of a larger compromise.
BEC costs organizations billions of dollars per year, with around half of all compromises including malicious rules. Businesses should therefore monitor email activity and mail rules, verify suspicious emails with employees, and limit email forwarding. Traditional email security is still vital, but it is insufficient to stop a large-scale BEC attack in its tracks. As such, IT teams must be prepared to conduct investigations if even a single email rule violation or other suspicious activity is detected.
