# Business email compromise also known as

> Business email compromise, also known as Email Account Compromise, is a transfer-of-funds scam. Learn how BEC differs from phishing and CEO fraud.

Business email compromise is also known as Email Account Compromise, or EAC, in [FBI Internet Crime Complaint Center public service announcements](https://www.ic3.gov/PSA/2024/PSA240911). The terms are often paired as BEC/EAC because both involve fraudsters using compromised communications or impersonation to pursue unauthorized transfers of funds. "CEO fraud" is not a full synonym. It names one BEC scenario involving an executive wire-transfer request.

## Quick takeaways

- Email Account Compromise, or EAC, is the alternative name most closely paired with business email compromise.
- The FBI's IC3 began tracking BEC and EAC as one crime type in 2017 because their techniques became similar.
- BEC is distinct from phishing, though phishing messages can help an attacker gather details for a BEC attempt.
- A compromised email account can expose financial correspondence, address books, forwarding settings, and mailbox rules.
- CEO fraud describes one executive-impersonation BEC scenario, not every type of BEC.
- DMARC, SPF, and DKIM help validate email identity, but they do not replace mailbox-access controls or transfer verification.

## How BEC and EAC work

The [FBI IC3 BEC information page](https://www.ic3.gov/CrimeInfo/BEC) describes business email compromise as a scam targeting businesses and people involved in transfer-of-funds activity. It is frequently carried out by compromising legitimate business email accounts through social engineering or computer intrusion, with the goal of an unauthorized transfer.

IC3's 2017 public service announcement distinguishes the terms historically. BEC described scams targeting businesses that work with suppliers or regularly make wire-transfer payments. EAC described the component targeting individuals who make wire-transfer payments. IC3 says it began tracking the scams as a single crime type in 2017 because their techniques had become increasingly similar.

A compromised mailbox can make the fraud more convincing because the attacker can use a legitimate account and learn how the organization communicates. The [2025 IC3 Annual Report](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf) also notes that fraudsters can compromise other forms of communication, including phone numbers and virtual meeting applications.

BEC commonly involves a financial request, but the visible message alone does not establish how the attacker got access. A sender might impersonate an executive without accessing that executive's mailbox. In another case, the sender may control a legitimate account and reply within an existing conversation.

For related education on impersonation and account-based threats, see Palisade's [email threats and impersonation learning hub](/learning/threats).

## When the name changes, and when it does not

Use "Email Account Compromise" when referring to the BEC/EAC pairing used in IC3 public service announcements. Use "CEO fraud" only for the executive wire-transfer-request scenario that IC3 identifies as one variant. The same IC3 notice also gives separate names for its supplier-invoice scenario, including "Bogus Invoice Scheme," "Supplier Swindle," and "Invoice Modification Scheme."

A practical decision rule is:

- If the question is about the broader transfer-of-funds scam against a business or an individual, call it BEC or the IC3-paired term BEC/EAC.
- If the attacker has gained access to a real mailbox, describe that mailbox as an email account compromise.
- If the request falsely appears to come from an executive, "CEO fraud" can describe that scenario, but it does not cover every BEC case.
- If an unsolicited message asks for credentials or personal information, it fits IC3's separate Phishing/Spoofing category unless evidence shows it is part of a broader BEC operation.

This distinction matters because the response differs. An impersonated executive request calls for out-of-band payment verification. A compromised mailbox also calls for account investigation, mailbox-rule review, and access remediation.

![Decision flow showing when to use the terms BEC, EAC, CEO fraud, and phishing](/images/editorial/business-email-compromise-also-known-as/business-email-compromise-also-known-as-decision-flow.webp "1200x829")

*Source: Palisade.*

## A worked BEC and EAC example

IC3 documents five main BEC scenarios, including supplier fraud, executive wire-transfer requests, fraudulent correspondence through compromised email, executive and attorney impersonation, and data theft. The following is a worked classification example, not a message template.

```text
Observed request: A finance employee receives an urgent request
to change a supplier's payment destination.

If the sender only imitates an executive:
Classification: BEC scenario, potentially "CEO fraud."

If the request arrives inside a real supplier mailbox thread:
Classification: BEC involving an Email Account Compromise.

If an earlier unsolicited message sought login details:
Classification: Phishing may be a precursor, but it is not the
same crime type as the later BEC attempt.
```

The [IC3 BEC/EAC scenario notice](https://www.ic3.gov/PSA/2017/PSA170504) says victims may first receive phishing emails seeking details about the business or person being targeted. That makes phishing a possible precursor to BEC, not another name for it.

