The threat has evolved

AI-Powered Business Email Compromise

How attackers use AI to take over your email, watch your conversations, and steal your money. Not one phishing email anymore: an AI agent impersonating you across a whole thread, cloning your CFO's voice, and replying to your team in real time while it drains the account.

$2.8 billion lost to BEC in 2024 alone  ·  Every step of it is preventable with the right controls

$2.8B

in BEC losses reported to the FBI in 2024. The second-costliest cybercrime category.

FBI IC3 2024 Annual Report

82%

of phishing emails in 2025 were AI-generated, exceeding human-written attacks for the first time.

SecuredIntel 2025

62%

of Microsoft-blocked phishing in mid-2025 came from one kit, Tycoon 2FA, which bypasses MFA by stealing the session token.

Microsoft Security Blog

$1.1B

in U.S. deepfake fraud losses in 2025, triple the prior year. Voice-clone attacks average $243K each.

Keepnet Labs 2026

What is different in 2025 and 2026

BEC stopped being one email. It is now a conversation, and an AI is running it.

The old playbook was one spoofed email asking finance to wire money. Modern BEC is fundamentally different. Attackers take over a real mailbox, study the victim for weeks, then deploy an AI agent that reads incoming replies and responds in the victim's tone in real time. It can sustain a twelve-message thread with your CFO while running a thousand other victims at the same time. Traditional defenses were not designed for this.

🎤

Voice cloning from three seconds of audio

Attackers scrape a LinkedIn video, a podcast clip, or a voicemail greeting and clone the executive's voice. "Call to verify" no longer works if the voice on the line is fake.

$243K average loss per voice-clone fraud. Keepnet 2026
🎥

Live deepfake video calls

Arup, Hong Kong, 2024: a finance employee wired $25.6M across fifteen transactions after a video call where every other participant, including the CFO, was an AI deepfake. Singapore, 2025: same playbook, $499K.

Widely reported, 2024 to 2025
🤖

AI agents replying in your voice

A language model reads the victim's sent mail, learns their tone, vocabulary, and signature, then answers incoming questions in real time while the human attacker focuses on the wire. Your team never hears from a non-fluent attacker.

82% of 2025 phishing AI-generated. SecuredIntel
🔑

MFA bypass at industrial scale

Phishing-as-a-service kits (Tycoon 2FA, EvilProxy, Sneaky 2FA, Mamba 2FA) sit between the victim and the real Microsoft or Google login, capture the password and the session cookie, and skip the MFA prompt entirely.

Microsoft Security Blog
🎯

Hyper-personalization at scale

One attacker now runs thousands of parallel BEC conversations. Each email references the victim's real vendors, projects, and pending invoices, scraped from compromised inboxes and public sources.

Verizon DBIR 2025: pretexting nearly doubled
💬

Conversation hijacking, not new emails

Attackers reply inside legitimate threads with vendors and clients, often from a look-alike domain that differs by one character. Your team sees a familiar thread and trusts it.

Abnormal Security 2025: vendor email compromise engagement 90% higher than standard BEC
The five-step attack chain

How an AI-powered BEC actually unfolds

Every modern BEC follows the same five phases, and each phase has specific technical controls that stop it. Understand the chain and you know exactly where to invest.

1

Compromise

A phishing kit steals the session cookie. MFA bypassed.

2

Watch

Hidden inbox rules forward your mail. AI reads everything.

3

Identify

Map your vendors, approval flow, and pending invoices.

4

Strike

A look-alike domain or hijacked thread changes the wire instructions.

5

Drain

The wire goes out before anyone notices. 88% of BEC transfers are wires.

