Financial Spear Phishing Digest

High-value BEC persistence and approval-phishing

High-value BEC persistence and approval-phishing

Key Questions

What are the latest trends in BEC and vendor email compromise attacks?

BEC accounts for 61-74% of incidents with heavy use of AI for payroll spoofing, invoices, and deepfakes, leading to losses like $25M at Wells Fargo and $25.6M at Arup; FBI reports exceed $3B annually. VEC often employs lookalike domains that bypass DMARC when attackers control the domain and set permissive policies.

How do attackers achieve long-term persistence in high-value email compromises?

One case showed a global stock exchange executive compromised for five months using legitimate tools like Aspose and Dropbox for exfiltration with repeated inbox theft. Techniques include inbox rule manipulation, shared access links, session hijacking via MFA bypass, and living-off-the-land approaches that avoid malicious attachments or URLs.

What makes deepfake-based BEC particularly challenging to defend against?

Deepfake fraud reached $3.7B with 89% occurring in 2025-2026, and detection tools lose 45-50% accuracy in real conditions while attacks can originate from social media or use video conference impersonation. Durable defenses focus on process changes like out-of-band verification and dual approvals rather than relying solely on detection tools.

How are attackers combining evasion tactics in recent BEC phishing campaigns?

Campaigns use link laundering through trusted security vendor wrappers, callback phishing via Google Calendar without malicious links, and compromised nonprofit domains mixing clean and malicious content to bypass SPF/DKIM/DMARC. Additional methods include Lua loaders disguised as font files and DocuSign-themed kits delivering RMM tools like ScreenConnect.

What controls are recommended to counter AI-powered BEC and approval phishing?

Experts advocate deterministic controls, supplier DMARC enforcement with RejectDirectSend policies, CASB/DLP for data exfiltration, and relationship history checks over manual review. ARToken-style BEC-as-a-service platforms and dark web deepfake tools highlight the need for layered defenses as AI lowers barriers for attackers.

Abnormal BEC>VEC (61%/26.5% vendor spoof); AI payroll/invoices/deepfakes (Wells $25M, Arup $25.6M). FBI $3B; AI voice vishing. New: URL manipulation taxonomy (link laundering via trusted vendor wrappers). New cases: fake Vistage invoice via Amazon SES, fake DocuSign with Google Maps redirect, fake Webroot callback via Google Calendar. City government BEC case ($913K). Deepfake fraud $3.7B; detection tools lose 45-50% accuracy; process redesign is durable defense. Classic homoglyph BEC case ($113K) reinforces need for out-of-band verification. Latest: Barracuda controlled test shows compromised inbox's own AI assistant (Copilot) can be weaponized for CEO impersonation and wire fraud—no malware needed. Independent verification of payment details critical. Recent research (Email Account Takeover Trends 2026) adds AI attack patterns and post-authentication signals. A detailed AiTM BEC case demonstrates vendor payment diversion via personalized HR lure (PTO Request Denied), session token hijack, and 30-day persistence with inbox rule concealment.

Sources (1)
Updated Aug 26, 2026