Business email compromise, often shortened to BEC, is a category of fraud in which an attacker uses email to trick someone into sending money or sensitive information. The FBI's Internet Crime Complaint Center has repeatedly highlighted BEC as a high-loss form of cyber crime. Law firms are frequent targets because they hold client funds, handle closings and settlements, and communicate constantly with outside parties.
Most BEC attacks leave clues. This post covers what to look for, both in individual messages and in the mailbox itself.
Two flavors of BEC
Spoofing and lookalikes
The attacker sends a message from a fake address that resembles a real one, such as a domain with one letter changed, or uses a display name matching a partner or client. Nothing inside your systems has been breached.
Account takeover
The attacker actually logs into a real mailbox, often after stealing a password through phishing. From inside, they read conversations, learn who pays whom and when, and then insert themselves at the right moment. These attacks are harder to detect because the messages come from a legitimate account.
Message-level red flags
- A request to change payment instructions, especially close to a closing or disbursement
- Urgency, secrecy or reluctance to talk by phone
- A sender who suddenly cannot take calls, is "in a meeting" or "traveling"
- Slightly different email address, reply-to address or domain
- Tone or phrasing that differs from the person's normal style
- Requests for gift cards, payroll changes or W-2 style information
- Replies that ignore earlier questions in the thread
- Unexpected attachments or links to shared documents
None of these proves fraud. Together, they justify a phone call to a number you already have.
Mailbox-level red flags for IT and administrators
If an account has been taken over, the mailbox itself often shows evidence:
- New inbox rules, especially ones that forward mail externally, move messages to obscure folders such as RSS feeds, or mark messages as read. Attackers use these to hide their activity.
- Sign-ins from unusual locations or devices, or impossible travel between sign-ins.
- New multi-factor methods added to the account.
- Unexpected delegates or permission changes on mailboxes or calendars.
- Newly authorized third-party apps with access to mail.
- Sent items the user does not recognize.
- Large numbers of messages deleted around the time of a fraud attempt.
Ask your IT provider whether alerting is turned on for these events. Detection works best when it is automatic.
What to do the moment something looks wrong
- Stop. Do not send the payment or reply to the message.
- Verify by phone using a number from a trusted source.
- Report internally to IT and a partner, even if you are unsure.
- Preserve evidence. Do not delete the message. Forward it as an attachment to IT.
- If you suspect account compromise: reset the password, revoke active sessions, review inbox rules and MFA methods, and check for forwarding.
- If money has moved: call your bank's fraud department immediately, file a report with IC3 and notify your cyber insurance carrier per your policy.
Speed is critical, because recalls are most likely to succeed soon after the transfer.
Preventive controls
- MFA on all mailboxes, ideally phishing-resistant
- Alerts for new forwarding rules and unusual sign-ins
- Disabling legacy authentication
- External email banners and lookalike-domain protection
- SPF, DKIM and DMARC for your own domain, which helps prevent others from impersonating you
- Dual approval and call-back verification for payments
Training the humans
Give staff real examples, using anonymized or hypothetical messages, and rehearse the response steps. A paralegal who knows exactly whom to call in ninety seconds is a stronger control than any filter.
Client communication
If a compromise might expose client information, ABA Model Rule 1.4 addresses communicating with clients, and Formal Opinion 483 discusses obligations following a data breach. Consult your ethics counsel and confirm local notification rules with your state bar.
Where we can help
Counsel Cyber monitors for the mailbox warning signs above and helps firms respond quickly when something looks off. If you would like us to check your email configuration against these indicators, we can run a focused review.