Phase 1 Compromise: getting in past MFA

  • Adversary-in-the-middle phishing kits. The victim clicks a link, lands on a reverse-proxy server (Tycoon 2FA, EvilProxy, Sneaky 2FA, Mamba 2FA), enters real credentials, completes MFA, and the attacker captures the resulting session cookie. The attacker now is the user. One-time codes and push approvals do nothing.
  • OAuth consent phishing. A "review document" link asks for permission to read and send mail. Many users approve without thinking. No password is stolen and MFA is never in the loop.
  • Scale. Tycoon 2FA alone accounted for roughly 62% of Microsoft-blocked phishing in mid-2025, with more than 30 million malicious emails blocked in a single month from that one platform.
The defense: phishing-resistant MFA (passkeys or FIDO2 hardware keys). The credential is bound to the legitimate domain, so a reverse-proxy phishing page cannot complete the challenge. Our plain-English setup guide is at cythentic.com/mfa.

Phase 2 Watch: silent persistence inside the mailbox

  • Hidden inbox rules auto-forward incoming mail to an external address while also moving the original to RSS Subscriptions, Conversation History, or Junk, so the victim never sees the replies. Common signatures: rules named with a single character or a single dot, and rules that delete after forwarding.
  • ForwardingSmtpAddress on the mailbox itself, set through Exchange Online or the Graph API, bypassing the Outlook interface entirely. Users cannot see this in their own Outlook.
  • OAuth grants to attacker-controlled apps, quietly added to keep access even after the password is rotated. Look for unknown applications with Mail.Read or Mail.ReadWrite scopes.
  • Audit log tampering. Sophisticated attackers try to disable mailbox auditing so their actions are never recorded.
The defense: disable external auto-forwarding tenant-wide, audit inbox rules continuously, require admin approval for OAuth grants, and export the unified audit log to a SIEM. The exact commands are in the detection section below.

Phase 3 Identify: reconnaissance inside your inbox

  • Vendor mapping. The AI reads every email, identifies who you pay, who you invoice, your approval workflow, and your accounting cycle.
  • Pending invoices. Attackers search for "wire", "invoice", "ACH", "remit", "banking details", and "routing number". When a real invoice is in flight, they intercept it.
  • Relationship learning. The AI learns that you call your CFO "Sam", uses your tone, and references real shared projects. The phish becomes indistinguishable from a real email.
  • Timing. They wait for Friday afternoons, vacations, executive travel, and holiday weekends to maximize the window before anyone catches the wire.
The defense: mailbox audit logging exported to a SIEM, anomaly detection on unusual mail searches, and identity monitoring that catches impossible travel and credential abuse. Then test your people: a controlled phishing assessment shows you who clicks before an attacker finds out.

Phase 4 Strike: the money-movement message

  • Thread hijacking. The attacker replies inside an existing, legitimate vendor thread. Same subject, same signatures, but with a new "updated banking details" attachment.
  • Look-alike domains. One-character typosquats, Unicode homographs (a Cyrillic "a" in place of a Latin one), or alternate top-level domains. The reply-to changes but the display name stays identical.
  • Voice clone or deepfake confirmation. If finance pushes back, the attacker schedules a "quick call", and the cloned CFO voice or a real-time deepfake video resolves the doubt.
  • Last-minute banking change. The classic closing-day pattern: legitimate transaction, legitimate parties, and a "we changed banks" email the morning of.
The defense: mandatory out-of-band callback verification, to a number from your own vendor master file and never the number in the email, for every wire, every ACH change, and every banking-detail update. Pair it with a pre-shared codeword the AI cannot know.

Phase 5 Drain, and the race to recover

  • 88% of BEC fund transfers are wires (Verizon DBIR 2025). Wires are fast and effectively irreversible once they land at the receiving bank.
  • Mule networks move the money through three to five hops in under four hours, often crossing jurisdictions to defeat recovery.
  • The Financial Fraud Kill Chain. If reported within 72 hours and the wire is $50,000 or more, the FBI can sometimes claw it back. After 72 hours the recovery rate collapses.
The defense: a rehearsed first hour. Within minutes of suspicion, call the originating bank, file at ic3.gov, and alert the receiving bank. Have the playbook printed before you need it. If you are in this situation right now, use the Have a Breach button at the top of this page.
The controls that actually stop it

10 controls that prevent AI-powered BEC

Each control with exactly where to configure it in Microsoft 365 and Google Workspace, and why it matters in the AI era. The first six stop the attack chain. The last four catch it if the first six fail.

