Blog · Fraud

Business Email Compromise in the AI Era

Business email compromise was already the most expensive category of corporate fraud before generative AI arrived. Now the same models that write clean marketing copy write flawless scam emails, mimic a specific executive's voice, and research a target company in minutes. This guide explains how business email compromise AI attacks work, why traditional email filters miss them, which finance workflows are most exposed, and the layered defense that still holds.

Executive summary

Business email compromise (BEC) is a fraud in which an attacker impersonates a trusted person — an executive, a supplier, a lawyer, a colleague — and manipulates an employee into moving money or changing where money is sent. It rarely involves malware. It succeeds by exploiting human trust and the ordinary gaps in finance processes. That is precisely why generative AI has made it so much more dangerous.

For years, the practical defense against BEC leaned on a comforting assumption: fraudulent messages tend to look wrong. They arrived with clumsy grammar, odd phrasing, mismatched branding, and a tone that did not sound like the person they claimed to be from. Alert employees learned to spot the tells. Generative AI erases those tells. A large language model produces grammatically perfect, on-brand, correctly localized text in any language, and can be prompted to imitate the writing style of a specific individual after ingesting a handful of that person's real emails. Voice-cloning models reproduce a named executive's voice from seconds of sample audio, so a follow-up "approval call" sounds authentic. The result is a scam that no longer looks or sounds like a scam.

This article is written for the people who own the risk: chief financial officers and treasurers, controllers and accounts-payable leaders, heads of procurement, and the security and risk executives who support them. It explains what BEC is and its main variants, how generative AI supercharges each stage of an attack, why secure email gateways were never designed to catch it, which financial workflows draw the most fire, and the layered, process-first defense that continues to work when the message itself can no longer be trusted. Where a control connects to a Deflected capability, we link to the relevant page so you can go deeper.

The one-sentence version

Generative AI removes the errors that used to expose business email compromise, so the only reliable defense is one that verifies the request and the workflow — out-of-band call-backs, dual authorization, payment controls, and synthetic-media detection — rather than trusting how convincing the message looks or sounds.

What business email compromise actually is

Business email compromise is a targeted social-engineering fraud that abuses the trust embedded in business communication. Instead of breaking through technical defenses, the attacker persuades a human being with legitimate authority — someone who can approve a payment, update a vendor record, or release data — to act on a fraudulent instruction. The instruction usually arrives by email, though it increasingly spans phone calls, text messages, and chat, and it is engineered to look like routine business.

Three features distinguish BEC from ordinary phishing and make it uniquely costly. First, it is targeted: the attacker studies a specific organization, its people, its suppliers, and its payment habits before sending anything. Second, it is payload-free: there is often no malicious link or attachment to detect, just plain, credible text. Third, it exploits authority and urgency: the request appears to come from someone senior or trusted and carries time pressure that discourages the recipient from pausing to verify.

A typical attack unfolds in recognizable stages. The attacker gathers open-source intelligence about the target — names, titles, reporting lines, supplier relationships, travel schedules, and the phrasing a company uses internally. They then establish a plausible channel, either by compromising a real mailbox through stolen credentials or by registering a look-alike domain that differs from the genuine one by a single character. Next comes the pretext: an urgent wire for a confidential deal, an updated invoice with new bank details, a payroll change requested by an employee. Finally, the payment is executed and the funds are rapidly moved through intermediary accounts, often before anyone realizes the request was fraudulent.

Why BEC is different from a malware breach

A malware breach leaves technical evidence: a suspicious binary, an unusual network connection, a signature an endpoint tool can match. BEC leaves almost none. The email is clean. The login, if a mailbox was compromised, may come from a plausible location using valid credentials. The wire transfer looks like thousands of legitimate wires. The fraud lives in the meaning of the message and the decision it induces, not in code — which is why it slips past defenses built to inspect infrastructure. Understanding this distinction is the foundation of every effective countermeasure that follows.

The main BEC variants

BEC is not a single scam but a family of them, unified by impersonation and differentiated by who the attacker pretends to be and which process they exploit. The four variants below account for the overwhelming majority of losses, and each is amplified in a distinct way by generative AI.

