# What is a different name used for business email compromise?

> Business email compromise (BEC) is also called email account compromise (EAC), the FBI's term pairing for this scam category, per its official guidance.

The FBI's official guidance says business email compromise (BEC) is "also known as email account compromise (EAC)." Both terms cover the same scam category: a criminal impersonates or takes over a trusted email account to redirect a legitimate transfer of money or data. Security vendors also use "CEO fraud" for the narrower pattern where the impersonated sender is a company executive, but EAC is the term federal reporting groups pair directly with BEC.

## Quick takeaways

- The FBI's business email compromise page states BEC is "also known as email account compromise (EAC)."
- The FBI's Internet Crime Complaint Center (IC3) uses the combined heading "Business Email Compromise/Email Account Compromise (BEC)" in its 2024 scam report.
- "CEO fraud" is a narrower, vendor-defined term for the executive-impersonation subtype of BEC, not a synonym for the whole category.
- IC3 recorded $55,499,915,582 in total exposed BEC/EAC losses across 305,033 domestic and international incidents in the period its September 2024 report covers.
- EAC typically describes a case where the criminal had real access to the mailbox, not just a look-alike address.
- Liability for a BEC loss is decided case by case under state adoptions of UCC Article 4A, not by one federal rule.

## Why the FBI pairs two names for one scam

The [FBI's public guidance on business email compromise](https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-frauds-and-scams/business-email-compromise) states: "In a BEC scam, also known as email account compromise (EAC), criminals send an email message that appears to come from a known source making a legitimate request." The two labels sit on one mechanism because a BEC scam can happen in two different ways.

In the first pattern, a criminal spoofs an address or domain that looks like a trusted sender's without ever touching the real account. In the second, a criminal actually gains control of the real account, through phishing, credential theft, or malware, and sends the fraudulent message from inside it. The [FBI's Internet Crime Complaint Center](https://www.ic3.gov/CrimeInfo/BEC) defines the underlying crime as one "frequently carried out when a subject compromises legitimate business e-mail accounts through social engineering or computer intrusion techniques resulting in an unauthorized transfer of funds." IC3's September 2024 public service announcement uses the combined heading ["Business Email Compromise/Email Account Compromise (BEC)"](https://www.ic3.gov/PSA/2024/PSA240911), treating them as one reporting category rather than two separate crime types. BEC sits inside a wider set of impersonation-based [email threats](/learning/threats) that all rely on the reader trusting a familiar sender.

EAC works as a companion label, not a competing one: it names which of the two mechanisms produced the fraudulent message.

## When a different term applies

Not every BEC-adjacent term means the same thing. [KnowBe4 defines CEO fraud](https://www.knowbe4.com/ceo-fraud) narrowly, as "a phishing attack where cybercriminals spoof executive email accounts to fool employees into giving away sensitive information." That definition covers only the subset of BEC scams where the impersonated sender holds an executive title. It does not cover the vendor-invoice or title-company patterns the FBI lists as BEC examples, where no executive is impersonated at all. For how a spoofed BEC message compares with a broader phishing attempt, see [business email compromise vs. phishing](/learning/business-email-compromise-vs-phishing).

Use EAC when the evidence points to real account access: sent-item history the owner did not create, a login from an unrecognized location, or a mail forwarding rule the owner never set up. Use BEC as the umbrella term whenever the mechanism has not been established yet, since every EAC incident is also a BEC incident, but not every BEC incident involves an actual account takeover.

## What the three BEC patterns FBI cites look like

The [FBI's BEC page](https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-frauds-and-scams/business-email-compromise) lists three confirmed patterns from real victims:

- A vendor a company regularly deals with sends an invoice listing an updated mailing or payment address.
- A company CEO asks an assistant to buy gift cards for employee rewards and to send back the card serial numbers by email.
- A homebuyer receives a message that appears to come from a title company, with wire instructions for a down payment.

In every case the FBI cites, the message looked legitimate and the funds went to the criminal instead of the real recipient. Only one of the three involves an executive, which is why "CEO fraud" cannot stand in for the whole BEC category.

