How BEC Attacks Are Evolving in the AI Era
AI has not reinvented Business Email Compromise. It has made it faster for attackers to research people, personalize messages, manage conversations, and impersonate trusted identities.
Business Email Compromise, or BEC, has always worked by abusing trust., or BEC, has always worked by abusing trust. The attacker does not need malware if they can convince the right person to take the wrong action.
AI has not changed that basic idea. It has changed the speed and scale.
Attackers can research targets faster, write more believable messages, adapt their language, and manage more conversations at once. That is why modern BEC can look simple on the surface while becoming harder to catch in practice.
According to Microsoft's Q2 2026 email threat research, generic outreach such as "Are you at your desk?" made up 87-92% of initial BEC contact emails during the quarter. Direct requests for financial transactions or documents were only 3-8%.
Attackers are not always trying to win in the first message.
They are trying to get you to answer.
BEC Still Starts With Trust
People often imagine BEC as an obvious payment request:
`I need you to make an urgent transfer.
That happens, but many attacks start earlier.
The attacker asks whether you are available. They ask for a quick favor. They pretend to follow up on something routine. The first message does not need to contain the fraud. It only needs to start the conversation.
Once you reply, the attacker can build context and introduce the real request later.
That makes BEC difficult to detect because the first email may have:
- no malicious link;
- no malware;
- no attachment;
- no fake login page;
- no known bad domain.
The danger is not always in the message itself. Sometimes the danger is the conversation the message creates.
What AI Changes
AI gives attackers leverage.
It can turn public information into a believable message quickly. It can rewrite the same request in different tones. It can translate messages. It can help attackers personalize outreach for different roles, teams, and companies.
Microsoft's 2026 research into AI as attacker tradecraft describes threat actors using AI to customize phishing messages with scraped information such as job titles, companies, and recent activity.
An attacker might start with simple data:
Name: Sarah
Role: Accounts Payable Manager
Company: Example Corp
Manager: David
Location: Portugal
Languages: Portuguese and English
With AI, they can quickly turn that into several possible approaches:
- a CEO request;
- a supplier follow-up;
- a payroll update;
- a document request;
- an internal task.
AI does not create trust from nothing. Attackers still need useful information.
But once they have it, AI makes social engineering cheaper to write, localize, and test.
BEC Is Getting Easier To Scale
BEC used to feel mostly manual: one attacker, one target, one carefully written conversation.
That still exists, but automation is changing the economics.
In June 2026, Microsoft observed a BEC campaign that reached more than 67,000 users across more than 42,000 organizations in under three hours.
The campaign used business-information and payroll-diversion lures. Microsoft found that the attacker generated messages programmatically, sent them through the Amazon Simple Email Service API, inserted per-message variables, targeted role-based addresses, and used tracking identifiers to measure engagement.
The messages had no malicious links or attachments.
That campaign shows automation, not necessarily generative AI. But it shows how naturally AI can fit into the same workflow.
- Collect target data
- Generate message variations
- Send personalized outreach
- Track replies
- Adapt the follow-up
The result is not that every message becomes brilliant. The result is that attackers can scale messages that are good enough.
The First Message May Look Harmless
For BEC, the best opening message may be four words:
Are you available today?
That kind of message gives very little away. If the attacker asks for money, credentials, or a document immediately, the user and the security system have more context to judge.
A short opener looks like normal work.
Then the attacker uses the reply to guide the next step:
Attacker:
Are you available?
Recipient:
Yes, what do you need?
Attacker:
I'm tied up in a meeting.
Can you help me with something quickly?
Recipient:
Sure.
Attacker:
[The real request begins]
By the time the sensitive request appears, the conversation already feels familiar.
That is why one email is not always enough. To detect BEC well, you need to understand the conversation around the message.
Impersonation Is Moving Beyond Email
BEC still has "email" in the name, but the trust attack can move across channels.
An attacker can start by email and then push the target to a messaging app, a phone call, or a voice note. They can also use another channel to make the email feel more credible.
Microsoft has documented threat actors using voice cloning to impersonate executives or trusted individuals in vishing and BEC scams. The FBI has also warned about criminals using synthetic voices, fake videos, and other AI-generated content to make impersonation more convincing.
The FBI's 2025 Internet Crime Report summary reported 22,364 complaints involving AI-related information and nearly $893 million in losses across AI-related fraud categories.
This does not mean every BEC attack now uses deepfakes.
It means verification needs to be more careful.
Do not verify a suspicious request by replying to the same thread. Do not call a number from the suspicious message. Do not treat a voice note as proof of identity.
Use a contact method or business process you already trust.
How To Defend Against AI-Era BEC
You do not need an "AI-only" defense strategy.
You need stronger ways to evaluate trust.
Start with identity. Is the sender really who the recipient thinks they are?
Then look at the relationship. Has this person contacted the recipient before? Is the request normal for them? Did the tone, timing, destination, payment detail, or process suddenly change?
Look at intent too. A message does not need a malicious link to create risk. Requests involving payments, payroll, bank details, credentials, sensitive documents, account changes, secrecy, or urgent exceptions deserve extra scrutiny even when the email looks clean.
Useful signals include:
- first-time communication;
- unusual sender-recipient relationships;
- changes in historical communication patterns;
- new reply-to destinations;
- executive or trusted-party impersonation;
- similar outreach across multiple employees;
- unusual activity from legitimate accounts;
- conversation-level intent.
The goal is not to treat every short email as malicious. The goal is to notice when a normal-looking message does not fit the behavior around it.
The Core Problem Has Not Changed
AI has not replaced Business Email Compromise.
The attacker still wants the same thing: your trust.
What changed is the amount of work required to earn and exploit that trust.
Attackers can research faster, personalize more messages, communicate across languages, adapt conversations, and support impersonation with synthetic audio or video.
But the most dangerous BEC email may still look incredibly simple.
It may have no payload. No malware. No suspicious link. It may only ask:
Are you available?
That is why defending against BEC in the AI era requires more than asking whether an email looks malicious.
You have to ask whether the behavior behind the message makes sense.





