Knowledge / identity IR acsc-glossary

Business email compromise

Email fraud aimed at an organisation's money or data. Invoice redirection is the local dialect.

PHISHING / identity abuse, not a malware class01Lure02Landing03Capture04ReuseControls: phishing-resistant MFA, reporting, mail auth, drills.

Business email compromise is cybercrime that uses fraudulent email to push a specific business outcome: a changed bank account, a fake lawyer, a CEO who needs a gift card. The mailbox may be spoofed or actually taken over.

Defence is process more than a product: dual control on payments, verify account changes on a known number, monitor mailbox rules, MFA on every privileged and finance identity.

If money left, treat it as fraud and an incident together. Banks and ACSC both have a clock.

Fact source: ASD's ACSC glossary.