Back to all articles
Email Security12 min read
Business Email Compromise, How Attackers Get In and How M365 Can Stop Them
Business Email Compromise (BEC) is consistently the highest-value cybercrime category in Australia, with reported losses running into hundreds of millions of dollars annually. BEC is different from most cybercrime in that it often doesn’t require any technical exploit, just a convincingly written email and a moment of inattention.
How BEC Attacks Work
- •CEO fraud / executive impersonation: an email appearing to be from a senior executive requesting an urgent payment
- •Invoice fraud / vendor impersonation: advising that supplier bank details have changed
- •Payroll diversion: requesting a change to direct deposit details
- •Account compromise and lateral movement: attacking from within a compromised internal account
Why BEC Is So Effective
- •They exploit human psychology, not technical vulnerabilities
- •They often contain no malicious content: no malware, no links, no attachments
- •The financial transactions are hard to reverse
How Microsoft 365 Can Help
- •Multi-Factor Authentication (MFA): blocks over 99% of automated account compromise
- •Conditional Access Policies: block sign-ins from unexpected locations or devices
- •Anti-phishing with impersonation protection: ML-based detection in Defender for Office 365
- •External email tagging: display a warning banner on all emails from outside your organisation
- •DMARC, SPF, and DKIM: block spoofed emails at the receiving end
- •Alert policies: notify on unusual behaviour like mass forwarding or sign-ins from unusual locations
The Human Layer
A simple policy (any request to change bank details or make a payment outside normal processes must be verified by phone using a known number) eliminates a huge proportion of BEC risk. Attack Simulation Training in M365 Business Premium lets you test staff awareness with simulated campaigns.