CEO fraud and executive impersonation

In CEO fraud, the attacker poses as a senior executive — often the chief executive or chief financial officer — and directs a subordinate in finance to make an urgent, confidential payment. The request leans hard on authority and secrecy: a time-sensitive acquisition, a regulatory settlement, a supplier that must be paid immediately to avoid disruption, all framed as something the employee should handle discreetly and not discuss with colleagues. The combination of a recognized name, apparent seniority, and manufactured urgency is designed to override the employee's normal instinct to verify. Executive impersonation is the variant most transformed by voice cloning, because a follow-up call in the executive's own voice appears to confirm the email.

Vendor and invoice fraud

Vendor fraud, sometimes called invoice fraud or vendor email compromise, targets the accounts-payable relationship between a company and its suppliers. The attacker impersonates a legitimate vendor — or compromises the vendor's actual mailbox — and submits an invoice or a request to update the supplier's bank details. Because the company genuinely owes the vendor money and expects invoices from them, the fraudulent instruction blends into normal operations. The redirected payment goes to an account the attacker controls, and the fraud may not surface until the real vendor asks why they have not been paid. This variant is especially damaging because it can persist across multiple invoices before anyone notices.

Payroll diversion

In payroll diversion, the attacker impersonates an employee and contacts human resources or payroll to change that employee's direct-deposit bank account. The request is modest, routine, and easy to grant — updating deposit details is an ordinary self-service task — which is exactly what makes it effective. On the next pay run, the employee's salary is deposited into the attacker's account. Individually these losses are smaller than a fraudulent wire, but they are simple to execute at scale, and a single successful change can be repeated across many employees in an organization that lacks a verification step for deposit changes.

Attorney and legal impersonation

Attorney impersonation exploits the confidentiality and pressure that surround legal matters. The attacker poses as a lawyer or law firm handling a sensitive, time-critical issue — a confidential acquisition, litigation settlement, or regulatory deadline — and pressures an employee to act quickly and quietly. The legal framing supplies both authority and a built-in reason for secrecy, discouraging the employee from consulting colleagues who might catch the fraud. These attacks are frequently timed to moments when an organization is genuinely engaged in deal activity, so the pretext aligns with real events the employee is aware of.

The common thread

Every BEC variant substitutes a trusted identity for a verification step. The scam works because the recipient treats a familiar name, voice, or relationship as proof of authenticity. Generative AI attacks that exact substitution — it manufactures the trusted identity more convincingly than ever, so any defense that still relies on recognition rather than verification is being defeated on purpose.

How generative AI supercharges BEC

Generative AI does not invent a new category of fraud; BEC predates it by years. What AI changes is the economics and the quality of every stage of the attack. Tasks that once required a fluent, patient, well-resourced human — writing a convincing email, sounding like a specific person on the phone, researching a target — are now fast, cheap, scalable, and nearly flawless. The following capabilities are the ones that matter most to a defender.

Flawless, localized phishing text

The single most reliable indicator of a scam used to be the writing itself: misspellings, broken grammar, and stilted phrasing that a native speaker or a careful colleague would never produce. Large language models eliminate that signal. They generate grammatically perfect, natural-sounding, correctly localized text in essentially any language, complete with the register and idiom appropriate to a corporate finance exchange. A message that would previously have exposed a non-native attacker now reads exactly like something a real executive or supplier would send. The awareness training that taught employees to "look for typos" has quietly lost most of its value.

Cloned writing style

Beyond correctness, generative models can imitate a particular person's voice on the page. Fed a sample of an executive's real emails — often obtainable from newsletters, public correspondence, prior threads on a compromised mailbox, or leaked data — a model can reproduce that person's characteristic greetings, sign-offs, sentence length, and turns of phrase. The fraudulent message does not merely avoid errors; it sounds like the specific human it claims to be from. For a recipient who knows the executive, this stylistic fidelity is a powerful and unfamiliar form of false confirmation.

Deepfake voice on approval calls

Many organizations added a sensible control after early BEC losses: for a large or unusual payment, call the requester and confirm verbally. Voice cloning is engineered to defeat exactly this step. From a short sample of a target's speech — a conference talk, an earnings call, a voicemail greeting, a social video — a model can synthesize that person's voice saying anything the attacker types, in some cases in real time. The employee places or receives the "confirmation call," hears the CFO's recognizable voice authorizing the transfer, and proceeds. The verification control the company trusted has been turned into the instrument of the fraud. We examine this attack surface in depth in our guide to deepfake and voice-clone fraud.

