Live Threat Pulse: 2,847 threats detected in last 24h

menu_book Concept

Business Email Compromise (BEC)

Also known as: BEC, Email account compromise

Business email compromise (BEC) is a fraud in which attackers gain access to or impersonate a corporate email account to trick employees, customers, or partners into transferring money or data. Stolen email credentials from infostealers are a common enabler.

What is BEC?

BEC attacks abuse trusted business email relationships. After compromising or spoofing an executive or finance account, attackers send convincing requests for wire transfers, invoice changes, or sensitive data. BEC consistently ranks among the costliest categories of cybercrime.

How infostealers enable BEC

Infostealers capture saved email and webmail credentials and session cookies, giving attackers direct, authenticated access to corporate mailboxes — the foothold needed to run a convincing BEC scheme from inside a real account.

How VantaPrism Tracks Business Email Compromise (BEC)

VantaPrism surfaces compromised email credentials and sessions from infostealer logs, enabling teams to secure mailboxes before they are weaponised for BEC.

Check Your Exposure arrow_forward

Frequently Asked Questions

How do attackers get into email accounts for BEC?

expand_more
Often via credentials and session cookies harvested by infostealers, or through phishing, giving them authenticated access to a real corporate mailbox.
← All Glossary Terms Last reviewed: June 2026