CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard
An attacker compromises the email account of a company's trusted vendor and, mimicking the vendor's writing style and past invoice format, sends an urgent email to the client's accounts payable department requesting that future payments be redirected to a new bank account. The finance employee, recognizing the familiar contact and context, updates the payment details and wires $85,000. Which social engineering attack does this best describe?
- ABusiness email compromise (BEC)
- BVishing
- CTyposquatting
- DWhaling
Show answer & explanationAnswer & explanation
Correct answer: A. Business email compromise (BEC)
Business email compromise involves compromising or spoofing a trusted business email account to manipulate an organization into fraudulent financial transactions, exploiting existing trust relationships rather than targeting a specific high-profile executive or using voice calls.
Why the other options are wrong
- B. Vishing uses voice/phone calls to manipulate victims, not compromised email accounts.
- C. Typosquatting registers lookalike domains to deceive users, not compromising an actual existing account.
- D. Whaling specifically targets high-profile executives as the victim, not accounts payable staff via a vendor account.
Business Email Compromise (BEC)
A social engineering attack in which an attacker compromises or spoofs a trusted business email account to trick an organization into making fraudulent wire transfers or disclosing sensitive information.
- Often targets accounts payable/finance staff via vendor or executive impersonation
- Relies on existing trust relationships and plausible context (invoices, urgency)
- Mitigated by out-of-band payment verification and email authentication (DMARC/SPF/DKIM)
Memory trick: BEC = a wolf wearing the vendor's email suit to steal the payroll