BEC Isn't an Email Problem. It's a Supply Chain.

Underground forums reveal Business Email Compromise as a multi-stage operation built on account access, target research, and cash-out networks, not a clever phishing lure.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
BEC Isn't an Email Problem. It's a Supply Chain.
Share

Key points - BEC is a coordinated criminal supply chain, not a phishing trick. - Initial access brokers sell corporate mailbox credentials, with session cookies prized for bypassing multi-factor authentication. - Attackers spend days reading email threads before touching a single transaction. - Lookalike domains and malicious inbox rules are the two most common pivot techniques. - Out-of-band payment verification and inbox-rule hunting are the controls that actually interrupt the chain.

Business Email Compromise gets filed under "phishing" the way SQL injection gets filed under "web bugs." Technically true. Wildly incomplete.

The FBI's IC3 has BEC sitting at the top of the financial-loss charts for years, with reported losses running into the tens of billions globally since 2013. Those figures don't come from clever Nigerian-prince emails. They come from a working criminal supply chain, and the underground forums are not shy about advertising it.

How does the attack actually start?

Initial Access Brokers sell credentials to corporate mailboxes by the bundle. Business accounts command a premium over consumer ones, because the buyer already knows the end use. Much of that inventory comes from infostealer logs, Redline, Lumma, StealC, dumped into Telegram channels and forum threads. Session cookies are the prize. They sidestep multi-factor authentication the same way a stolen session token sidesteps a login form. We first covered the credential-broker economy feeding this pipeline in "The 'Search-as-a-Service' Economy Built on Stolen Credentials" on 22 June 2026.

What happens once an attacker is inside?

They read. Invoice threads, vendor relationships, the CFO's travel schedule, who signs off on wire transfers and under what threshold. Forum posts trade tips on which industries pay fastest and which banks raise the fewest flags on large transfers. This is the stage defenders consistently underweight. There is no technical exploit here, only patience.

When the attacker is ready to move, two plays dominate. Either they register a lookalike domain (rnellow.com instead of mellow.com) and inject themselves into an existing invoice thread, or they send from the real compromised mailbox and quietly add an inbox rule that routes replies to a folder nobody watches. Classic, and still effective.

Cash-out follows: mule networks, crypto off-ramps, rotating "drop" bank accounts. Forums advertise mule recruitment the way legitimate vendors advertise uptime guarantees.

Should you worry if your sector isn't finance?

Forum intelligence suggests attackers choose targets partly by speed of payment and partly by how little friction their banks apply to outbound wires. That logic reaches well beyond financial services. Any organization with predictable invoice cycles or external vendor relationships is a candidate.

What actually helps?

Treat infostealer infections as identity incidents rather than malware incidents. If a corporate cookie appeared in a stealer log, that session is burned. Revoke it immediately. Our coverage of infostealer churn, collected across six stories in the past 90 days, keeps returning to this same point: the credential is the intrusion.

Monitor for lookalike domain registrations against your own brand and your top vendors. Certificate Transparency logs are free and updated in near-real time.

Require out-of-band verification for any payment instruction change. A phone call to a known number, not a reply to the email requesting the change.

Hunt for malicious inbox rules.

None of this is novel. It is hygiene applied to the right layer. As our 29 June story noted, the phishing payload is gone; the pretext is the payload now, and most secure email gateways were never designed to catch it. BEC keeps working because organizations defend the inbox while the supply chain feeding it runs uncontested. Attackers figured that out years ago.

© 2026 Threat Vectr