CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard

An attacker compromises the email account of a company's trusted vendor and, mimicking the vendor's writing style and past invoice format, sends an urgent email to the client's accounts payable department requesting that future payments be redirected to a new bank account. The finance employee, recognizing the familiar contact and context, updates the payment details and wires $85,000. Which social engineering attack does this best describe?

  1. ABusiness email compromise (BEC)
  2. BVishing
  3. CTyposquatting
  4. DWhaling
Show answer & explanation

Correct answer: A. Business email compromise (BEC)

Business email compromise involves compromising or spoofing a trusted business email account to manipulate an organization into fraudulent financial transactions, exploiting existing trust relationships rather than targeting a specific high-profile executive or using voice calls.

Why the other options are wrong

  • B. Vishing uses voice/phone calls to manipulate victims, not compromised email accounts.
  • C. Typosquatting registers lookalike domains to deceive users, not compromising an actual existing account.
  • D. Whaling specifically targets high-profile executives as the victim, not accounts payable staff via a vendor account.

Business Email Compromise (BEC)

A social engineering attack in which an attacker compromises or spoofs a trusted business email account to trick an organization into making fraudulent wire transfers or disclosing sensitive information.

  • Often targets accounts payable/finance staff via vendor or executive impersonation
  • Relies on existing trust relationships and plausible context (invoices, urgency)
  • Mitigated by out-of-band payment verification and email authentication (DMARC/SPF/DKIM)

Memory trick: BEC = a wolf wearing the vendor's email suit to steal the payroll

More Attacks and Exploits questions