Business Email Compromise Activity Card
BEC Activity — June 2026
June 2026 BEC activity combined rising attack volume with higher requested wire amounts, continued gift-card and payroll diversion, and identity-centric techniques that can bypass basic MFA through token and session theft.
Top 10 Briefing Points
- 1
Fortra observed a material June increase — Fortra FIRE reported a 22% increase in BEC attack volume from May to June across its active-defense engagements; this is a vendor dataset, not a global incident count.[1]
- 2
Gift cards remained the leading cash-out method — Gift cards represented 59.9% of Fortra-observed cash-out methods, with Apple Store requests comprising 53.6% of gift-card requests.[1]
- 3
Average wire requests became more severe — The average requested BEC wire increased to $71,295, 32% above May, even though Fortra observed a 7% decline in wire-transfer attack frequency.[1]
- 4
Free webmail dominated sending infrastructure — Fortra attributed 72% of observed attacks to free-webmail addresses and 28% to maliciously registered domains, reinforcing that many BEC lures do not require sophisticated infrastructure.[1]
- 5
BEC is an identity and session problem, not only an email-filter problem — Microsoft documented AiTM flows that capture authentication tokens and bypass non-phishing-resistant MFA, giving attackers immediate account access.[2][4]
- 6
Trusted services and identities increase lure credibility — Microsoft observed SharePoint delivery, trusted compromised senders, internal identity reuse, and follow-on phishing across organizations.[4]
- 7
Password resets alone can be insufficient — BEC containment should include session revocation, inbox-rule removal, OAuth and MFA-method review, and investigation of newly created persistence.[4]
- 8
Vendor impersonation remains a major loss path — Beazley's Q1 incident-response data identified vendor impersonation as the leading BEC vector and found basic MFA present in approximately 53% of handled cases.[3]
- 9
Professional services and finance deserve focused scrutiny — Professional services and financial institutions represented a combined 37% of Beazley's investigated Q1 BEC cases, reflecting payment-flow and client-interaction exposure.[3]
- 10
Fast bank coordination can determine recovery — On any suspected diversion, preserve messages and audit logs, contact the financial institution immediately, validate payment changes out of band, and scope every affected identity and trusted relationship.[1][3][4]
Activity Signals
- Gift-card fraud
- Wire-transfer diversion
- Payroll diversion
- AiTM token theft
- Vendor impersonation
- Trusted-identity phishing
Initial Access Patterns
- Credential phishing
- AiTM session interception
- Compromised vendor accounts
- Typosquatted vendor domains
- Trusted SharePoint links
Target Sectors
- Professional services
- Financial institutions
- Healthcare
- Technology
- Organizations with frequent vendor payments
Business Impact
- Fraudulent wire transfers
- Payroll diversion
- Gift-card loss
- Mailbox and sensitive-message exposure
- Client and vendor trust erosion
- Notification and litigation exposure
Defensive Priorities
- Require phishing-resistant MFA for payment and executive roles
- Verify payment changes through a known out-of-band channel
- Use dual approval for wires and payroll changes
- Alert on inbox rules, OAuth grants, MFA changes, and anomalous sessions
- Maintain immediate financial-institution and law-enforcement escalation procedures
Citations
Retained Sources and Claim Treatment
| # | Publisher | Published | Why Used / Claim Treatment | Source |
|---|---|---|---|---|
| 1 | Fortra FIREprimary research | 2026-07-08 | Metrics reflect Fortra's active-defense engagements and should not be treated as the entire BEC market. | BEC Global Insights Report: June 2026 https://www.fortra.com/blog/bec-global-insights-report-june-2026 |
| 2 | Microsoft Defender Security Researchprimary research | 2026-05-04 | Campaign-specific Microsoft telemetry; used for technique and exposure context, not June volume. | Breaking the code: Multi-stage phishing leads to AiTM token compromise https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/ |
| 3 | Beazley Securityincident response | 2026 | Incident-response and MDR case mix; sector and outcome percentages are dataset-scoped. | Quarterly Threat Report: First Quarter, 2026 https://beazley.security/insights/quarterly-threat-report-first-quarter-2026 |
| 4 | Microsoft Defender Security Researchprimary research | 2026-01-21 | Campaign-specific evidence supporting session theft, inbox-rule persistence, and trusted-identity propagation. | Resurgence of a multi-stage AiTM phishing and BEC campaign abusing SharePoint https://www.microsoft.com/en-us/security/blog/2026/01/21/multistage-aitm-phishing-bec-campaign-abusing-sharepoint/ |
