Business email compromise (BEC) and its voice-based sibling vishing are cons, not hacks: an attacker impersonates a boss, vendor, or IT technician — by email, phone, or both — and talks a real employee into wiring money, buying gift cards, or reading out a multi-factor code. These schemes cause the largest direct reported losses of any internet crime category in the FBI's IC3 statistics, exceeding ransomware year after year, because they exploit trust and process rather than software. The defense that works is procedural: out-of-band verification for every payment or credential change, and a hard rule that nobody legitimate ever needs your MFA code.
How do BEC attacks work?
The classic patterns are stable:
- CEO/CFO fraud: an email or call impersonating an executive pressures finance staff to wire funds urgently — "in a meeting, handle this now, confidential."
- Vendor email compromise: attackers compromise a real supplier's mailbox, watch invoicing, then send a believable "updated bank details" email; payments flow to the criminal account for weeks.
- Payroll diversion: an email "from an employee" redirects their salary deposit.
- Gift-card and receipt scams: lower value, higher volume, aimed at any staff member.
The credential access that powers mailbox-takeover BEC comes from infostealer logs and phishing; once inside a real mailbox, the attacker reads the thread and replies within it — the reply-to address is genuine, the domain is genuine, and no filter flags it because the email is technically real.
Where does vishing come in?
Voice adds immediacy and authority. The recurring enterprise version: a caller claiming to be IT support, often referencing a real ticket or the company's actual tooling, walking an employee through "enrolling a new MFA device" — in practice approving a push prompt or generating an MFA-enrollment that hands over the second factor. Help-desk impersonation targeting password resets works the same way, exploiting the exact staff whose job is to be helpful. The AI-voice era has lowered the production cost of convincing audio — a cloned executive voice is now minutes of work, as our deepfake-call guide covers — but the core mechanics were working with ordinary human voices for years.
Why do technical defenses miss these?
Because there is nothing technical to catch. BEC emails usually come from legitimate or lookalike accounts with no malware and no malicious links; the malicious part is the payment instruction, which no scanner evaluates. Filters catch the crude lookalike domains; they cannot judge that a genuine email from a genuinely compromised vendor mailbox contains a false bank account. The controls that actually function are human-process ones: verification channels, payment thresholds, and drilled reflexes.
What protects an organization?
- Out-of-band verification for money and credentials: any bank-detail change, new payee, urgent wire, or MFA enrollment is confirmed through a previously known channel — call the vendor's number on file, walk to the executive's office. The callback habit alone defeats most BEC.
- MFA-code hygiene: a standing rule, trained until boring, that no legitimate IT, bank, or service will ever ask for a code or a prompt approval you did not initiate — and that requests to do so are reported, not complied with.
- Payment process friction: delays built into new-payee setups, dual approval above thresholds, and a culture where a CFO accepts "I called to verify" as praise rather than insubordination.
- Mailbox hardening: MFA and sign-in alerts on executive and finance mailboxes, banners on external mail, and removal of legacy protocols that bypass MFA.
- Rehearse it: run the scenario in training — the first time an employee hears a convincing fake-IT call should be in a drill.
What should individuals watch for?
The consumer versions arrive as bank fraud calls, fake employer onboarding, and marketplace cons: anyone creating urgency around a payment, a code, or remote access to your device. The same rules apply: hang up and call back on the number you look up; never read codes to anyone; and treat "stay on the line" as a red flag in itself. If a payment went through, the response speed decides recovery — the bank's fraud line, the FBI's IC3 at ic3.gov, and for businesses the FBI's Recovery Asset Team, which has a strong record on wire recalls when notified within days.
For more context, read Deepfake voice scam calls explained: the 'family emergency' call that sounds real.
For more context, read quishing.
For more context, read infostealer malware.

