The Phishing That Leads to BEC — And Why It Looks So Ordinary
September 16, 2026
The email that starts a business email compromise is usually dull: a shared document, a voicemail, a DocuSign. Here is what makes it work.
Nobody clicks the obvious scam. The phishing that produces a business email compromise is deliberately mundane.
The lures we see most
- A shared file notification that mirrors SharePoint or Google Drive
- A voicemail or fax notification with an attached "player" link
- A signature request styled like DocuSign or Adobe Sign
- A "your password expires today" notice with your own branding
- A quarantined-message digest from what looks like your own filter
- An internal message from a colleague whose mailbox is already compromised
That last one is the important one. Internal phishing from a genuine, trusted address converts at a far higher rate than anything from outside, which is why one compromise so often becomes several.
What happens after the click
Modern kits do not just store the password. They proxy the real login page in real time, pass the MFA challenge through to the user, and capture the session cookie. The victim lands on the actual application and notices nothing wrong. From the tenant's perspective, a legitimate sign-in occurred.
Detection worth building
- Sign-ins with an anomalous user agent, ASN, or geography for that user
- New OAuth consent grants and new forwarding rules — always
- Newly registered domains being visited from corporate devices
- Reported-phish volume as a health metric, not a nuisance queue
Training that actually moves the number
Simulate these specific lures, not a cartoon Nigerian prince. Make reporting one click and make it socially rewarded. Measure report rate alongside click rate — a workforce that reports fast gives your SOC the window it needs. Our awareness and phishing training programs are built on that pairing.
And accept the ceiling: some percentage of people will always click. That is why phishing-resistant MFA matters more than any awareness campaign.
Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.