Business email compromise also known as
In brief
Business email compromise, also known as Email Account Compromise, is a transfer-of-funds scam. Learn how BEC differs from phishing and CEO fraud.

Business email compromise is also known as Email Account Compromise, or EAC, in FBI Internet Crime Complaint Center public service announcements. The terms are often paired as BEC/EAC because both involve fraudsters using compromised communications or impersonation to pursue unauthorized transfers of funds. "CEO fraud" is not a full synonym. It names one BEC scenario involving an executive wire-transfer request.
At a glance
Quick takeaways
- Email Account Compromise, or EAC, is the alternative name most closely paired with business email compromise.
- The FBI's IC3 began tracking BEC and EAC as one crime type in 2017 because their techniques became similar.
- BEC is distinct from phishing, though phishing messages can help an attacker gather details for a BEC attempt.
- A compromised email account can expose financial correspondence, address books, forwarding settings, and mailbox rules.
- CEO fraud describes one executive-impersonation BEC scenario, not every type of BEC.
- DMARC, SPF, and DKIM help validate email identity, but they do not replace mailbox-access controls or transfer verification.
How BEC and EAC work
The FBI IC3 BEC information page describes business email compromise as a scam targeting businesses and people involved in transfer-of-funds activity. It is frequently carried out by compromising legitimate business email accounts through social engineering or computer intrusion, with the goal of an unauthorized transfer.
IC3's 2017 public service announcement distinguishes the terms historically. BEC described scams targeting businesses that work with suppliers or regularly make wire-transfer payments. EAC described the component targeting individuals who make wire-transfer payments. IC3 says it began tracking the scams as a single crime type in 2017 because their techniques had become increasingly similar.
A compromised mailbox can make the fraud more convincing because the attacker can use a legitimate account and learn how the organization communicates. The 2025 IC3 Annual Report also notes that fraudsters can compromise other forms of communication, including phone numbers and virtual meeting applications.
BEC commonly involves a financial request, but the visible message alone does not establish how the attacker got access. A sender might impersonate an executive without accessing that executive's mailbox. In another case, the sender may control a legitimate account and reply within an existing conversation.
For related education on impersonation and account-based threats, see Palisade's email threats and impersonation learning hub.
When the name changes, and when it does not
Use "Email Account Compromise" when referring to the BEC/EAC pairing used in IC3 public service announcements. Use "CEO fraud" only for the executive wire-transfer-request scenario that IC3 identifies as one variant. The same IC3 notice also gives separate names for its supplier-invoice scenario, including "Bogus Invoice Scheme," "Supplier Swindle," and "Invoice Modification Scheme."
A practical decision rule is:
- If the question is about the broader transfer-of-funds scam against a business or an individual, call it BEC or the IC3-paired term BEC/EAC.
- If the attacker has gained access to a real mailbox, describe that mailbox as an email account compromise.
- If the request falsely appears to come from an executive, "CEO fraud" can describe that scenario, but it does not cover every BEC case.
- If an unsolicited message asks for credentials or personal information, it fits IC3's separate Phishing/Spoofing category unless evidence shows it is part of a broader BEC operation.

A worked BEC and EAC example
IC3 documents five main BEC scenarios, including supplier fraud, executive wire-transfer requests, fraudulent correspondence through compromised email, executive and attorney impersonation, and data theft. The following is a worked classification example, not a message template.
Observed request: A finance employee receives an urgent request
to change a supplier's payment destination.
If the sender only imitates an executive:
Classification: BEC scenario, potentially "CEO fraud."
If the request arrives inside a real supplier mailbox thread:
Classification: BEC involving an Email Account Compromise.
If an earlier unsolicited message sought login details:
Classification: Phishing may be a precursor, but it is not the
same crime type as the later BEC attempt.
The IC3 BEC/EAC scenario notice says victims may first receive phishing emails seeking details about the business or person being targeted. That makes phishing a possible precursor to BEC, not another name for it.
IC3's annual-report taxonomy treats BEC and Phishing/Spoofing as separate crime types. Its definition of phishing covers unsolicited email, text messages, and phone calls that appear to come from a legitimate company and request personal, financial, or login credentials. A phishing event can be harmful on its own, while a BEC event focuses on the unauthorized transfer objective.
What to check after a suspected compromise
Start with the evidence available from the affected account and payment process.
- Review mailbox rules and automatic forwarding. The IC3 cloud-email compromise advisory says attackers may configure rules that delete key messages or forward mail to an outside account.
- Review retained login and mailbox-setting changes. IC3 recommends logging and retaining these changes for at least 90 days, and enabling alerts for suspicious activity such as foreign logins.
- Check whether the attacker accessed financial conversations or address books. IC3 says attackers analyze compromised mailboxes for financial-transaction evidence and may use address books to identify additional phishing targets.
- Verify payment changes through an independently known contact method before moving funds. A reply to the suspicious message thread is not independent verification.
- Confirm that SPF, DKIM, and DMARC are configured as part of the anti-spoofing controls IC3 recommends. For broader context, see email security.
Continue your email-security review
BEC/EAC response begins with the compromised account, the payment request, and the organization’s identity controls. Use Palisade's email security guide to place those controls alongside the wider risks of spoofing, account compromise, and email-based fraud.
The guide cannot determine whether a particular mailbox is compromised or approve a payment change. Those decisions require account logs, mailbox evidence, and your organization’s payment-verification process.
Evidence
Sources and further reading
Questions readers ask
Frequently asked questions

Written by
Samuel ChenardCEO & Co-Founder, Palisade
Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.
More from Samuel →