IC3's annual-report taxonomy treats BEC and Phishing/Spoofing as separate crime types. Its definition of phishing covers unsolicited email, text messages, and phone calls that appear to come from a legitimate company and request personal, financial, or login credentials. A phishing event can be harmful on its own, while a BEC event focuses on the unauthorized transfer objective.

## What to check after a suspected compromise

Start with the evidence available from the affected account and payment process.

- Review mailbox rules and automatic forwarding. The [IC3 cloud-email compromise advisory](https://www.ic3.gov/PSA/2020/PSA200406) says attackers may configure rules that delete key messages or forward mail to an outside account.
- Review retained login and mailbox-setting changes. IC3 recommends logging and retaining these changes for at least 90 days, and enabling alerts for suspicious activity such as foreign logins.
- Check whether the attacker accessed financial conversations or address books. IC3 says attackers analyze compromised mailboxes for financial-transaction evidence and may use address books to identify additional phishing targets.
- Verify payment changes through an independently known contact method before moving funds. A reply to the suspicious message thread is not independent verification.
- Confirm that SPF, DKIM, and DMARC are configured as part of the anti-spoofing controls IC3 recommends. For broader context, see [email security](/learning/email-security).

A public posture check can help identify published-domain gaps after the immediate investigation. You can [assess your email-security posture](/tools/email-security-score), then compare the result with DNS records and the evidence from the actual mailbox. A public check cannot show whether a specific account was compromised, inspect private mailbox rules, or prove why a payment request was fraudulent.

## Continue your email-security review

BEC/EAC response begins with the compromised account, the payment request, and the organization’s identity controls. Use Palisade's [email security guide](/learning/email-security) to place those controls alongside the wider risks of spoofing, account compromise, and email-based fraud.

The guide cannot determine whether a particular mailbox is compromised or approve a payment change. Those decisions require account logs, mailbox evidence, and your organization’s payment-verification process.

## Sources and further reading

- [FBI IC3: Business Email Compromise](https://www.ic3.gov/CrimeInfo/BEC)
- [FBI IC3 PSA: Business Email Compromise/Email Account Compromise](https://www.ic3.gov/PSA/2024/PSA240911)
- [FBI IC3 PSA: BEC/EAC scenarios and terminology](https://www.ic3.gov/PSA/2017/PSA170504)
- [FBI IC3 PSA: Cloud-based email-service exploitation](https://www.ic3.gov/PSA/2020/PSA200406)
- [FBI IC3 2025 Annual Report](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf)

## Frequently asked questions

### What is another name for a business email compromise?

Email Account Compromise, or EAC, is the alternative name paired with BEC in [IC3's 2024 public service announcement](https://www.ic3.gov/PSA/2024/PSA240911). IC3 previously described BEC as targeting businesses and EAC as the component targeting individuals who make wire transfers, then began tracking them as one crime type in 2017. IC3's 2025 annual-report definitions use "Business Email Compromise (BEC)" alone.

### What is a business email compromise?

A business email compromise is a scam that targets businesses and people performing transfers of funds. According to the [FBI IC3 BEC definition](https://www.ic3.gov/CrimeInfo/BEC), attackers frequently compromise legitimate business email accounts through social engineering or computer intrusion to cause an unauthorized transfer of funds.

### Is BEC the same as phishing?

No. IC3 tracks BEC and Phishing/Spoofing as separate crime types in its [2025 Annual Report](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf). A BEC operation may begin with phishing messages that collect information about a target, but phishing can also occur independently and does not necessarily involve a transfer-of-funds scam.

### What does a compromised email mean?

A compromised email account means an unauthorized party has gained access to the mailbox. The [IC3 cloud-email advisory](https://www.ic3.gov/PSA/2020/PSA200406) says attackers may examine messages for financial information, create rules to delete messages, enable external forwarding, and use address books to target additional people.

### Is CEO fraud another name for all BEC?

No. IC3 identifies "CEO Fraud" as an alternative name for a scenario in which a business executive receives or initiates a wire-transfer request. Other BEC scenarios involve supplier invoices, compromised correspondence, attorney impersonation, or data theft, so CEO fraud is narrower than BEC/EAC.