Faster, OSINT-driven targeting

Reconnaissance used to be the slow, manual part of a targeted scam. AI compresses it. Models can rapidly ingest and summarize open-source intelligence — organizational charts from professional networks, press releases about deals and leadership changes, supplier relationships disclosed in filings and case studies, and the personal details employees share publicly — and assemble a tailored profile of who to impersonate, who to target, what pretext will resonate, and when to strike. This lowers the effort required to run a highly personalized attack and lets a single operator pursue many targets in parallel with convincing specificity.

Real-time conversational chatbots

Traditional phishing was a single message; if the victim replied with a question, the attacker had to answer manually, and delays or awkward responses often broke the illusion. AI-driven chat changes this. A model can sustain a fluent, context-aware back-and-forth — answering the accounts-payable clerk's clarifying questions, adjusting the story on the fly, maintaining a consistent persona across a thread — without a skilled human present for every exchange. The scam becomes an interactive conversation that adapts to resistance, making it far harder for a hesitant employee to talk their way out of it.

Scale without loss of quality

Historically, attackers faced a trade-off: mass phishing was cheap but generic and easy to spot, while highly tailored spear-phishing was convincing but labor-intensive and therefore rare. Generative AI collapses that trade-off. It produces bespoke, individually tailored messages at the volume of a mass campaign. Every target can receive a message crafted for their role, their vendors, and their current projects, with no human bottleneck. For defenders, this means the assumption that "we are too small or too specific to be worth a tailored attack" no longer holds.

Why traditional email filters miss AI-era BEC

A frequent and dangerous assumption is that the enterprise email security stack — the secure email gateway, the spam filter, the malware sandbox — will catch BEC the way it catches other threats. It usually does not, and the reasons are structural rather than a matter of tuning.

There is no malicious payload to detect

Most email defenses are built to find and neutralize dangerous content: links to credential-harvesting sites, weaponized attachments, embedded malware. A BEC message typically contains none of this. It is plain, well-written text with a request. There is nothing to detonate in a sandbox, no URL to reputation-check, no file hash to match against a threat feed. The very thing that makes the message dangerous — its meaning — is invisible to controls that scan for known-bad artifacts.

The sender is often legitimate or nearly so

When an attacker compromises a real mailbox using stolen credentials, the fraudulent email originates from a genuine, trusted account and passes authentication checks such as SPF, DKIM, and DMARC because it truly is that domain sending it. When instead the attacker uses a look-alike domain, the difference from the real domain can be a single transposed or substituted character that a busy human skims past. Either way, the sender signals that email defenses rely on are satisfied or nearly satisfied, so the message is delivered as legitimate correspondence.

The linguistic tells are gone

Some filtering approaches attempt to flag the hallmarks of scam writing — urgency language, unusual phrasing, requests for secrecy. Generative AI produces text that is fluent, measured, and contextually appropriate, without the crude markers that heuristic filters key on. As the messages read more like genuine business communication, content-based detection loses much of its discriminating power, and the false-positive cost of tightening it rises.

The decisive events happen outside email

Perhaps most fundamentally, the loss in a BEC attack occurs in a financial workflow, not in the inbox. The email is only the trigger. The actual harm happens when a wire is approved, a vendor's bank details are changed, or a payroll deposit is redirected — actions that take place in banking portals, ERP systems, and payment platforms that the email gateway never sees. A control that inspects messages cannot govern a payment. This is why an email-only strategy is insufficient by design, and why the effective defenses described next live largely in process and in the systems where money actually moves.

What this means for defenders

Email filtering remains a worthwhile layer, but it is the wrong place to stake your defense against BEC. Treat inbound email as untrusted by default and move the decisive controls to where the money moves — verification, authorization, and payment governance — so that a convincing message can never, on its own, cause an irreversible transfer.

The finance, treasury, and AP workflows most at risk

BEC targets processes, not just people. The workflows most exposed share a common shape: they move money or redirect where money goes, they can be triggered by an inbound request, and they can be accelerated by urgency or authority. Mapping these workflows honestly is the first practical step toward defending them.

