Business Email Compromise
Overview
Robust and effective communication via emails is an integral part of a business’s operations. But it comes at a cost. A large number of email exchanges are often an optimal hunting ground for cyber attackers.
BEC or Business Email Compromise is a type of cyberattack involving multinational organizations. It targets email accounts of highly-ranked employees and executives by launching a phishing attack on the organization with the motive to steal money and sensitive data. Since MNC’s rely on wire transfers for operations, attackers spoof the email addresses and reroute the money to their own bank accounts.
Attackers start by building a target list often using a business’s contact database or by stalking LinkedIn profiles. They then launch phishing and spoofing campaigns pretending to be people of authority, such as the CEO or CFO, to convince the end-user. When trust is established, they steal data and money from the company and customer.
For detailed information, read more on What is DMARC?
EmailAuth provides free tools to validate and verify domains for DMARC, SPF and DKIM, and also generate new records. It completely automates the setup process for DMARC, making it easier to choose who is allowed to send an email on the specific domain’s behalf and keep track of that domain’s enforcement policies.
You can check your DMARC record using EmailAuth’s Record Checker.

BEC STATS
A report states that 17,607 attempts were made to implement a BEC scam in 2020 itself. A whopping $1.86 billion was lost due to BEC and EAC scams. In September 2020, it was revealed that 47.6% of all email traffic was spam. This could have been avoided had the companies or businesses complied with the DMARC norms while sending and receiving emails. If DMARC is implemented universally, businesses will stand to cut down on losses incurred due to these cyberattacks.
- BEC rose by 14% in 2020 and up to 80% in other sectors.
- In 2020, BEC costs increased from $54,000 in Q1 2020 to $80,183 in Q2.
- The energy and infrastructure sector topped the 2020 list with 93% of attacks.
- In 2020, 80% of firms experienced an increase in cyberattacks.
- 62% of BEC scams involve the cybercriminal asking for gift or money cards.
- The most common type of BEC scam is invoice fraud.
- The average amount requested in wire transfer-based BEC attacks almost doubled in 2020, from $48,000 in Q3 to $75,000 in Q4.

How Can DMARC Help?
DMARC (Domain-Based Message Authentication, Reporting, and Conformance) is an email authentication standard or protocol that determines whether an email is authentic or not. It relies on SPF and DKIM, two other protocols, to decide the authentication status of an email.
For detailed information, read more on What is DMARC?
DMARC is crucial when defending against BEC since it provides visibility of an email’s original source and not the source it claims to be from. An email sender trying to impersonate a reputed domain will be blocked if the recipient has DMARC already implemented. It is the only effective solution to ensuring that your employees, business partners, supply chains, or other end recipients do not get spoofed by an attacker using your domain.
You can set up DMARC on your domain using EmailAuth’s DMARC Record Generator. The EmailAuth dashboard completely automates the DMARC setup process, making it easier to choose who is allowed to send emails on your domain’s behalf and keep track of your enforcement policies. To monitor and verify your DMARC records, use EmailAuth’s DMARC Record Checker.
Apart from providing companies and organizations with email security and complete control of their email domains via DMARC, EmaiAuth has other pros. Head to Benefits of DMARC to read more about them.