01

Phishing-resistant MFA on every account

SMS codes, authenticator-app codes, and push notifications are all defeated by adversary-in-the-middle kits. Passkeys and FIDO2 hardware keys (YubiKey, Titan) bind the credential to the legitimate domain, so a reverse-proxy phishing page cannot complete the challenge.

Microsoft 365

Entra ID › Security › Authentication methods › enable Passkey (FIDO2), then a Conditional Access policy requiring phishing-resistant MFA

Google Workspace

Admin Console › Security › Authentication › 2-Step Verification › "Only security keys", and enroll in the Advanced Protection Program

CISA phishing-resistant MFA guidance. Step by step for individuals: cythentic.com/mfa
02

Disable external auto-forwarding tenant-wide

The number one way attackers keep silent persistence. An auto-forward rule sends a copy of every inbound message to the attacker even after the password is rotated. Block it at the tenant level, not the user level. Almost no one has a business reason to auto-forward externally.

Microsoft 365

Defender › Email & collaboration › Anti-spam › Outbound spam policy › AutoForwardingMode = Off. Also: Set-RemoteDomain Default -AutoForwardEnabled $false

Google Workspace

Admin Console › Apps › Google Workspace › Gmail › End User Access › disable "Automatic forwarding"

Microsoft Defender outbound spam policies
03

Out-of-band callback verification for every money movement

Phone back to a number from your vendor master file, never the number in the email. In the deepfake era, a voice alone is not enough: pair the callback with a pre-shared codeword or a specific shared-history question the AI cannot answer. Required for every wire, every ACH change, every banking-detail update, and every gift-card request.

Procedural

Document it in your money-movement runbook with an approval matrix by dollar threshold and a sign-off log. The playbook below gives you the templates.

Technical layer

Add DLP rules that flag outbound mail mentioning "wire", "ACH", or "banking change" for a second approval.

FBI IC3 BEC public service announcement
04

Audit inbox rules and ForwardingSmtpAddress continuously

Run it every week. Look for rules with single-character names, rules that forward externally, rules that move mail to RSS Subscriptions, Conversation History, or Junk, and any ForwardingSmtpAddress set on a mailbox. These are the classic indicators of a compromised mailbox.

Microsoft 365 (PowerShell)Get-Mailbox -RecipientTypeDetails UserMailbox | Get-InboxRule | Where {$_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo}
Google Workspace

Security Center › Investigation Tool › search "Email forwarding" and filter for external destinations

Microsoft: responding to a compromised mailbox
05

DMARC at p=reject with SPF and DKIM aligned

Stops attackers from spoofing your domain to your own employees or your customers. Quarantine is not enough: it sends suspicious mail to spam, where employees still see and trust it. Reject blocks delivery entirely.

DNS (at your registrar)

TXT record at _dmarc.yourdomain.com:
v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain.com; pct=100

Verify it free

The Cythentic™ exposure scan checks your SPF, DKIM, and DMARC posture in about a minute.

RFC 7489 (DMARC). CISA DMARC guidance
06

Block legacy authentication and enforce Conditional Access

Legacy protocols (IMAP, POP3, basic-auth SMTP) do not support MFA, and attackers target them on purpose. Block them tenant-wide, then layer Conditional Access requiring a trusted device, a compliant location, and phishing-resistant MFA for high-risk actions.

Microsoft 365

Entra ID › Conditional Access › "Block legacy authentication" policy, then "Require phishing-resistant MFA for all users"

Google Workspace

Admin › Security › Access and data control › Context-Aware Access › require a security key and a corporate device

Microsoft Conditional Access: block legacy authentication
07

Look-alike domain monitoring and defensive registration

Attackers register typosquats, Unicode homographs, and alternate top-level domains days before launching. Continuous monitoring catches the registration so you can block the domain at your gateway before the first phish arrives.