Wire transfers and treasury payments

High-value wire transfers are the marquee target because they are fast, often irreversible once sent, and capable of moving large sums in a single instruction. Treasury and finance functions that can initiate a same-day wire on the strength of an emailed or phoned request — particularly outside normal approval chains, framed as urgent or confidential — carry the greatest single-transaction exposure. The attacker's entire pretext is engineered to get one such wire released before anyone verifies it.

Accounts payable and vendor invoice processing

Accounts payable is a high-volume, routine function that processes many invoices from many suppliers, which is exactly what makes it vulnerable. A fraudulent invoice or a request to update a supplier's payment details blends into a stream of legitimate ones. Because the organization genuinely does business with the impersonated vendor and expects to pay them, the fraudulent instruction does not stand out, and the redirected funds may flow across several payment cycles before the discrepancy surfaces.

Vendor bank-detail changes

A specific and dangerous subset of AP risk is the change-of-bank-account request. Updating a supplier's banking details is an administrative task that, if performed without independent verification, silently reroutes every future payment to that vendor into an attacker-controlled account. A single unverified change can cause repeated losses, because each subsequent legitimate invoice is paid to the wrong destination. This workflow deserves its own hardened procedure separate from ordinary invoice handling.

Payroll and direct-deposit updates

Payroll direct-deposit changes are frequent, low-friction, and often self-service, which makes them an easy target for impersonation. An attacker posing as an employee asks HR or payroll to update deposit details, and the next salary run pays into the attacker's account. Individually modest, these losses scale readily and can recur until the affected employee reports a missing paycheck — by which point at least one pay cycle has already been diverted.

Deal-related and legal payments

Payments tied to mergers, acquisitions, real-estate closings, and litigation settlements combine large amounts, genuine urgency, and legitimate confidentiality. Attorney- and executive-impersonation scams are frequently timed to these events, because the secrecy the deal genuinely requires provides cover for the fraud and discourages the employee from the very cross-checking that would expose it. Any function that handles deal or escrow payments should treat inbound instructions during active transactions as elevated-risk by default.

New-vendor onboarding and one-off payments

Finally, the onboarding of a new supplier and the processing of unusual, one-off payments deserve attention. A brand-new payee has no established payment history against which to sanity-check a request, and a one-off payment lacks the recurring pattern that would make an anomaly visible. Attackers exploit these gaps precisely because the normal signals of "this looks different from before" are absent when there is no before.

A layered defense that still works

Because AI has neutralized the message-level tells that defenders once relied on, the effective response is to stop trusting the message and instead build defense into the process, the people, and the systems where money moves. No single control is sufficient. Together, the layers below create a posture in which even a flawless, deepfake-backed request cannot, by itself, cause an irreversible loss.

Out-of-band verification

The most important control against BEC is independent, out-of-band verification of any request to move money or change payment details. Before acting, the employee confirms the request through a separate, pre-established channel — a phone call to a number already on file for that person or vendor, not the number or reply address supplied in the request itself. The principle is simple and decisive: the request and its confirmation must travel over different channels, so that compromising one channel is not enough to complete the fraud. Critically, in an era of voice cloning, out-of-band verification should be paired with a challenge that a synthetic voice cannot easily satisfy, such as a pre-agreed verification phrase or a call-back to a known individual who can confirm context that an attacker would not possess.

Payment controls and dual authorization

Process controls in the payment systems themselves provide a hard backstop when human judgment is manipulated. The most valuable are:

  • Dual authorization — high-value payments, new payees, and bank-detail changes require approval by a second authorized person, so no single compromised or deceived individual can complete a transfer alone.
  • Separation of duties — the person who initiates a payment is not the person who approves or releases it, removing the single point of failure that BEC depends on.
  • Thresholds and holds — payments above defined amounts, or to newly added accounts, trigger additional review or a mandatory waiting period during which verification must complete.
  • Hardened change-of-bank procedures — any change to a vendor's or employee's banking details follows a dedicated, independently verified workflow rather than an ordinary email request.
  • Payee allow-listing and confirmation of payee — payments are restricted to verified accounts, and account-name matching is used to catch redirection to a mismatched destination.

