Business Email Compromise

Business Email Compromise

Stop a CEO impersonation wire fraud.

What Is Business Email Compromise?

Business email compromise turns a routine payment request into fraud with no malware and no malicious link. An attacker impersonates an executive and uses urgency to push through a wire transfer, a vendor bank change, or a release of employee records. You'll work an urgent request that appears to come from your CEO: read the real header instead of the display name, spot the lookalike domain, and confirm the request on a channel the sender does not control before any money moves.

What You'll Learn in Business Email Compromise

Business Email Compromise — Training Steps

  1. Introduction

    Last week, Tessaly was acquired by Harwelde Industries, a multinational corporation. The merger has created a whirlwind of activity - new processes, unfamiliar systems, and countless emails from the parent company's various departments.

  2. The Chaos of Transition

    Alice's desk is cluttered with merger documents, and her inbox is overflowing with messages from Harwelde employees she's never met before. The transition has been overwhelming, with new vendor approvals, budget reconciliations, and urgent requests coming in hourly. She barely has time to process everything properly, let alone verify every single communication through official channels.

  3. The Deceptive Newsletter

    Alice notices a new email in her inbox from 'Harwelde Communications' with the subject line '[URGENT, FOR FINANCE MANAGERS] - New Partnership Announcement.' She clicks the email since the subject implies it's for her. The sender's email address appears to be news@harwelde-corp.net , which looks official enough given all the Harwelde domains she's been seeing lately.

  4. Clicking the Link

    Alice clicks on the link to read more about the new supplier partnership, thinking it's important to stay informed about parent company developments. The browser opens to what appears to be Harwelde's internal news portal, complete with company branding and recent merger-related articles.

  5. The Fake Portal

    The article discusses Harwelde's strategic partnership with 'Meridian Supply Solutions' and emphasizes the urgent need to establish payment channels for immediate project implementation. The website looks professional and contains other legitimate-seeming corporate news, making Alice believe this is genuine company information. What Alice doesn't realize is that this website is fake. By clicking the link, she has unknowingly validated her email address and confirmed she's actively reading communications that appear to be from Harwelde.

  6. The Urgent Financial Request

    Thirty minutes later, Alice receives another email - this time from the legitimate Harwelde email system.

  7. The Fatal Decision

    Against her better judgment, Alice decides to process the transfer. She reasons that the email came from a Harwelde Finance Manager, references the official partnership announcement, and carries an urgent business justification. With everything happening so quickly since the merger, she assumes this must be part of the new corporate procedures she hasn't been fully briefed on yet.

  8. Accessing Payment System

    Alice logs into Tessaly's financial portal and initiates a wire transfer for $85,000 to the bank account details provided in Michael Chen's email.

  9. Submitting The Transfer Details

    She feels a lingering sense of unease but pushes it aside, telling herself she was following instructions from the parent company's finance leadership.

  10. The Shocking Phone Call

    Answer the incoming phone call from CEO James Morrison.

Security Framework Coverage

MITRE ATT&CK

  • T1534 Internal Spearphishing
  • T1656 Impersonation

CIS Controls

  • CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind