<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US">
	<id>https://www.insurerbrain.com/w/index.php?action=history&amp;feed=atom&amp;title=Definition%3ABusiness_email_compromise_%28BEC%29</id>
	<title>Definition:Business email compromise (BEC) - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.insurerbrain.com/w/index.php?action=history&amp;feed=atom&amp;title=Definition%3ABusiness_email_compromise_%28BEC%29"/>
	<link rel="alternate" type="text/html" href="https://www.insurerbrain.com/w/index.php?title=Definition:Business_email_compromise_(BEC)&amp;action=history"/>
	<updated>2026-06-14T09:57:35Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://www.insurerbrain.com/w/index.php?title=Definition:Business_email_compromise_(BEC)&amp;diff=6716&amp;oldid=prev</id>
		<title>PlumBot: Bot: Creating new article from JSON</title>
		<link rel="alternate" type="text/html" href="https://www.insurerbrain.com/w/index.php?title=Definition:Business_email_compromise_(BEC)&amp;diff=6716&amp;oldid=prev"/>
		<updated>2026-03-10T04:42:40Z</updated>

		<summary type="html">&lt;p&gt;Bot: Creating new article from JSON&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;📧 &amp;#039;&amp;#039;&amp;#039;Business email compromise (BEC)&amp;#039;&amp;#039;&amp;#039; is a form of [[Definition:Social engineering | social engineering]] fraud in which an attacker impersonates a trusted party — a CEO, vendor, or business partner — through manipulated or spoofed email to trick an employee into transferring funds, diverting payments, or disclosing sensitive information. Within the [[Definition:Cyber insurance | cyber insurance]] market, BEC ranks among the most frequent and costly causes of [[Definition:Claim | claims]], often exceeding [[Definition:Ransomware | ransomware]] in aggregate [[Definition:Loss | loss]] dollars because the attacks are simple to execute and notoriously difficult to detect before money has left the victim&amp;#039;s account.&lt;br /&gt;
&lt;br /&gt;
⚙️ A typical BEC attack begins with reconnaissance: the threat actor studies an organization&amp;#039;s email patterns, identifies key personnel, and either compromises a legitimate email account through [[Definition:Phishing | phishing]] or registers a look-alike domain. The attacker then sends an urgent, convincing message — often referencing a real transaction in progress — directing the recipient to wire funds to a fraudulent account. Because the fraud relies on human behavior rather than malware, traditional [[Definition:Cybersecurity | cybersecurity]] tools may not flag it. [[Definition:Cyber insurance | Cyber policies]] typically cover BEC under [[Definition:Social engineering coverage | social engineering]] or [[Definition:Funds transfer fraud | funds transfer fraud]] endorsements, though coverage limits, sub-limits, and verification-procedure requirements vary significantly among [[Definition:Insurance carrier | carriers]]. Some [[Definition:Crime insurance | crime insurance]] and [[Definition:Fidelity bond | fidelity]] products also respond to BEC losses, creating potential overlaps that require careful policy coordination.&lt;br /&gt;
&lt;br /&gt;
🔍 For [[Definition:Underwriter | underwriters]], BEC exposure is a key variable in [[Definition:Cyber risk | cyber risk]] assessment. During the [[Definition:Application | application]] and [[Definition:Underwriting | underwriting]] process, carriers routinely ask about multi-factor authentication on email accounts, dual-authorization procedures for wire transfers, and employee training programs — controls that materially reduce BEC frequency. The FBI&amp;#039;s Internet Crime Complaint Center has reported BEC losses in the billions of dollars annually, and that trajectory keeps the peril at the center of [[Definition:Pricing | pricing]] and [[Definition:Loss ratio (L/R) | loss ratio]] discussions across the cyber insurance market. As attackers refine tactics using generative [[Definition:Artificial intelligence (AI) | AI]] to craft more convincing messages, the interplay between BEC prevention and insurance coverage will only intensify.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Related concepts&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
{{Div col|colwidth=20em}}&lt;br /&gt;
* [[Definition:Cyber insurance]]&lt;br /&gt;
* [[Definition:Social engineering coverage]]&lt;br /&gt;
* [[Definition:Funds transfer fraud]]&lt;br /&gt;
* [[Definition:Phishing]]&lt;br /&gt;
* [[Definition:Crime insurance]]&lt;br /&gt;
* [[Definition:Ransomware]]&lt;br /&gt;
{{Div col end}}&lt;/div&gt;</summary>
		<author><name>PlumBot</name></author>
	</entry>
</feed>