ZeroFox Intelligence Brief - Social Engineering Series: Business Email Compromise
|by Alpha Team

ZeroFox Intelligence Brief - Social Engineering Series: Business Email Compromise
Product Serial: B-2024-04-11a
TLP:CLEAR
ZeroFox's Social Engineering series breaks down aspects of the threat into digestible reports and outlines defensive actions that can be taken to combat it. Part Five of this series takes a deep dive into Business Email Compromise (BEC), why and how threat actors do it, and how the threat can best be mitigated.
Standing Intelligence Requirements
Social Engineering, Phishing, BEC
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- BEC is a high-effort phishing technique in which a threat actor targets the legitimate email addresses of organizations and individuals, tricking users into providing sensitive information which can lead to monetary theft or enable further malicious activity.
- Reporting suggests that BEC attacks are on a sharp upward trajectory, which is very likely due in part to their relatively high success rates and payoff in comparison to other methods of cyberattack.
- BEC is almost certain to remain a pertinent threat to organizations across industries in 2024, as threat actors continue to capitalize upon established techniques, high success rates, and constantly increasing financial payoffs.
Tags: tlp:clear, phishing & fraud