Cyber Threats · 6 min read
Business Email Compromise: How the Attack Actually Works
Business email compromise begins with access to a mailbox, usually obtained through a credential phishing page or a session token stolen after a user approves an unexpected sign-in prompt. Once inside, the attacker rarely acts immediately.
They read. They learn which vendors invoice you, who approves payments, how your finance team phrases requests, and when key people travel. Mail rules are created to hide replies. Then a single, well-timed message asks for a payment detail change.
Effective defenses are unglamorous: phishing-resistant multifactor authentication, conditional access policies, alerting on mailbox rule creation and impossible-travel sign-ins, and an out-of-band verification procedure for any change to payment instructions.
If you suspect an active compromise, preserve logs before making changes. Sign-in and audit data has a limited retention window, and it is often the only record of what the attacker touched.
Want this reviewed in your environment?
A DarkBox assessment establishes what is actually in place before anyone recommends spending.
