IntelliOS Threat Intel Operating System
← Activity Cards

Business Email Compromise Activity Card

BEC Activity — June 2026

June 2026 BEC activity combined rising attack volume with higher requested wire amounts, continued gift-card and payroll diversion, and identity-centric techniques that can bypass basic MFA through token and session theft.

Published · v4June 1–30, 20264 retained sources

+22%[1]

Period-over-period change

Fortra FIRE June versus May active-defense engagements

59.9%[1]

Gift-card cash-out

Share of Fortra-observed June cash-out methods

$71,295[1]

Average wire request

32% higher than Fortra's May average

72%[1]

Free-webmail delivery

Fortra-observed June BEC sending infrastructure

Top 10 Briefing Points

  1. 1

    Fortra observed a material June increaseFortra FIRE reported a 22% increase in BEC attack volume from May to June across its active-defense engagements; this is a vendor dataset, not a global incident count.[1]

  2. 2

    Gift cards remained the leading cash-out methodGift cards represented 59.9% of Fortra-observed cash-out methods, with Apple Store requests comprising 53.6% of gift-card requests.[1]

  3. 3

    Average wire requests became more severeThe average requested BEC wire increased to $71,295, 32% above May, even though Fortra observed a 7% decline in wire-transfer attack frequency.[1]

  4. 4

    Free webmail dominated sending infrastructureFortra attributed 72% of observed attacks to free-webmail addresses and 28% to maliciously registered domains, reinforcing that many BEC lures do not require sophisticated infrastructure.[1]

  5. 5

    BEC is an identity and session problem, not only an email-filter problemMicrosoft documented AiTM flows that capture authentication tokens and bypass non-phishing-resistant MFA, giving attackers immediate account access.[2][4]

  6. 6

    Trusted services and identities increase lure credibilityMicrosoft observed SharePoint delivery, trusted compromised senders, internal identity reuse, and follow-on phishing across organizations.[4]

  7. 7

    Password resets alone can be insufficientBEC containment should include session revocation, inbox-rule removal, OAuth and MFA-method review, and investigation of newly created persistence.[4]

  8. 8

    Vendor impersonation remains a major loss pathBeazley's Q1 incident-response data identified vendor impersonation as the leading BEC vector and found basic MFA present in approximately 53% of handled cases.[3]

  9. 9

    Professional services and finance deserve focused scrutinyProfessional services and financial institutions represented a combined 37% of Beazley's investigated Q1 BEC cases, reflecting payment-flow and client-interaction exposure.[3]

  10. 10

    Fast bank coordination can determine recoveryOn any suspected diversion, preserve messages and audit logs, contact the financial institution immediately, validate payment changes out of band, and scope every affected identity and trusted relationship.[1][3][4]

Activity Signals

  • Gift-card fraud
  • Wire-transfer diversion
  • Payroll diversion
  • AiTM token theft
  • Vendor impersonation
  • Trusted-identity phishing

Initial Access Patterns

  • Credential phishing
  • AiTM session interception
  • Compromised vendor accounts
  • Typosquatted vendor domains
  • Trusted SharePoint links

Target Sectors

  • Professional services
  • Financial institutions
  • Healthcare
  • Technology
  • Organizations with frequent vendor payments

Business Impact

  • Fraudulent wire transfers
  • Payroll diversion
  • Gift-card loss
  • Mailbox and sensitive-message exposure
  • Client and vendor trust erosion
  • Notification and litigation exposure

Defensive Priorities

  • Require phishing-resistant MFA for payment and executive roles
  • Verify payment changes through a known out-of-band channel
  • Use dual approval for wires and payroll changes
  • Alert on inbox rules, OAuth grants, MFA changes, and anomalous sessions
  • Maintain immediate financial-institution and law-enforcement escalation procedures

Citations

Retained Sources and Claim Treatment

#PublisherPublishedWhy Used / Claim TreatmentSource
1Fortra FIREprimary research2026-07-08Metrics reflect Fortra's active-defense engagements and should not be treated as the entire BEC market.BEC Global Insights Report: June 2026

https://www.fortra.com/blog/bec-global-insights-report-june-2026

2Microsoft Defender Security Researchprimary research2026-05-04Campaign-specific Microsoft telemetry; used for technique and exposure context, not June volume.Breaking the code: Multi-stage phishing leads to AiTM token compromise

https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/

3Beazley Securityincident response2026Incident-response and MDR case mix; sector and outcome percentages are dataset-scoped.Quarterly Threat Report: First Quarter, 2026

https://beazley.security/insights/quarterly-threat-report-first-quarter-2026

4Microsoft Defender Security Researchprimary research2026-01-21Campaign-specific evidence supporting session theft, inbox-rule persistence, and trusted-identity propagation.Resurgence of a multi-stage AiTM phishing and BEC campaign abusing SharePoint

https://www.microsoft.com/en-us/security/blog/2026/01/21/multistage-aitm-phishing-bec-campaign-abusing-sharepoint/