Tooling

DNSTwist (open source), DomainTools, Bolster, and the Cythentic exposure scan, which surfaces look-alike domains registered against your brand for free.

Defensive registration

Pre-register the obvious typosquats of your primary domain on day one. Around $15 a year per domain, and infinite return the day one of them prevents a wire.

Cythentic external exposure scan (free)
08

AI-aware inbound email filtering

Traditional signature-based gateways are blind to AI-written BEC: no malicious links, no malware, no spelling tells. Modern filtering (Microsoft Defender for Office 365, Abnormal, Mimecast, Cloudflare Email Security) detects tonal anomalies, impersonation patterns, and behavioral deviations from learned baselines.

Microsoft 365

Defender for Office 365: enable Safe Links, Safe Attachments, Zero-hour Auto Purge, and Attack Simulation Training

Google Workspace

Admin › Security › Gmail safety › enable advanced phishing and malware protection plus enhanced pre-delivery scanning

Abnormal Security BEC research
09

Mailbox audit logging exported to a SIEM

When you have an incident, you need 90 or more days of mailbox activity to reconstruct what the attacker did, saw, and sent. Enable auditing for every mailbox and ship the logs somewhere that alerts on suspicious patterns.

Microsoft 365 (PowerShell)Set-OrganizationConfig -AuditDisabled $false
Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true
Google Workspace

Admin › Reporting › Audit logs › enable, and export to your SIEM via BigQuery

Microsoft Purview audit log
10

Phishing simulations plus a written money-movement playbook

Quarterly phishing simulations aimed specifically at finance, accounts payable, and executive assistants, the people who actually move money. Pair them with a printed playbook: callback verification, pre-shared codeword, approval matrix by dollar threshold, and an incident quick card for when something goes wrong.

Microsoft 365

Defender for Office 365 › Attack Simulation Training (built in)

For every employee

Remi coaches each person through the lures that actually work, on their work and personal accounts, continuously. A Cythentic phishing assessment shows you who clicks today.

CISA phishing guidance
Free. Built for finance, IT, and executives

The BEC Manual Controls Playbook

The procedural controls that stop AI-BEC even when your tools fail. Work through the checklist here, then print it, or have us send you the formatted version to circulate to finance, accounts payable, and the executive team.

Seven controls to put in writing

0 of 7
  • Callback verification procedure. Exactly who calls, where they get the verified number (your vendor master file, never the email), and a sign-off log.
  • Money-movement approval matrix. Dollar thresholds mapped to required approvers, with dual control above a set amount.
  • Vendor onboarding and banking-change checklist. The fields to verify before accepting any new bank account, and who verifies them.
  • Admin audit commands. The PowerShell and Google queries to find hidden forwarding rules, run weekly. They are in the detection section.
  • Incident response quick card. The first 30 minutes when you suspect BEC: stop the wire, call the bank, file at ic3.gov, preserve the mailbox.
  • Quarterly tabletop exercise. Discussion scenarios for finance and IT, so the first real incident is not the first time anyone has thought about it.
  • Pre-shared codeword worksheet. A codeword or shared-history question for every money-movement approver, to defeat voice clones and deepfakes.

Want the formatted version, and a walkthrough?

Tell us where to send it. We will email you the playbook laid out for your team, and if you want, walk finance and IT through it on a short call. No drip sequence, no sales follow-up unless you ask for one.

Got it. The playbook is on its way, and we will reach out about the walkthrough if you asked for one.

We use your email only to send the playbook and, optionally, to schedule the walkthrough.

If you think you have been hit

Detection commands: find the rules attackers leave behind

Run these this week. If you find any of these indicators, treat that mailbox as compromised: rotate the password, revoke every session, and audit the OAuth grants immediately.

