Last materially reviewed: September 3, 2026
Direct Answer
Business email compromise (BEC) is a targeted fraud in which attackers impersonate or take over a legitimate business email account to trick employees, suppliers or customers into sending money, credentials or sensitive information. Philippine businesses should treat unusual payment instructions, bank-account changes, urgent executive requests and supplier invoice changes as high-risk events that require independent verification.
Key Takeaways
- BEC often looks like a normal business email rather than an obvious malware attack.
- Attackers may spoof an executive, supplier, finance employee or trusted partner.
- Payment changes should be verified through a separate trusted channel before funds are released.
- MFA, secure email settings, least-privilege access and staff training reduce the risk.
- If money was sent, contact the bank immediately, preserve evidence and report the incident.
Jump to a Section
- What is BEC?
- Warning signs
- Prevention controls
- What to do after a BEC incident
- Data privacy implications
- FAQs
What Is Business Email Compromise?
BEC is a social-engineering attack built around trust. Instead of simply sending a generic phishing email, the attacker studies the organization, identifies people who can authorize payments or access information, and creates a message that appears to fit normal business activity.
The Bangko Sentral ng Pilipinas has described BEC as a costly cyberattack in which seemingly legitimate email accounts are used to trick employees into giving credentials, money, personal information or financial details. BSP has also recommended layered email-security controls for supervised financial institutions.
Common BEC Warning Signs
- A supplier suddenly asks to change its bank account.
- An executive requests an urgent confidential payment outside the normal approval process.
- The sender address differs slightly from the legitimate domain.
- The message pressures the recipient not to call or verify.
- An employee asks for payroll or account details to be changed unexpectedly.
- A familiar email thread contains an unusual attachment, link or payment instruction.
- The request arrives just before a deadline, holiday, trip or executive absence.
How Philippine Businesses Can Prevent BEC
1. Require out-of-band verification for payment changes
Never approve a new bank account or payment destination solely from an email. Call the supplier or executive using a previously verified number, not a number contained in the suspicious message.
2. Use multi-factor authentication
MFA helps prevent an attacker from taking over an account even when a password has been stolen. See the Cybercode MFA guide.
3. Protect business email accounts
Use unique passwords, remove unused accounts, restrict administrative privileges, review forwarding rules and monitor unusual logins. For password controls, see the Password Security Guide.
4. Use a two-person payment process
High-value transfers and supplier-account changes should require a second approver. The goal is to make one compromised inbox insufficient to move money.
5. Train finance, HR and executive assistants
These roles are frequent targets because they can move money, change payroll records or access sensitive information. Use the Employee Phishing Awareness Guide as a training baseline.
6. Configure email authentication and filtering
Organizations should work with their email provider or IT team to implement appropriate anti-spoofing, spam filtering and domain-authentication controls such as SPF, DKIM and DMARC where applicable.
What to Do After a BEC Incident
- Stop further payments. Alert finance and management immediately.
- Contact the receiving and sending banks. If a transfer was made, request an urgent fraud review or hold.
- Secure the affected mailbox. Reset credentials, revoke sessions, enable or reconfigure MFA and inspect forwarding rules.
- Preserve evidence. Keep original emails, headers, screenshots, payment records, call logs and timestamps.
- Check other accounts. Determine whether the attacker accessed cloud storage, payment systems or other business tools.
- Report the cybercrime. Use the Cybercrime Reporting Directory for NBI, PNP and other relevant channels.
- Review whether personal data was exposed. If the incident involves personal data, assess obligations under the Data Privacy Act and NPC breach rules.
Data Privacy Implications
A compromised mailbox may contain customer, employee or supplier personal data. Under Philippine data-protection rules, a security incident can become a personal data breach when it results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to personal data. Organizations should follow their security-incident management process and assess whether notification obligations are triggered.
See the Data Breach Notification Philippines guide and Data Breach Response Checklist.
Frequently Asked Questions
Is BEC the same as phishing?
BEC is a form of social engineering that often uses phishing techniques, but it is usually more targeted and focused on business payments, credentials or sensitive information.
Should a company reimburse a customer or supplier after BEC?
Liability depends on the contract, facts, payment process, negligence, authentication controls and applicable law. Preserve the evidence and obtain legal advice for disputed or high-value losses.
What is the fastest control to implement?
Require independent verification of every new bank account or payment change. This procedural control can stop a BEC payment even if an email account has already been compromised.
Related Cybercode Guides
- What to Do If You Clicked a Phishing Link
- How to Know If Your Phone or Account Has Been Hacked
- Cybersecurity Checklist for Philippine Businesses
- Cyber Incident Response Checklist
