BEC Keeps Winning Because It Looks Exactly Like Normal Work

The phishing payload is gone. The pretext is the payload now, and your SEG was never built for that.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
BEC Keeps Winning Because It Looks Exactly Like Normal Work
Share

Key points

  • Business email compromise succeeds because it mimics normal business behavior, not because it delivers malware.
  • Secure email gateways were built for artifact-based threats and miss impersonation-only attacks.
  • Behavioral AI detection needs a clean baseline or it learns the attacker's behavior as normal.
  • The control that stops wire fraud is an out-of-band callback, not an inbox banner.
  • Audit log signals in Google Workspace and Microsoft Graph matter more than message-body analysis.

The dirty secret of business email compromise is that nothing detonates. No attachment to sandbox, no macro to flag, no second-stage payload phoning home to a freshly registered domain. It's a person, writing an email, asking another person to do something the business does every day.

That's why BEC keeps clearing the bar.

Why your email gateway can't see it

Secure email gateways were architected for a threat model where badness lives in the artifact. Strip the artifact, write fluent English, register a lookalike domain or compromise a real mailbox upstream at a supplier, and the message sails through. The signal isn't in the headers. It's in the behavior.

That's the pitch behind the wave of behavioral AI email products: instead of asking whether an attachment is malicious, they ask whether this sender, on this thread, at this time, requesting this action, fits the historical pattern. Does the CFO routinely email the AP clerk about wire changes near midnight from a mobile client? Does this vendor normally send invoices from a Gmail address? Has an internal account suddenly started creating inbox rules that auto-delete replies from the real recipient?

We've covered this vendor argument twice before: our 15 June piece asked what pattern-learning models mean for breach-notification timelines, and our 23 June story noted that SOC alert volume is precisely the problem these tools claim to solve.

Should you trust the behavioral AI pitch?

The approach is sound. It's also not magic. A few things worth saying out loud before you sit through another vendor webinar:

  • Behavioral models need a clean baseline. If your tenant is already compromised when you turn detection on, the "normal" the model learns includes the attacker.
  • Auto-remediation is where these tools earn their keep, but only if you trust the verdict enough to claw back messages from inboxes without a human in the loop. Most SOCs don't, at first.
  • The detections that matter most for BEC are usually in Google Workspace or Microsoft Graph audit logs: inbox rule creation, OAuth app consent grants, impossible travel. Whatever you buy must read those signals, not just SMTP headers.
  • The "AI" part is doing less than the marketing suggests. Most of the lift is graph analysis of communication patterns plus NLP for tone and intent. That's fine. Call it what it is.

What actually stops a wire going out

Every post-mortem says the same thing: the wire went out because a human believed another human. The control that would have stopped it was an out-of-band callback to a known phone number, not an inbox banner that says "external sender." Banners are wallpaper now.

If you're evaluating tools in this space, push the vendor on false-positive rates against your finance team's actual mail flow, and ask exactly which Microsoft Graph or Workspace APIs they consume. The rest is theater.

Treat BEC as an identity and process problem with an email-shaped symptom, and budget accordingly.

© 2026 Threat Vectr