Skip to primary navigation Skip to content Skip to footer

Determine And Investigate Service Email Compromise (bec) Scams Official

Detecting a BEC attempt requires looking for psychological and technical anomalies:

: A sudden request to change payment instructions or bank account details for a known vendor is a major indicator. Detecting a BEC attempt requires looking for psychological

: Requests that deviate from standard business procedures, such as a CEO asking an assistant to buy gift cards, are common lures. Investigating a Suspected Incident Detecting a BEC attempt requires looking for psychological

: Attackers use "lookalike" domains (e.g., company-inc.com instead of companyinc.com ) or spoofed display names to appear legitimate. Detecting a BEC attempt requires looking for psychological

If a BEC attack is suspected, investigators follow a technical workflow to determine the scope: Business Email Compromise - FBI

: Scams often use high-pressure language (e.g., "urgent," "strictly confidential") to force quick action without verification.