Microsoft 365: find every forwarding inbox rule across all mailboxes
# Connect first: Connect-ExchangeOnline
Get-Mailbox -ResultSize Unlimited -RecipientTypeDetails UserMailbox |
  ForEach-Object {
    Get-InboxRule -Mailbox $_.Identity |
      Where-Object { $_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo -or $_.DeleteMessage }
  } | Format-Table Mailbox,Name,ForwardTo,RedirectTo,DeleteMessage
Microsoft 365: find mailboxes with ForwardingSmtpAddress (the Outlook UI cannot see these)
Get-Mailbox -ResultSize Unlimited |
  Where-Object { $_.ForwardingSmtpAddress -ne $null -or $_.ForwardingAddress -ne $null } |
  Format-Table DisplayName,UserPrincipalName,ForwardingSmtpAddress,ForwardingAddress,DeliverToMailboxAndForward
Microsoft 365: verify mailbox audit logging is enabled
Get-OrganizationConfig | Format-List AuditDisabled,UnifiedAuditLogIngestionEnabled
Get-Mailbox -ResultSize Unlimited |
  Where-Object { $_.AuditEnabled -eq $false } |
  Format-Table DisplayName,UserPrincipalName,AuditEnabled
Microsoft 365: find suspicious OAuth app grants
Get-MgUserOauth2PermissionGrant -All |
  Where-Object { $_.Scope -match "Mail\.Read|Mail\.ReadWrite|Mail\.Send" }
Google Workspace: investigation tool query for forwarding
# Admin Console › Security › Investigation Tool › Source: Gmail log events
# Filter: Event = "Forwarding address added"  OR  Event = "POP/IMAP enabled"
# Time range: last 90 days
# For each finding: confirm the user authorized it, or revoke and rotate.
Classic indicators of compromise: the inbox rule patterns to look for
# Rule names that mean "hidden":
"."    " "    ".."    "a"    "b"    (single character, single dot, or blank)

# Rule actions that mean "exfiltration":
ForwardTo: an external address
Move to folder: RSS Subscriptions, Conversation History, Junk, Archive
MarkAsRead + Delete

# Mailbox-level red flags:
ForwardingSmtpAddress set
AuditEnabled changed to $false in the last 90 days
New OAuth grant with a Mail.* scope to an unknown app

If any of these come back positive, you are probably in an active incident. Do not wipe anything. Preserve the mailbox, rotate credentials from a clean device, revoke sessions, and use the Have a Breach button at the top of the page. The first hour matters more than anything that follows.

Recent real-world losses

What AI-powered BEC actually costs

Selected incidents that defined the threat landscape.

$25.6M

Arup, Hong Kong

2024 · video deepfake

A finance employee wired fifteen separate transactions after a video call where every other participant, including the CFO, was an AI-generated deepfake. Now the canonical reference case.

Widely reported: CNN, FT, Reuters
$499K

Multinational firm, Singapore

2025 · video deepfake

A finance director joined what appeared to be a routine call with senior leadership. The CFO requested an urgent transfer. None of the executives on the call were real.

Multiple 2025 reports
$1.1B

U.S. deepfake fraud losses

2025 · triple the prior year

Total U.S. deepfake fraud losses reached $1.1 billion in 2025, up from $360 million the year before. Voice-clone-only attacks averaged $243,000 each.

Keepnet Labs 2026
30M

Phishing emails in one month

mid-2025 · one phishing-as-a-service kit

A single platform, Tycoon 2FA, drove 30 million malicious emails that Microsoft blocked in one month, roughly 62% of all Microsoft-blocked phishing. It makes MFA-bypass attacks available to non-technical criminals.

Microsoft Security Blog
$300M

Vendor email compromise attempts

2024 to 2025 · twelve months

Attackers attempted to steal more than $300 million through vendor email compromise in a year. 83% of large enterprises were hit, and 98.5% of these scams went unreported until the money was gone.

Abnormal Security 2025
$2.8B

Total U.S. BEC losses

2024 · FBI IC3

21,442 BEC complaints in 2024 totaling $2.8 billion in confirmed losses. The second-costliest cybercrime category. Nearly $8.5 billion cumulative over the three years through 2024.

FBI IC3 2024 Annual Report
The fine print most boards miss

Cyber insurance and the law will not save you

Two surprises every executive learns the hard way after a BEC: how little the cyber policy actually pays out for it, and how far behind the law still is.

What the cyber policy actually pays

BEC was the leading cause of cyber-insurance claims globally in 2025, about 31% of all incidents. But the payout is rarely full:

  • Funds-transfer fraud is almost always a sub-limit, not the full policy limit. A typical sub-limit is $100K to $250K, even on a $5M policy.
  • Carriers increasingly require proof of callback verification for the claim to pay. If finance wired without out-of-band verification, expect a denial.
  • "Voluntary parting with funds" exclusions deny losses where the insured transferred the money themselves, even under deception.
  • MFA evidence is required. If MFA was not enforced on the compromised mailbox at the time, expect a denial.
Insurance Times 2025. Read your social-engineering rider before you need it.

AI-fraud law is still catching up

The regulatory frame around AI-enabled BEC is fragmented and moving fast:

  • State deepfake laws (California, Texas, New York, and roughly twenty others) mostly target elections and non-consensual imagery, not financial fraud. They rarely give a BEC victim a usable cause of action.
  • NYDFS Part 500 updates require financial-services firms to implement controls against AI-augmented social engineering, including phishing-resistant MFA and 72-hour incident reporting.
  • FinCEN advisories have called out AI-generated business identity fraud and require suspicious-activity reporting for suspected deepfake-enabled wire fraud.
  • The EU AI Act requires labeling of AI-generated content but does not retroactively protect prior victims.
Bottom line: legislation describes the threat. It does not stop it. Your controls have to.
Map the attack to the defense

How Cythentic helps you stop it, phase by phase

Every step of the attack chain maps to something you can verify, test, or fix. Most of it you can do yourself with the controls above. Where you want independent proof, or a second set of eyes, this is where we come in.

Attack phaseWhat the attacker doesHow Cythentic helps
1 · CompromiseA phishing kit steals the session cookie and MFA is bypassed.MFA gap analysisRemi™We verify that phishing-resistant MFA is actually enforced everywhere, including the bypass paths a login screen never shows. Remi walks every employee through setting it up on their own accounts.
2 · WatchHidden inbox rules, ForwardingSmtpAddress, and OAuth grants keep the attacker inside.Security assessmentFree scanWe audit forwarding rules, OAuth grants, and audit logging across the tenant, and the free exposure scan shows your email authentication posture from the outside.
3 · IdentifyThe AI maps your vendors, invoices, and approval workflow.Phishing assessmentRemiA controlled campaign shows exactly who clicks, before an attacker finds out. Remi keeps coaching them afterward.
4 · StrikeA look-alike domain or hijacked thread delivers the banking change, backed by a voice clone if needed.Free scanPlaybookThe exposure scan surfaces look-alike domains and DMARC gaps. The playbook above gives finance the callback procedure and codeword that defeat the deepfake.
5 · DrainThe wire moves to a mule network and the 72-hour recovery window starts.IR readinessHave a BreachWe build and rehearse the first hour before you need it. If it is happening now, Corey has led response on some of the largest breaches on record.
FoundationEverything above sits on a network an attacker may already be inside.Penetration testVirtual CISOIndependent testing of the external and internal network, and ongoing security leadership without a full-time hire.
Do not wait for the wire to go out

Find out what an attacker already sees

The free exposure scan shows your email authentication gaps, look-alike domains registered against your brand, and what is exposed to the internet, in about a minute, with nothing to install. Then put Remi in front of every employee so the people who approve your wires are the hardest ones to fool.

Verifying the ten controls across every mailbox, testing your people, and proving it to your insurer is what a Cythentic engagement handles. Business email compromise is where businesses actually lose money, so it is the first thing we lock down.