← All posts

How Does Business Email Compromise Actually Happen?

September 16, 2026

From the first phishing page to the fraudulent invoice: the real kill chain behind a business email compromise, stage by stage.

Business email compromise looks like a single event to the victim — a bad invoice — but it is the last step of a patient process.

Stage 1: reconnaissance

The attacker maps the org from public sources: who approves payments, who reports to whom, who the suppliers are, when leadership travels. Nothing illegal happens yet.

Stage 2: access

Three common routes. A phishing page that harvests the password. An adversary-in-the-middle page that captures the session token and therefore defeats app-based MFA. Or credential reuse, where a password leaked elsewhere still works on your tenant.

Stage 3: persistence

Once inside, the attacker makes sure a password reset will not cost them access: an OAuth consent grant, an app password, their own MFA method, or mailbox delegation.

Stage 4: quiet observation

Days to weeks of reading. Learning your invoice format, your approval language, your payment cycle, the phrases your CFO uses. Meanwhile a hidden rule keeps the eventual fraud thread out of the owner's sight.

Stage 5: the pivot

Either they hijack an existing thread and reply with new bank details, or they register a lookalike domain and move the conversation off your tenant so containment does not interrupt them. Internal phishing from the trusted mailbox is a common side quest, expanding access before the payday.

Stage 6: the ask, and the exit

A precisely timed payment instruction. Once the money lands, it is dispersed within a day or two, which is why the recovery window is measured in hours.

Where to break the chain

Phishing-resistant MFA breaks stage 2. Alerting on consent grants and forwarding rules breaks stages 3 and 4. Out-of-band payment verification breaks stage 6 even when everything else failed. Defence in depth here is not a slogan — each layer catches a different stage. Our managed detection and response service is built around the middle stages, where dwell time makes detection possible.


Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.

BECkill chainphishingsecurity awareness

24 / 7 Recovery

When the worst day hits, every minute matters.

Our breach team is standing by — call, email, or submit a request and we respond within minutes.