Glossary · simply explained

Spear phishing & BEC (CEO fraud)

Spear phishing is targeted phishing: instead of mass mails, selected people receive tailored messages built on real research — roles, projects, writing style, current matters. Business email compromise (BEC), known as CEO fraud, is its money-focused tip: perpetrators pose as management, supplier or lawyer and trigger transfers or data handovers.

BEC often works entirely without malware — the weapon is credibility. That is exactly why these attacks pass classic virus filters and rank among the most expensive forms of fraud.

How do BEC attacks unfold?

It starts with reconnaissance: org charts, signing authorities, holiday schedules, ongoing projects — much of it public. Then comes the approach: a deceptively similar sender domain, a compromised real mailbox, or plain response pressure (confidential, urgent, only you). Increasingly, AI-generated texts and deepfake voices reinforce the deception.

The most dangerous variant uses real, taken-over mailboxes: perpetrators read along for weeks, join ongoing invoice threads and change only the bank details at the right moment.

What really protects

  • Processes before technology: four-eyes principle and callback via known numbers for payment and master data changes — without exception.
  • Email authentication (SPF, DKIM, DMARC) against spoofed sender domains.
  • Phishing-resistant login (passkeys) so mailboxes do not get taken over in the first place.
  • Trained scepticism: urgency plus confidentiality plus payment change is the pattern.

Frequently asked questions about Spear phishing & BEC (CEO fraud)

What distinguishes spear phishing from normal phishing?

Mass phishing spreads wide and hopes for chance hits; spear phishing researches the target and writes tailored messages — real names, real projects, fitting tone. The detection chance drops drastically because the usual warning signs are missing.

How do I recognise a CEO fraud attempt?

By the pattern, not the sender: unusual payment instruction, time pressure, confidentiality, bypassing normal processes, new bank details. With this combination: stop the transaction and verify via a known, independent channel — never via the mail itself.

Is a spam filter enough against BEC?

No — many BEC mails contain neither links nor attachments and sometimes come from real, taken-over mailboxes. Filters help at the margins; what decides are payment processes with a four-eyes principle, mandatory callbacks and email authentication of your own domains.

What is thread hijacking?

Perpetrators take over a real mailbox, read ongoing conversations and reply mid-thread — with changed bank details for an expected invoice, say. Because sender and context are genuine, this is the hardest BEC form to detect.

What role does AI play in these attacks?

AI lowers the cost of tailoring: flawless, stylistically fitting texts in any language, plus cloned voices for callback fraud (vishing). Processes that do not rely on a feeling of authenticity become all the more important — callbacks via known numbers, the four-eyes principle.

Wondering how this looks in your own network? Talk to KAEMI: we plan, build and manage the right solution with you.