Spear phishing is targeted phishing: instead of mass mails, selected people receive tailored messages built on real research — roles, projects, writing style, current matters. Business email compromise (BEC), known as CEO fraud, is its money-focused tip: perpetrators pose as management, supplier or lawyer and trigger transfers or data handovers.
BEC often works entirely without malware — the weapon is credibility. That is exactly why these attacks pass classic virus filters and rank among the most expensive forms of fraud.
How do BEC attacks unfold?
It starts with reconnaissance: org charts, signing authorities, holiday schedules, ongoing projects — much of it public. Then comes the approach: a deceptively similar sender domain, a compromised real mailbox, or plain response pressure (confidential, urgent, only you). Increasingly, AI-generated texts and deepfake voices reinforce the deception.
The most dangerous variant uses real, taken-over mailboxes: perpetrators read along for weeks, join ongoing invoice threads and change only the bank details at the right moment.
What really protects
- Processes before technology: four-eyes principle and callback via known numbers for payment and master data changes — without exception.
- Email authentication (SPF, DKIM, DMARC) against spoofed sender domains.
- Phishing-resistant login (passkeys) so mailboxes do not get taken over in the first place.
- Trained scepticism: urgency plus confidentiality plus payment change is the pattern.