Attack combining email identity spoofing and manipulation to obtain a fraudulent wire transfer, straddling the boundary between cyber cover and conventional fraud cover.
Business Email Compromise (BEC) is a category of attack in which a malicious actor spoofs or compromises the email account of an executive, supplier or partner to send fraudulent instructions, typically a wire-transfer order to an account controlled by the attacker. In France, the term Faux Ordre de Virement (FOVI) is used when the fraud specifically targets a company's finance teams by impersonating an executive or supplier. BEC differs from ordinary phishing in the absence of a visible technical exploit: the attacker relies on the credibility of the spoofed identity and the urgency of the request to bypass standard controls. Techniques include header spoofing without actual account compromise, genuine account compromise, and increasingly voice or video deepfake to simulate a conversation with the executive. For insurance, qualifying a BEC loss is delicate as it sits at the boundary between cyber cover (computer compromise) and conventional fraud cover (manipulation without intrusion). Both covers may coexist in a contract but with different definitions and sub-limits, hence the importance of carefully reading the specific conditions.
A CFO at a mid-sized company receives an email apparently sent by the CEO, urgently requesting a 480,000-euro transfer to finalize a confidential acquisition. The transfer is executed. Analysis reveals the email came from a lookalike domain, without compromising the CEO's account. The cyber fraud cover covers the act, but with a sub-limit of 200,000 euros leaving 280,000 euros at the insured's expense.
BEC, Business Email Compromise, FOVI, faux ordre de virement, fraude au virement