
When Trust Becomes a Threat: Understanding Business Email Compromise in the AI Era
Most cyberattacks try to break in. Business Email Compromise does something more unsettling: it asks to be let in, politely, in the voice of someone you trust. There is no malware to detect, no suspicious link to block, often nothing technically wrong with the message at all. Just a request—to move money, change banking details, share sensitive files—that appears to come from a person you have no reason to doubt. BEC weaponizes the one thing every organization runs on and cannot function without: trust.
This is why it is so costly. According to the FBI’s IC3 2025 figures, Business Email Compromise caused $3.046 billion in losses across 24,768 complaints, an average of roughly $123,000 per incident. These are not opportunistic smash-and-grab attacks. They are patient, researched, and aimed squarely at the people authorized to approve transactions. And AI has just handed the attackers a dramatic upgrade.
An Attack That Exploits Hierarchy, Not Technology
To understand BEC, it helps to see that it is fundamentally a social attack wearing a technical costume. The classic scenario runs like this: an employee in finance receives an urgent email, apparently from a senior executive, asking them to process an immediate payment to a new account, perhaps for a confidential acquisition or a time-sensitive vendor settlement. The message is brief, authoritative, and stresses discretion and speed.
Every element is engineered to short-circuit judgment. The apparent sender is someone the employee would not casually question. The urgency removes time to reflect. The request for confidentiality discourages the very thing that would expose the fraud—checking with a colleague. The attacker is not exploiting a software vulnerability. They are exploiting organizational hierarchy, the natural human reluctance to challenge a superior, and the pressure of a busy workday.
This is also why technical defenses struggle against BEC. There is frequently no attachment to scan and no malicious link to flag. The email may even come from a genuinely compromised internal account, in which case it passes every authenticity check because it really is from inside the building. The fraud lives entirely in the meaning of the message, not its mechanics.
How AI Turbocharged the Con
For years, BEC had natural limits. Convincingly impersonating an executive took research and writing skill, and the cracks often showed—a phrase the CFO would never use, a tone that felt slightly off. AI has removed those limits and the cracks along with them.
Today’s attacker can feed an AI model an executive’s public communications, interviews, and posts, and generate messages that mirror their tone, vocabulary, and rhythm with eerie accuracy. The result reads exactly like the person it imitates. This sits within a broader surge—AI-driven scams rose 1,210% in 2025, with projected losses around $40 billion by 2027—and BEC is one of its most lucrative expressions, because it targets the people who can authorize the largest transfers.
The escalation goes further than text. Attackers now layer in synthetic voice and video to defeat the very act of verification. Vishing rose 442% in 2025, and 41% of organizations were hit by a deepfake combined with social engineering on an audio call, with 35% on a video call. The defining example is the engineering firm Arup, which lost $25 million in 2024 when an employee, seeking to confirm a suspicious instruction, joined a video conference with what appeared to be the CFO and colleagues—all of them deepfakes. The employee did the responsible thing and verified. The attack had simply faked the verification.
The Quiet Damage Beyond the Wire Transfer
It is easy to fixate on the headline number—the millions wired to a fraudulent account—but BEC inflicts damage well beyond the immediate loss, and leaders should weigh all of it.
The financial hit is the most visible layer. The IC3’s roughly $123,000 average per incident understates the tail risk; large, targeted attacks reach into the tens of millions, as Arup discovered. But the consequences extend further:
1. Regulatory exposure. If a BEC attack involves a breach of personal data, India’s DPDP Act requires that all breaches be reported, with penalties up to ₹250 crore for failing to maintain reasonable safeguards and ₹200 crore for failing to report.
2. Erosion of internal trust. A successful executive-impersonation attack makes people second-guess legitimate requests, introducing friction and suspicion into everyday operations.
3. Reputational harm. Customers, partners, and investors lose confidence when an organization is shown to have been deceived into handing over money or data.
The deepest irony is that BEC corrodes the trust it exploits. The whole point of internal trust is to let an organization move quickly without verifying everything. Once that trust is abused, the natural response is to verify everything—which is exactly the drag on operations the trust was meant to prevent.
Building Defenses That Assume the Message Looks Real
The strategic shift required against AI-era BEC is to stop relying on detecting fakes and start building processes that hold even when the request looks completely authentic. If you assume the email, the voice, and even the video can be convincingly forged—and in 2025 you must—then your defense cannot depend on spotting the forgery. It has to depend on the process around the request.
In practice, that means a few durable principles. High-risk actions—moving money, changing payment details, releasing sensitive data—should require verification through a second, independent channel, using a known contact method rather than the details in the suspicious message itself. Crucially, no one should be penalized or made to feel they are obstructing leadership for pausing to verify; the culture has to make verification a sign of diligence, not distrust. And these habits have to be practiced, not just published in a policy, because under real pressure people fall back on instinct rather than documents they skimmed once.
This is precisely where realistic simulation earns its keep. Practicing against convincing impersonation attempts—including the multi-channel and verification-defeating tactics attackers now use—builds the reflex to pause and confirm before acting. The employee who has navigated a realistic BEC scenario before is far more likely to apply the same composure when a real one lands at 4:55 on a Friday.
Make Verification the Habit, Not the Exception
Business Email Compromise is the purest example of why human risk now dominates the security conversation. It bypasses technology entirely and goes straight for trust, and AI has made the impersonation good enough to fool careful people who do everything right. The answer is not to abandon trust—an organization cannot run on suspicion—but to pair trust with verification habits strong enough to survive a perfect-looking lie.
Conclusion
Business Email Compromise does not break in; it asks to be let in, in the voice of someone you trust, with no malware or malicious link to detect. AI has removed the cracks that once gave impersonation away, extending the con into synthetic voice and video that can defeat the very act of verification. Because the message can now look and sound entirely real, defense has to rest on process rather than detection—requiring independent, second-channel verification for high-risk actions and a culture that treats pausing to check as diligence, not distrust. The next request to move money may look completely legitimate, which is precisely the point.
How Shieldbyte Infosec Can Help
Shieldbyte Infosec built ShieldPhish to turn “pause and verify” into a reflex across the teams attackers target most. The platform runs realistic simulations of executive-impersonation and BEC-style attacks—including the multi-channel and verification-defeating tactics now in use—so employees practice the habit of confirming high-risk requests through a known, independent channel before acting. In-the-moment coaching reinforces that instinct at the moment it matters, building composure that holds when a real request lands under pressure. A human risk score highlights which roles, such as finance and approvers, carry the most exposure, and adaptive training concentrates effort there. Reporting gives leadership clear visibility into how prepared the organization is to withstand a perfect-looking lie. The question worth answering before the next request arrives is whether your people would pause to check.

