Business email compromise (“BEC”) attacks are one of the most significant cyber threats facing companies today, and the latest federal data show that the problem is intensifying. In its 2025 Internet Crime Report, the FBI’s Internet Crime Complaint Center (“IC3”) reported that BEC alone accounted for 24,768 complaints and $3.047 billion in reported losses and was second only to investment fraud among cyber-enabled fraud categories by loss. Phishing and spoofing remained the most frequently reported crime type, with 191,561 complaints, and IC3’s new AI-related descriptor captured 22,364 complaints and $893 million in losses, reflecting the growing role of generative AI and impersonation tooling in social-engineering attacks.
Insurance and incident-response data reinforce the same point. Coalition’s 2025 Cyber Claims Report found that BEC and funds transfer fraud accounted for 60% of total claims in 2024 and that nearly 30% of BEC incidents escalated to funds transfer fraud.
Given the financial and reputational risks at stake, companies should consider preventive measures to avoid a BEC and to otherwise prevail if a BEC happens and litigation ensues. In this blog post, we provide practical guidance for businesses concerning common BEC schemes, mitigation strategies, the BEC litigation landscape, and effective strategies for dispute resolution and recovery.
Common BEC Schemes
BEC schemes can vary, but they generally seek to exploit routine business processes and fall into two broad categories: those involving spoofed email accounts—where attackers create addresses that closely resemble legitimate ones—and those involving hacked email accounts. In spoofing cases, the attacker never actually gains access to a legitimate mailbox but instead relies on visual deception such as look-alike domains. In a hacked account scenario, the attacker compromises a real email account, allowing them to read prior correspondence (often over extended periods), insert themselves into ongoing conversations, and send highly convincing fraudulent messages.
BEC attacks are also increasingly sophisticated, involving advanced tactics such as real-time voice or video deepfakes requesting wire transfers, AI-generated phishing emails, spoofed phone calls, QR-code and CAPTCHA-based credential-harvesting pages, and the abuse of compromised SaaS or email accounts to add credibility to fraudulent requests.
Attackers often execute the following BEC schemes:
- Senior executive fraud. An attacker impersonates a senior executive, board member, or deal principal through spoofing, a hacked account, or a voice/video deepfake to instruct an employee to make an urgent, confidential payment.
- Vendor payment redirection. A compromised vendor account, look-alike domain, or fake vendor portal is used to send altered bank details for invoice settlement, diverting substantial payments in commercial supply or service contracts to the attacker.
- M&A transaction interception. During sensitive deal negotiations or closings, attackers compromise or spoof a banker’s, lawyer’s, escrow agent’s, or counterparty’s email account to insert fraudulent payment instructions for deposits, purchase-price payments, advisory fees, or escrow transfers.
- Payroll and benefits diversion. HR, payroll, or benefits personnel receive fraudulent instructions—often from a hacked employee account or a spoofed benefits vendor—to change direct-deposit, tax, or reimbursement information, routing funds to the attacker.
To facilitate these schemes, attackers do not limit their actions to emails. They convincingly call the target using area codes in the same area as the company they are impersonating. They also monitor the target’s messages about missed calls and return those calls, thereby getting around a common defensive tactic of relying on a confirming phone call.
Strategies for Mitigating BEC Risk
BEC schemes exploit technical weaknesses, fragmented payment workflows, and human trust, making prevention a multifaceted challenge. While no defense is entirely foolproof, companies can meaningfully reduce their exposure to BEC attacks by adopting layered safeguards that address system access, payment controls, vendor management, and employee behavior, including:
- Implementing phishing-resistant multifactor authentication (“MFA”) across all accounts. Require MFA for email, financial systems, remote access, and vendor portals; where feasible, prioritize phishing-resistant methods such as security keys, passkeys, or other cryptographic-based authentication, and require step-up authentication for new devices, mailbox-forwarding rules, and payment-administration changes.
- Establishing robust verification protocols for financial transactions. Use previously verified contact information (in particular, phone numbers) for any request to change payment instructions, authorize wire transfers, update vendor bank details, or reset financial-portal credentials; do not rely on contact information supplied in the same message requesting the change. For sensitive transactions, consider a video call to verify.
- Requiring wait periods for account changes that affect authentication or payment. Wait periods can provide a buffer period to detect and investigate potentially unauthorized changes to MFA settings, contact details, beneficiary accounts, or bank instructions before they can be exploited to facilitate fraudulent transactions.
- Training employees on social engineering awareness. Provide recurring training on spotting phishing attacks, domain spoofing, QR-code lures, deepfake or spoofed phone requests, and urgent or emotionally manipulative messages, with simulated exercises to reinforce skills.
- Deploying technical controls to detect suspicious activity. Configure email filters, email authentication protocols, domain-monitoring tools, intrusion detection systems, and identity logs to flag look-alike domains, unexpected email-forwarding or OAuth-consent rules, impossible-travel logins, and log-in attempts from unfamiliar geographies.
- Enforcing dual-approval requirements for high-risk transactions. Require two or more authorized sign-offs for large payments, changes to standing payment instructions, or sensitive data transfers, with separation of duties and independent confirmation for any exception request.
BEC Litigation Examples
The central question in BEC litigation is who bears the financial loss. It may seem that the answer is which party was hacked. But in reality, courts often allocate it to the party best positioned to have detected and prevented the fraud, and the hacked party is not often in the best position to identify that the fraud has occurred. Implicating varying iterations of the “imposter rule” under the Uniform Commercial Code (the “UCC”) or related equitable principles, this analysis considers factors such as whether each party secured its systems, had notice of prior compromises or targeting, scrutinized spoofed addresses, followed payment-change protocols, and confirmed wire instructions.