These controls are powerful precisely because they do not depend on detecting the fraud. They assume a request may be fraudulent and make it structurally impossible for a single deceived action to cause an irreversible loss.

Deepfake and voice-clone detection

Because attackers now use synthetic voices to defeat call-back verification, detection of synthetic media has become a meaningful layer in high-trust workflows. Synthetic-media detection analyzes audio and video for the subtle artifacts that generative models leave behind — unnatural spectral patterns, inconsistent timing, and statistical signatures absent from genuine recordings — and flags suspected synthetic content before an approval is granted. This is the focus of Deflected's Deepfake & Voice-Clone Defense, which applies detection to wire approvals and other high-trust interactions so that a cloned voice on a confirmation call raises an alert rather than closing the deal. Detection is strongest as one layer inside a process that also enforces out-of-band verification and dual authorization; it strengthens human judgment rather than replacing it.

Employee awareness, updated for the AI era

Awareness remains essential, but its content must change. Training that teaches employees to look for typos and awkward grammar is now actively misleading, because AI-generated messages have neither. Modern BEC awareness should instead teach staff to:

  • Treat urgency, secrecy, and appeals to authority as risk signals in their own right, regardless of how polished or familiar the message is.
  • Understand that a recognizable voice on the phone is no longer proof of identity, and that a call can be cloned.
  • Follow the verification and authorization process every time, without exception, even when the request appears to come from a senior leader who is pressing for speed.
  • Know that no legitimate executive will penalize an employee for verifying a payment request through the proper channel — and that leadership explicitly endorses pausing to verify.
  • Report suspected attempts quickly, so the security team can warn others and act on an active campaign.

The goal is a culture in which verification is the default and the norm, not an act of insubordination against an apparently urgent boss. That cultural shift is often the difference between a near miss and a loss. For leadership teams, structured executive and staff education on AI-era threats helps set the tone from the top.

Monitoring and rapid response

The final layer assumes some attempts will get through and focuses on catching them fast. Effective monitoring includes watching for the signs of mailbox compromise — anomalous logins, newly created inbox rules that hide or auto-forward messages, unusual sending patterns — and for the financial anomalies that accompany BEC, such as first-time payees, sudden changes to established vendor accounts, and payments that deviate from historical patterns. Equally important is a rehearsed response plan: because fraudulent transfers can sometimes be recalled if the bank and authorities are notified quickly, the speed of detection and escalation directly affects whether funds can be recovered. Knowing in advance whom to call, how to freeze a payment, and how to preserve evidence turns a potential loss into a contained incident.

Defense in depth, made concrete

Assume the email is perfect. Assume the voice on the phone is real. A layered defense means that even under those assumptions, the money still cannot move: out-of-band verification catches the impersonation, dual authorization removes the single point of failure, deepfake detection flags the synthetic call, awareness keeps staff from being rushed, and monitoring shortens the window to recover if anything slips. The strength is in the combination, not any one control.

Encryption and the AI security layer

BEC defense is primarily a matter of process and human verification, but it sits within a broader security posture — and the systems that support anti-fraud controls, from verification records to monitoring data and case files, hold sensitive information that itself must be protected. Deflected treats that protection as a default rather than an add-on, and applies post-quantum cryptography across the platform so that the data underpinning fraud defense is safe against both present and future threats.

Concretely, the platform relies on the encryption standards finalized by the U.S. National Institute of Standards and Technology (NIST):

  • ML-KEM-1024 (NIST FIPS 203) for key encapsulation — securely exchanging keys at a high, quantum-resistant security level.
  • Hybrid X25519 + ML-KEM key exchange, which runs a proven classical algorithm alongside the post-quantum one, so protection holds even if either scheme is ever weakened.
  • AES-256 for symmetric encryption of data at rest and in transit.
FIPS 203
ML-KEM-1024 key encapsulation
Hybrid
X25519 + ML-KEM together
AES-256
Symmetric at rest & transit
Default
Across the whole platform

The relevance to BEC is indirect but real: an organization serious about fraud is also an organization whose sensitive records — payment histories, verification logs, vendor master data — are attractive to attackers and useful for building future pretexts. Protecting that data with post-quantum encryption denies attackers the raw material that makes the next impersonation more convincing, and ensures that long-lived financial data is not exposed to a future adversary who harvests encrypted traffic today to decrypt later.

