# Business Email Compromise Attacks Keep Succeeding—And AI Is Making Them Harder to Detect


Business email compromise (BEC) has evolved into one of the most financially devastating cyber threats facing organizations worldwide. Unlike ransomware campaigns that announce their presence or data breaches that eventually surface in public disclosures, BEC attacks operate in plain sight—disguised as routine business communications from trusted colleagues, executives, and partners. The result: attackers successfully trick employees into authorizing fraudulent transfers, sharing sensitive data, or granting system access, often before anyone realizes what happened.


A forthcoming webinar on July 8, 2026, hosted by BleepingComputer will examine why these attacks remain so effective and how behavioral artificial intelligence is changing the detection landscape. The webinar, "Stop chasing alerts: Automating email security with behavioral AI," will feature Dan Nickolaisen, Solutions Architect Manager at Abnormal AI, and Eric Danneker, Director of Cyber Vigilance and Defense at Novant Health—two security leaders at the front lines of the BEC battle.


## The Threat: BEC's Shift From Malware to Social Engineering


Business email compromise attacks have fundamentally changed. The threats that dominated security headlines a decade ago relied on malicious attachments, suspicious links, or telltale signs of compromise. Modern BEC attacks are different.


Today's threat actors focus on impersonation over infection. They craft emails that appear to come from:


  • C-level executives requesting urgent wire transfers or employee personal information
  • Trusted vendors and partners asking for updated banking information or invoice verification
  • Colleagues and peers requesting access credentials or sensitive project files
  • HR departments collecting payroll or tax information

  • These emails arrive in employee inboxes alongside dozens of legitimate communications each day. They lack malicious attachments. They don't point to credential-harvesting pages. Instead, they exploit the most dangerous vulnerability in any organization: human trust.


    According to industry reports, BEC attacks have cost organizations billions of dollars annually. The FBI's Internet Crime Complaint Center (IC3) regularly ranks BEC among the costliest cyber threats, often surpassing losses from ransomware attacks in the categories where it occurs most frequently.


    ## Background and Context: Why Traditional Defenses Fail


    Email security has evolved significantly over the past two decades. Modern email systems employ:


  • Spam filters and malware detection engines that scan attachments and links
  • Authentication protocols (SPF, DKIM, DMARC) designed to prevent domain spoofing
  • URL rewriting and sandboxing that detonates suspicious links in isolated environments
  • Machine learning models trained to identify phishing patterns

  • Yet BEC attacks continue to bypass these defenses with alarming consistency. Here's why:


    Traditional security tools focus on technical indicators. They look for malicious code, forged headers, or suspicious domains. BEC attacks use legitimate infrastructure. An attacker impersonating a vendor might use a domain that's visually similar to the real vendor's (like vendorname-services.com instead of vendor-services.com), or they might compromise an actual vendor email account entirely.


    The attacks don't exploit software vulnerabilities. There's no zero-day to patch, no malware to quarantine. The vulnerability is social and behavioral—and no firewall can block human psychology.


    Volume overwhelms security teams. Security operations centers (SOCs) receive hundreds or thousands of alerts daily. Distinguishing a carefully crafted BEC email from routine business communication requires contextual understanding that automated systems struggle to provide.


    ## Technical Details: How Modern BEC Attacks Work


    A successful BEC attack typically follows this pattern:


    1. Reconnaissance: Attackers gather intelligence on company structure, executive names, vendor relationships, and communication patterns through public sources (LinkedIn, company websites, SEC filings) or previous breaches.


    2. Domain or Account Compromise: The attacker either registers a lookalike domain or compromises a legitimate business email account (through credential theft, password reuse, or phishing).


    3. Impersonation: Using the lookalike domain or compromised account, the attacker sends an urgent email requesting a wire transfer, employee data, or system access. The request is framed as time-sensitive ("before end of business today") to prevent verification.


    4. Social Engineering: The email leverages established relationships and business context. A finance team member might receive an email from what appears to be their CEO, referencing a recent acquisition or partnership they'd expect to exist.


    5. Execution: An employee, following normal business procedures, approves the transfer or shares the information. By the time verification occurs, money has moved or data has been exfiltrated.


    ### The AI Factor: Attackers' New Advantage


    Artificial intelligence is amplifying the threat. Generative AI models can now:


  • Generate convincing prose in the style of a specific executive or partner organization
  • Adapt tone and language to match expected communication patterns
  • Craft contextually relevant requests that fit organizational workflows
  • Scale campaigns to target hundreds of organizations simultaneously with personalized variations

  • This makes the attacker's job easier and the defender's job exponentially harder. Traditional email filters trained on phishing datasets now struggle to identify AI-generated impersonation that mimics legitimate business communication.


