How to Prevent and Contain Business Email Compromise

TL;DR
Enable multi-factor authentication across all accounts, disable external forwarding and legacy mailbox protocols, limit delegated access, and turn on mailbox auditing. If compromise occurs, reset passwords for affected accounts and every account reusing those passwords, revoke persistence by removing forwarding rules, review available logs and endpoint artifacts, and alert financial institutions to suspicious transactions.
Transcript
Hello, and welcome to this installment of our RSA Conference webcast series, The Surge of BEC Attacks and How to Mitigate Damages. I am your host, Britta Glade, director of content and curation for the RSA Conference team. As a reminder, this webcast is pre-recorded. Following the webcast, you will receive an email containing the link to the video ... Read More
Key Insights
- Business email compromise is an impersonation attack conducted through email, either with a forged sender address or unauthorized access to a legitimate account. A compromised real account can make fraudulent requests more convincing because the attacker can operate within trusted correspondence.
- Payment-authorized employees are common BEC targets because executives and finance personnel can initiate or approve wire transfers. Attackers may pursue more than money, including sensitive personal information, intellectual property, confidential emails, and business trade secrets found inside compromised mailboxes.
- Reconnaissance is a central part of sophisticated BEC attacks. Threat actors can study a victim's email habits, signatures, contacts, and active conversation threads, then imitate the sender or reply directly within an existing exchange to make fraudulent instructions appear credible.
- Credential theft can begin with a phishing email that directs a victim to a malicious link and captures an account name and password. If multi-factor authentication is not enabled, those credentials may give the attacker remote access to the mailbox.
- External forwarding rules can provide persistent email exfiltration because new messages are automatically sent to an attacker-controlled account. The attacker can continue monitoring conversations without repeatedly signing in, making centrally disabling external forwarding an important defensive control.
- Legacy mailbox protocols can increase exposure because enabled IMAP or POP3 connections may let an attacker download an entire mailbox and bypass multi-factor authentication. Organizations should disable these protocols unless they are absolutely necessary for legitimate business purposes.
- Mailbox auditing is essential for investigating suspicious activity because it records actions performed by users and administrators. If audit logging is not enabled before an incident, responders may have less evidence for determining what happened, when access occurred, and which actions were taken.
- A private investment organization remained compromised for at least six months before its bank flagged abnormal attempted transactions. Investigators found two compromised accounts and tens of thousands of forwarded emails, but no fraudulent transaction was completed because the bank notified the organization.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is business email compromise and how does it work?
Business email compromise is an attack in which a malicious actor impersonates a trusted individual through email. The attacker may forge the sender address or gain unauthorized access to a genuine account using stolen or guessed credentials. After studying the victim's correspondence and contacts, the attacker can request fraudulent payments, steal confidential information, or continue monitoring messages through forwarding rules.
Q: Who is most commonly targeted by BEC attacks?
BEC attacks commonly target employees who can make, approve, or authorize payments, including C-suite executives and members of finance departments. These roles are valuable because a convincing impersonation may produce an urgent fraudulent wire transfer. Attackers can also target other employees, clients, vendors, and contractors through lateral phishing to obtain additional accounts, information, or access.
Q: How does phishing lead to a business email compromise?
A typical BEC sequence begins when a target receives a phishing email, clicks a malicious link, and enters an account name and password. If multi-factor authentication is not enabled, the attacker may use those credentials for remote access. The attacker can then study the mailbox, target additional contacts, steal information, create forwarding rules, or prepare a fraudulent payment request.
Q: Why are email forwarding rules dangerous during a BEC attack?
Email forwarding rules are dangerous because they can automatically send incoming messages from a compromised mailbox to an attacker-controlled account. This gives the attacker continuing visibility into conversations and allows persistent information theft without repeated logins. Organizations should remove malicious rules during containment and disable forwarding to external domains centrally when external forwarding is not required for business operations.
Q: How can multi-factor authentication reduce BEC risk?
Multi-factor authentication reduces risk by adding another requirement beyond the account name and password. In the attack sequence described, stolen credentials could grant remote access when multi-factor authentication was absent. Enforcing it across the organization makes credential theft less likely to result in easy account access, although legacy mailbox protocols should also be disabled because they may permit attackers to bypass it.
Q: Why should organizations disable IMAP and POP3?
Organizations should disable IMAP and POP3 unless they are necessary because these legacy connection protocols can allow mailbox downloads and may enable an attacker to bypass multi-factor authentication. In the private investment case, both protocols were enabled by default. Their availability increased the risk that compromised accounts could expose complete mailboxes containing sensitive or confidential business information.
Q: What should an organization do after discovering compromised email accounts?
After discovering compromised accounts, the organization should reset their passwords and reset passwords for any other accounts that reused the same credentials. Responders should remove malicious forwarding rules, disable external forwarding through a centralized administrative platform, enforce multi-factor authentication, and disable unnecessary legacy protocols. Available email logs and forensic artifacts from affected endpoints should also be examined to identify the cause and scope.
Q: What did the private investment BEC case demonstrate?
The private investment case demonstrated how long a compromise can remain hidden and how much information forwarding rules can expose. The organization had at least six months of attacker dwell time, two compromised accounts, and tens of thousands of emails forwarded externally. Its bank detected abnormal attempted transactions and notified the organization, so no fraudulent transaction was completed, although private correspondence had already been disclosed.
Summary & Key Takeaways
-
Business email compromise begins when an attacker impersonates a trusted person through a forged sender address or unauthorized access to a real email account. Attackers commonly target executives and finance employees who can approve payments, but they may also seek personal information, intellectual property, confidential correspondence, or business trade secrets.
-
A typical attack starts with phishing and credential theft. Without multi-factor authentication, the stolen credentials can permit remote access. The attacker then studies messages, writing patterns, signatures, and existing conversations before requesting fraudulent payments, stealing information, targeting additional contacts, downloading mailboxes through legacy protocols, or creating external forwarding rules for persistent access.
-
Organizations can reduce exposure by enforcing multi-factor authentication, strong passwords, least-privilege access, limited mailbox delegation, disabled external forwarding, disabled legacy protocols, and mailbox auditing. After discovering an incident, responders should reset affected and reused passwords, remove malicious forwarding rules, centralize forwarding restrictions, examine available logs and endpoint artifacts, and investigate suspicious transactions promptly.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator