← All AI scams
🏢

AI business email compromise

A convincing executive message still does not authorize a payment.

Business email compromise (BEC) is a payment or data theft scheme built around impersonating someone a worker trusts: an executive, finance leader, attorney, or vendor. A criminal may spoof an address, take over a real mailbox, or use information from earlier conversations to make a fraudulent request fit the normal workflow.

Generative AI can polish the email, imitate a voice, or add a believable video meeting, but detecting synthetic media is not a dependable control. The durable defense is procedural: confirm sensitive instructions through a separately chosen, pre-established channel and require approvals that urgency or seniority cannot waive.

How the scam works

1
Map the approval chain
The attacker studies public profiles, compromised mailboxes, invoices, and routine language to learn who requests payments, who releases them, and when a request will feel plausible.
2
Impersonate or take over
A spoofed address, lookalike domain, or compromised real account delivers an invoice change, wire request, payroll update, credential request, or demand for confidential records.
3
Reinforce the story
AI-generated writing, cloned audio, or a staged virtual meeting can make the same instruction appear to arrive through several formats. Multiple impressions inside one attacker-controlled conversation are still only one source.
4
Push past the control
The request becomes urgent, confidential, or too senior to question. The crime succeeds when someone treats apparent identity as authorization and skips a callback, vendor check, or second approver.

Red flags to watch for

!
Payment details suddenly change
A new bank account, beneficiary, mailing address, or payroll destination is high risk even when the request sits inside a familiar email thread.
!
Urgency and secrecy override routine
Pressure to act before a meeting ends, keep the transaction confidential, or avoid contacting the usual owner is an attempt to remove independent review.
!
The request moves to an unusual channel
A personal mailbox, unfamiliar meeting link, text message, or chat account is not validated by a familiar display name, face, or voice.
!
Normal approval is called unnecessary
Claims that the CEO already approved it verbally, the vendor cannot be called, or dual approval will cause unacceptable delay attack the control that would expose the fraud.
!
Credentials or codes enter the request
A payment problem that supposedly requires a password, one-time code, mailbox rule, or remote-access session may be an account-takeover attempt as well as a payment scam.

What to do

Pause and verify out-of-band
Contact the named person or vendor using a number, internal directory, or account record you already trusted before this message arrived. Do not use contact details, reply paths, or meeting links supplied in the request.
Require two-person approval
Wires, payroll changes, vendor-bank changes, and releases of sensitive data should require a second authorized reviewer. Written policy should make clear that rank, voice, video, and urgency do not create exceptions.
Lock down change requests
Confirm account changes with a known vendor contact, record who verified them, and separate the person editing payment details from the person releasing funds. A reply in the same email thread is not independent verification.
If money moved, call the bank now
Ask the sending financial institution to attempt a recall and contact the receiving institution. Then file a detailed report with IC3, including account, transaction, message, and meeting information; recovery is not guaranteed, so speed matters.
Contain a suspected account compromise
Preserve messages and headers, notify security, reset affected credentials from a trusted device, revoke active sessions, review forwarding rules, and warn partners who may receive follow-on requests.

Frequently asked questions

Does flawless writing mean a BEC email is legitimate?
No. AI can remove the grammar and tone problems people once used as warning signs, and a compromised mailbox can contain genuine history. Verify the requested action and destination, not the quality of the prose.
What if I saw the executive approve it on video?
A video call is communication, not authorization. The account may be compromised, the meeting may be staged, or the media may be synthetic. Follow the same callback and approval process you would use for an email.
Can email security controls stop BEC?
Filtering, domain protections, and multi-factor authentication reduce risk, but no single technical control covers spoofed vendors, compromised accounts, social engineering, and virtual meetings. Payment and data-release controls are the final backstop.
What should be included in an IC3 report?
Include how contact started, sender addresses and phone numbers, transaction dates and accounts, the requested payment method, meeting links, messages, and any other identifiers. Preserve originals rather than forwarding or editing the evidence.

Sources and further help

Reviewed

Fight AI with AI.

Scambook's AI checker analyzes suspicious messages, numbers, and links against a live scam database — including the machine-generated ones. Free, in seconds.

Check a message free →Look up a number or website →

More AI scam guides

How to verify a human
✉️
AI-written phishing
🛟
Recovery scams

Scammers upgraded. So should your defenses.

Scambook is free on the App Store — check your first suspicious message in seconds.

Download on the App Store
Scambook
ANALYZE. DETECT. STAY SAFE.

The easiest way to answer one question: is this a scam?

© 2026 Scambook. All rights reserved.Scambook gives guidance, not legal or financial advice.