Business Email Compromise (BEC): The invisible attack
When the CEO's email orders an urgent transfer that never comes back.
Audience: Companies and Operations · Risk level: CRITICAL
Blindfy Intelligence Unit · Technical review by Blindfy
Scenario
The CFO receives an email from the "CEO" requesting an urgent payment to close a confidential deal.
How the scam works
The criminal studies the company hierarchy and creates an email with a near-identical domain to request funds.
Common mistake
Fulfilling financial requests "outside the workflow" without direct verbal confirmation.
Impact
Capital flight and internal compliance breach.
What works
Multi-factor processes for approving atypical payments.
Protection checklist
- Confirm atypical requests by phone call
- Set up alerts for similar external emails
- Implement triple approval workflows
- Monitor newly registered similar domains
- Train executives on exposure risks
- Audit email logs periodically
Editorial sources
- Banco Central do Brasil — Orientações oficiais sobre golpes e Pix
- CERT.br / NIC.br — Cartilha de Segurança para Internet
- ENCCLA / Ministério da Justiça — Enfrentamento a golpes digitais
Corporate shielding requires more than antivirus. It requires digital governance.