![Table naming business email compromise, its federal alternate name, and a narrower vendor term, with the source and scope of each](/images/editorial/what-is-a-different-name-used-for-business-email-compromise/what-is-a-different-name-used-for-business-email-compromise-records.webp "1200x533")

*Source: Palisade.*

For a single line that captures the mechanism and the name together, use this record:

```text
Business Email Compromise (BEC), also known as Email Account Compromise (EAC):
a scam in which a criminal impersonates or takes over a trusted email account
to redirect a legitimate transfer of funds or data to an account the criminal controls.
```

## What to check after a suspected BEC message

If a message matches one of the FBI's patterns, first work out which mechanism produced it. Compare the full sender address, not just the display name, against your organization's known contact for that vendor, executive, or title company. Check whether the sending domain passed SPF and DKIM, and whether the mailbox sits on infrastructure your organization controls. A pass on both, combined with unfamiliar login activity or a forwarding rule the mailbox owner did not set, points toward EAC rather than a simple look-alike spoof.

An authenticated sending domain makes it harder for a criminal to send a message that appears to come directly from your exact domain, but it does nothing against a look-alike domain or a genuinely compromised mailbox. For the financial and operational impact one successful message can cause, see [how business email compromise threatens a business](/learning/how-does-business-email-compromise-bec-threaten-your-business).

## Check your domain's exposure to a look-alike BEC message

The FBI's examples above all depend on the reader trusting a familiar-looking sender. Run your sending domain through Palisade's checker to see whether SPF, DKIM, and DMARC are published and aligned, which is one part of a wider [email security](/learning/email-security) posture that makes exact-domain spoofing harder.

[Check your domain's security posture](/tools/email-security-score)

A domain security score cannot detect a mailbox that has already been taken over, confirm that a specific email you received is fraudulent, or stop a look-alike domain that only resembles yours.

## Sources and further reading

- [FBI: Business Email Compromise](https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-frauds-and-scams/business-email-compromise)
- [FBI IC3: BEC (Internet Crime Complaint Center)](https://www.ic3.gov/CrimeInfo/BEC)
- [FBI IC3 PSA240911: Business Email Compromise: The $55 Billion Scam](https://www.ic3.gov/PSA/2024/PSA240911)
- [KnowBe4: CEO Fraud Attacks](https://www.knowbe4.com/ceo-fraud)
- [Holland & Knight: Fourth Circuit Limits Beneficiary Bank Liability in BEC Schemes](https://www.hklaw.com/en/insights/publications/2025/04/fourth-circuit-limits-beneficiary-bank-liability-in-bec-schemes)

## Frequently asked questions

### What are examples of business email compromise?

The FBI cites three confirmed patterns: a vendor invoice that lists a changed payment address, a company executive asking an assistant to buy gift cards and email back the serial numbers, and a homebuyer receiving fake wire instructions from what looks like a title company. In each case the message looked legitimate and the requested funds went to the criminal instead of the real recipient.

### What is a red flag for a business email compromise?

A red flag is an unsolicited request to change account, payment, or wire details, especially one that pressures the recipient to act quickly and skip verification. The FBI's guidance also points to slight misspellings in a sender's email address or a linked URL, and any payment request delivered only by email that discourages a phone call to confirm it.

### Who is liable for business email compromise?

Not one uniform answer applies. When a BEC scam results in a wire or ACH transfer, U.S. courts generally apply their state's version of UCC Article 4A to decide which party absorbs the loss. A 2025 Fourth Circuit ruling in Studco Building Systems US, LLC v. 1st Advantage Credit Union held that a beneficiary bank is not liable for accepting a misdirected transfer unless a bank employee had actual, provable knowledge of the fraud, not merely information the bank "should have" pieced together. Because BEC liability turns on the specific facts, the account agreement, and the applicable state law, a business that loses funds to a BEC scam should get its own legal counsel rather than assume a default outcome.

### What is the difference between business email compromise and email account compromise?

The FBI's Internet Crime Complaint Center does not treat business email compromise and email account compromise as two different scams. Its own reporting pairs them under one heading, "Business Email Compromise/Email Account Compromise (BEC)," and uses EAC to describe the subset of cases where the criminal gained real access to the victim's mailbox rather than only sending a look-alike message. Every EAC incident is also a BEC incident under this framing; not every BEC incident involves an actual account takeover.