    ## Implications for Organizations


    The impact of BEC extends beyond financial loss:


    | Impact Area | Details |

    |-------------|---------|

    | Financial | Direct losses from fraudulent transfers, often unrecoverable after funds clear |

    | Operational | Time spent investigating compromised accounts and fraudulent communications |

    | Legal and Compliance | Regulatory reporting requirements, potential liability for inadequate email security |

    | Reputational | Damage to vendor relationships if a compromised account sends malicious emails to partners |

    | Organizational | Erosion of trust in email as a communication channel; increased skepticism of routine business requests |


    For finance teams, BEC attacks pose an acute risk. A single successful attack can result in six- or seven-figure losses before detection.


    For IT and security teams, BEC investigations consume resources disproportionate to their frequency. Validating whether an email is legitimate, investigating compromised accounts, and implementing incident response all require manual effort that could be redirected to strategic security initiatives.


    ## How Behavioral AI Changes the Detection Game


    The webinar will highlight an emerging approach: behavioral artificial intelligence that learns normal communication patterns and flags anomalies.


    Unlike signature-based detection, behavioral AI systems:


  • Establish baselines for how executives, departments, and teams typically communicate
  • Monitor deviations in sender behavior, recipient patterns, language, and requests
  • Correlate signals across the organization to identify coordinated impersonation campaigns
  • Automate investigation workflows to accelerate response before damage occurs

  • For example, a behavioral AI system might flag an email from a CEO to finance if:


  • The CEO rarely emails finance directly (communication pattern deviation)
  • The message requests an unusual wire transfer to a new vendor (behavioral anomaly)
  • The request uses language inconsistent with the CEO's typical communication style (linguistic drift)

  • This approach doesn't rely on malware signatures or malicious URLs—it relies on understanding what "normal" looks like for each organization and rapidly identifying when something doesn't fit.


    ## Recommendations for Organizations


    Organizations can strengthen their defenses against BEC attacks through a layered approach:


    1. Implement verification protocols for financial requests

  • Establish a secondary verification channel (phone call) for wire transfers above a certain threshold
  • Require out-of-band confirmation for sensitive requests from executives
  • Document and enforce these protocols across finance and operations teams

  • 2. Deploy behavioral email security

  • Implement systems that learn and monitor communication patterns
  • Enable automation for rapid response to detected anomalies
  • Integrate with email gateways and user awareness training

  • 3. Enhance authentication controls

  • Enforce multi-factor authentication (MFA) on all email accounts, especially executive and finance accounts
  • Monitor for suspicious login patterns that may indicate compromise
  • Implement conditional access policies that flag logins from unusual locations

  • 4. Invest in human-centered security

  • Train employees on BEC risks and common impersonation tactics
  • Establish a clear reporting mechanism for suspicious emails
  • Create a non-punitive culture where employees feel comfortable flagging concerns

  • 5. Improve email authentication

  • Implement DMARC with a strict policy (p=reject)
  • Enforce DKIM signing on all outbound emails
  • Monitor for domain lookalikes and register them proactively

  • 6. Establish vendor communication standards

  • Verify vendor email addresses before adding them to distribution lists
  • Request email changes through established vendor contacts via phone
  • Implement internal wikis or directories of verified vendor communication channels

  • ## HackWire Analysis


    BEC attacks persist not because defenses are weak—they persist because they exploit the fundamental architecture of trust that enables business to function. Any organization that conducts business via email faces this risk. The traditional security community's response—better spam filters, tighter authentication, more user training—has value but cannot fully solve a problem rooted in human psychology rather than technical flaws.


    The timing of this webinar matters. We're at an inflection point where generative AI has crossed a threshold: attackers can now scale impersonation attacks that were once labor-intensive. A single attacker can craft dozens of personalized BEC emails in minutes, each calibrated to a specific target organization's context. This asymmetry—where AI amplifies attacker capabilities faster than defenses can adapt—is the real story.


    The emergence of behavioral AI as a detection mechanism is promising, but it's not a silver bullet. It's a necessary evolution because traditional approaches are fundamentally reactive: they identify compromised accounts after fraud occurs or catch malware after it's deployed. Behavioral AI, by contrast, can detect the *anomaly itself*—the deviation from what's normal—before damage occurs.


    For defenders, the lesson is clear: monitoring *what people do* (their communication patterns, their requests, their behavioral signatures) is becoming more valuable than monitoring *what systems process* (malware, malicious URLs, forged headers). Organizations that invest in this shift will be better positioned to survive the BEC era. Those that don't will continue feeding this threat.


    HackWire Editorial


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)