Building a BEC-resilient program

Translating the layers above into an operating program is a matter of sequencing, not heroics. The following path lets a finance and security organization close the most exposed gaps first and mature the rest over time.

  1. Map the money-movement workflows. Inventory every process that can move funds or change where funds go — wires, AP, vendor bank changes, payroll updates, deal payments — and identify who can trigger each and what verification, if any, exists today.
  2. Harden the highest-value paths first. Apply out-of-band verification and dual authorization to high-value wires, new payees, and change-of-bank requests, since these carry the largest single-event losses.
  3. Rewrite the change-of-bank procedure. Give vendor and payroll bank-detail changes a dedicated, independently verified workflow, because a single unverified change causes recurring loss.
  4. Add synthetic-media detection to approval calls. Where verbal confirmation is part of the process, layer deepfake and voice-clone detection so a cloned voice raises an alert rather than granting approval.
  5. Retrain staff for AI-era tells. Replace "look for typos" guidance with training on urgency, authority, secrecy, cloned voices, and unconditional adherence to the verification process.
  6. Instrument monitoring and rehearse response. Watch for mailbox-compromise signals and financial anomalies, and rehearse the recall-and-escalation playbook so speed is on your side when an attempt succeeds.
  7. Review and adapt. Attacker tactics evolve with the models; revisit workflows, controls, and training on a regular cadence rather than treating the program as finished.

None of these steps depends on detecting a perfect message, which is the point. They assume the message may be flawless and the voice may be cloned, and they make the organization resilient anyway. That is the durable answer to business email compromise in the AI era: shift trust from how a request looks to how a request is verified, and build the controls that hold when appearances can no longer be believed.

Frequently asked questions

What is business email compromise in the AI era?
Business email compromise (BEC) is a social-engineering scam in which an attacker impersonates a trusted party — an executive, vendor, lawyer, or colleague — to trick an employee into wiring money, changing bank details, or releasing sensitive data. In the AI era, generative models let attackers write flawless, localized messages, mimic a specific person's writing style, produce a deepfake voice for approval calls, and research targets far faster, making these scams more convincing and harder to detect than the error-riddled phishing of the past.
How does AI make BEC harder to detect than traditional phishing?
Older phishing was often given away by spelling mistakes, awkward grammar, and generic wording. Generative AI removes those tells: it produces grammatically perfect text in any language, adapts tone to a specific sender by learning from real emails, and can generate a cloned voice or real-time chat responses that keep a conversation going. The message a victim receives looks and sounds like a genuine communication from a person they know, so the instinctive skepticism that used to flag a scam never triggers.
Why do secure email gateways and spam filters miss AI-enhanced BEC?
Email security tools are tuned to catch malicious links, attachments, malware, and known-bad senders. A BEC message frequently contains none of those — it is clean, well-written text sent from a compromised legitimate mailbox or a convincing look-alike domain. There is no payload to detonate and no signature to match. Because the attack targets human trust and business process rather than infrastructure, controls that inspect the channel rather than the intent and the workflow routinely let it through.
Which finance workflows are most exposed to AI-driven BEC?
The highest-risk workflows are those that move money or change where money goes: wire transfers and treasury payments, accounts payable and vendor invoice processing, vendor bank-detail changes, payroll direct-deposit updates, and lawyer- or executive-directed deal payments such as those around acquisitions. Any process where an urgent, senior, or authoritative request can accelerate a payment or bypass a normal check is a prime target for AI-enabled impersonation.
What is the most effective control against AI-enabled BEC and deepfake wire fraud?
Out-of-band verification combined with mandatory dual authorization. Before any high-value payment, new vendor bank details, or payroll change is executed, staff should independently confirm the request through a known, pre-verified contact method — never the number or reply address in the request itself — and a second authorized person should approve it. Layering synthetic-media detection, employee awareness, and monitoring on top of that process defeats the large majority of AI-enabled BEC, because it no longer matters how convincing the message or voice is.

Defend your payment workflows from AI-era fraud

Book a working session with our team. We'll map deepfake and BEC defenses to your finance, treasury, and AP processes — and show exactly where each layer fits.