Business Email Compromise — wire transfer controls, email authentication, financial process safeguards, and social engineering red flags. Based on FBI IC3 guidance and FinCEN advisories.
BEC causes more dollar losses than any other cybercrime category. The attack exploits process gaps, not technical vulnerabilities — controls must be procedural.
SPF and DKIM establish identity; DMARC enforces policy on mismatches. A domain without DMARC enforcement (p=none) is spoofable by anyone.
~all (softfail) initially, then -all (hardfail) once the full sending inventory is confirmed.p=none to collect reports, then p=quarantine, then p=reject. Use DMARC aggregate reports (rua=) to find legitimate sources before tightening policy.rua) show all sources sending as your domain. Forensic reports (ruf) include sample failing messages. Both are needed to catch unauthorized use.sp=reject in your DMARC record to apply enforcement to subdomains you don't use for email. Unprotected subdomains are common BEC spoofing targets.company-invoices.com or c0mpany.com. Use a domain monitoring service or periodic manual searches for common substitutions on your key domains.BEC relies on bypassing process controls by manufacturing urgency, authority, or trust. Train staff to recognize these patterns — and to treat them as reasons to slow down, not speed up.
vendor-corp.com instead of vendorcorp.com; character substitution