White Papers

The Expanding Scope of Business Email Compromises

Business Email Compromises (BECs) are often seen as incidents where attackers gain unauthorized access to email accounts, typically for wire fraud or theft. However, BECs are fundamentally identity compromises. In many cases, the same credentials used for email access also grant access to an organization’s Single Sign-On (SSO) system, opening the door to various cloud-based applications and remote access services, thus amplifying the potential damage.
By clicking submit, I consent to the processing of my contact information by CrowdStrike and its partners, including to CrowdStrike contacting me and sharing my contact information with its partners. I acknowledge that CrowdStrike will use and keep my contact information for as long as necessary for these purposes in accordance with its Privacy Notice.
CrowdStrike logo

Thank You

Business Email Compromises (BECs) are often seen as incidents where attackers gain unauthorized access to email accounts, typically for wire fraud or theft. However, BECs are fundamentally identity compromises. In many cases, the same credentials used for email access also grant access to an organization’s Single Sign-On (SSO) system, opening the door to various cloud-based applications and remote access services, thus amplifying the potential damage.

This paper explores the shift from viewing BECs as simple financial attacks to recognizing the broader threat posed by Nation State or eCrime adversaries.

Additional Resources
  • Modernize Legacy OT with Security logo

    Modernize Legacy OT with Security

    Read whitepaper
  • The Frontier AI Adversary:<br>How Frontier AI Is Changing the Nature of Cyberattacks logo

    The Frontier AI Adversary:<br>How Frontier AI Is Changing the Nature of Cyberattacks

    Read whitepaper
  • AI Detection and Response: A Runtime Security Architecture for AI Systems logo

    AI Detection and Response: A Runtime Security Architecture for AI Systems

    Read whitepaper