An email scam impersonating an executive or a supplier to obtain a fraudulent transfer, with no malware involved.
Business email compromise, of which the so-called CEO fraud is the emblematic case, is a scam that relies on social engineering rather than on technique. By email, the attacker impersonates an executive, a supplier or a trusted partner, and persuades an employee to make an urgent, confidential transfer to an account they control. No sophisticated intrusion is required, the weapon being manipulation that plays on authority, urgency and secrecy. It is precisely this simplicity that makes it so widespread and so costly, the worldwide harm running into billions according to US authorities. For cyber insurance, business email compromise occupies an ambiguous place, because it belongs as much to financial fraud as to information security. It is frequently subject to a specific sub-limit, or even to an exclusion where the insurer considers it falls under a separate crime cover. The best defense is not technical but organizational, namely procedures for the dual validation of transfers and verification through a second channel, which underwriting questionnaires now scrutinize carefully.
The accountant of an SME receives an email apparently signed by the executive, who is traveling, asking them to settle urgently and in full confidence a secret acquisition. The transfer of several hundred thousand euros leaves for a foreign account before the deception is discovered.
BEC, business email compromise, fraude au virement, arnaque au président, CEO fraud, Compromission de messagerie professionnelle (BEC)