Recent decisions applying the imposter rule have continued to emphasize ordinary care and red flags. In Thomas v. Corbyn Restaurant Development Corp., 111 Cal. App. 5th 439 (May 27, 2025), a California appellate court applied the UCC’s imposter rule to a fraudulent wire transfer of settlement funds, affirming the trial court’s finding that the payor ignored multiple red flags while executing payment—including altered payee information, changes to payment method, spoofed email addresses, and inoperable phone numbers—and was therefore responsible for the $475,000 loss. Notably, the court emphasized that a party’s negligence “may contribute to a finding that that party was in the best position to prevent the fraud” but was neither necessary nor dispositive to its analysis. Id. at 453.
Courts often apportion losses based on the extent to which each party exercised ordinary care. This is significant because BEC events often involve failures on both sides—for example, one party may have had the compromised account or ambiguous payment-change process, while another may have ignored mismatched payee names, suspicious domains, or broken callback procedures. In Beau Townsend Ford Lincoln, Inc. v. Don Hinds Ford, Inc., 759 F. App’x. 348, 357 (6th Cir. 2018), the court overturned a summary judgment award for the payee because the payee “was at least partially responsible for its own losses” and instructed further factfinding on loss apportionment. See also Schultz Excavating & Asphalt of Ludington, LLC v. Smyrna Ready Mix Concrete, LLC, 2025 WL 2061229, at *3 (6th Cir. July 23, 2025) (allowing for the possibility that commercially unreasonable behavior can “affect the allocation of liability”).
BEC disputes also often involve disagreements over contractual provisions regarding payment instructions or indemnification obligations, focusing on the payor’s compliance with agreed-upon payment procedures rather than questions governed solely by the UCC’s imposter-rule framework. In Peeples v. Carolina Container, LLC, 2021 WL 4224009, at *3–6 (N.D. GA. 2021), the court followed the strict and explicit requirements on payment instructions within the Asset Purchase Agreement at issue, as well as its indemnification clause, to find that the payor could not escape liability for failing to pay the plaintiff. See also Erie Insurance Company v. WAWGD, Inc., 2024 WL 1856155, at *3 (D. Md. 2024) (citing Peeples to find that payor’s payment to an imposter did not constitute performance under a settlement agreement).
In addition, insurance coverage analysis plays an essential role, as crime, computer-fraud, funds-transfer-fraud, social-engineering, and cyber policies may respond differently to BEC losses. Coverage outcomes turn on policy language, causation, and exclusions. For example, courts have found policies to be applicable where fraudulent emails induced employees to transfer funds. See Ernst & Haas Management Co. v. Hiscox, Inc., 23 F.4th 1195, 1198–1201 (9th Cir. 2022); American Tooling Center, Inc. v. Travelers Cas. & Sur. Co. of Am., 895 F.3d 455, 462–63 (6th Cir. 2018). By contrast, in Aqua Star (USA) Corp. v. Travelers Cas. & Sur. Co. of Am., 719 F. App’x. 701, 702 (9th Cir. 2018), the Ninth Circuit found that the insured’s “Computer Fraud” policy did not apply because the insured’s employees changed wiring information based on fraudulent instructions, triggering an exclusion for losses resulting directly or indirectly from the input of electronic data by an authorized user. These divergent outcomes underscore the need to analyze all potentially responsive policies and to preserve the facts needed to support notice, causation, and direct-loss arguments.
Guidance on BEC Litigation
The following strategies can help companies position themselves should litigation arise from a BEC scheme:
- Leverage verification protocols as evidence of reasonable care. Show that your organization maintained strong controls, such as documented pre-verified callback procedures, dual approval, and payment-change holds, to argue that it was not in the best position to prevent the fraud under the imposter rule or related equitable principles.
- Highlight counterparty weaknesses in safeguards. Identify and document where the opposing party’s procedures were deficient compared to industry standards or contractual requirements, including failure to secure email accounts, ambiguous payment-change procedures, or failure to scrutinize red flags.
- Evaluate and enforce contractual provisions. Review agreements for cybersecurity obligations, payment verification requirements, authorized-signatory provisions, notice obligations, limitation-of-liability clauses, and indemnification language that may allocate responsibility for losses.
- Conduct early and thorough insurance coverage reviews. Analyze all potentially applicable policies, including crime, computer-fraud, funds-transfer-fraud, social-engineering, cyber, and fidelity coverage; provide timely notice; and preserve facts bearing on direct loss, causation, and exclusions.
- Preserve and present technical and procedural evidence. Retain email headers, mail-flow rules, sign-in logs, OAuth-consent records, vendor-portal logs, callback notes, training records, and incident response documentation to demonstrate a culture of compliance and security awareness.
- Integrate risk-mitigation measures into settlement strategy. Use evidence of security protocols, recovery efforts, counterparty fault, and insurance positioning as leverage in negotiations, potentially shifting liability or increasing recovery.
Conclusion
BEC remains one of the most financially damaging and fast-evolving threats to organizations, requiring preventive controls, rapid response measures, and litigation readiness. Implementing layered safeguards—such as phishing-resistant MFA, robust verification protocols, employee training, technical monitoring, and dual-approval processes—can both significantly reduce the likelihood of falling victim to a BEC scheme and enhance a recovery strategy, as the quality of an organization’s safeguards directly affects its position in any subsequent dispute.
*****
To subscribe to the Data Blog, please click here.
The cover art used in this blog post was generated by ChatGPT.
The authors would like to thank former Debevoise Associate Ned Terrace and Summer Law Clerk Mendel Jacobson for their work on this blog post.