Blindfy — Digital Protection

Business Email Compromise (BEC): The invisible attack

When the CEO's email orders an urgent transfer that never comes back.

Audience: Companies and Operations · Risk level: CRITICAL

Blindfy Intelligence Unit · Technical review by Blindfy

Scenario

The CFO receives an email from the "CEO" requesting an urgent payment to close a confidential deal.

How the scam works

The criminal studies the company hierarchy and creates an email with a near-identical domain to request funds.

Common mistake

Fulfilling financial requests "outside the workflow" without direct verbal confirmation.

Impact

Capital flight and internal compliance breach.

What works

Multi-factor processes for approving atypical payments.

Protection checklist

  • Confirm atypical requests by phone call
  • Set up alerts for similar external emails
  • Implement triple approval workflows
  • Monitor newly registered similar domains
  • Train executives on exposure risks
  • Audit email logs periodically

Editorial sources

Corporate shielding requires more than antivirus. It requires digital governance.

← All risk analyses · Blindfy initial assessment