Smart. Focused. Email.
Fast, cross-platform email designed to filter out the noise - so you can focus on what's important.
💡Business email compromise: a scam where someone impersonates a person you trust (your CEO, a vendor, even your own compromised account) to talk you into wiring money or handing over sensitive data. No malware, no suspicious attachment. Just a very convincing email. BEC isn't a hacking attack in the traditional sense. It's a con, run entirely through your inbox, and it's one of the most expensive categories of cybercrime that exists today.
Tuesday afternoon, an email arrives from your CEO. Urgent, a little terse, asking you to wire funds to a new vendor account before end of day. Would you question it, or would you just do it?
That is the (very human reaction) that BEC exploits. The FBI's Internet Crime Complaint Center logged 21,442 BEC complaints in 2024, totaling $2,770,151,146 in reported losses, according to the 2025 IC3 Annual Report. One category of scam, nearly $3 billion.
BEC works so well because it doesn't rely on breaking through your security software. It relies on breaking through you, at the exact moment you're busy, distracted, or eager to help. No ransomware, no virus, nothing your antivirus would ever flag. But a well-timed request that sounds exactly like someone you'd normally trust without a second thought? That works more often than anyone likes to admit.
Email clients like Spark can catch some of this before it reaches you.
Gatekeeper screens messages from senders you've never emailed before, which helps, since plenty of BEC attempts come from a look-alike address you've genuinely never seen. It won't catch every case, though. Some of the most damaging BEC attacks come from a legitimately hacked account, one that's emailed you plenty of times before.
You've got a handful of common patterns here, and they're not all the same threat.
CEO fraud (sometimes filed under whaling) is the classic version: an urgent request, supposedly from an executive, usually about money and usually needing to move fast. FACC, an Austrian aerospace supplier, lost roughly $56 million this way in 2016 after an employee wired funds on instructions that looked exactly like they came from the CEO. Both the CEO and CFO were fired afterward.
Vendor email compromise swaps out the executive for a supplier. An invoice looks completely normal, right account number, right formatting, except the bank details have been quietly swapped. You only find out once the real vendor calls asking where their payment went.
Account takeover is the scariest version, because there's no spoofing to spot. The attacker is inside a real, compromised mailbox, reading actual threads, and waiting for a genuine invoice to swap out. Nothing about the sender address looks wrong. And that's exactly the problem: it isn't wrong.
Payroll diversion targets HR instead of finance: a fake "employee" request to update direct deposit details, quietly rerouting someone's paycheck.
Screening and reporting habits go a long way, and the basics look similar everywhere you check mail.
In Gmail:
In Outlook:
In Spark:
None of that replaces the one habit that actually stops BEC cold: verify big requests through a second channel. A phone call to a known number. Not a reply to the email itself.
Verify by phone, always, for anything involving money or account changes. If the "CEO" is really in a hurry, they'll take your call.
Set up DMARC if you run a business domain. A DMARC record tells receiving servers what to do when someone tries to spoof your domain, closing off one of BEC's easiest paths in.
Slow down on urgency. Scammers manufacture time pressure on purpose. A real emergency can wait five minutes for a callback.
Require a second approval for wire transfers over a set amount, no matter who's asking. Boring policy. Also the single best defense against a $56 million mistake.
Watch for near-identical domains, like company-billing.com instead of company.com. It's a one-letter difference that costs people millions every year.