According to a recent study, 74% of organizations reported Business Email Compromise (BEC) attempts in 2025, up from 63% the previous year. In addition, 85% reported receiving messages impersonating trusted entities, while more than half encountered lookalike domains designed to mimic legitimate organizations.
At first glance, these numbers seem surprising.
Organizations are investing more than ever in email security. Employees receive security awareness training. Advanced filtering systems block millions of malicious messages every day.
So why do the numbers keep rising?
The answer is that today’s BEC attacks look very different from the attacks we saw in the past.
Attackers are no longer relying solely on suspicious emails containing malicious links or attachments. Instead, they are embedding themselves into legitimate business processes.
An email that appears to come from the CEO.
An urgent request to approve a payment.
A supplier notifying the finance team of updated banking details.
A message that continues an existing email thread and looks completely legitimate.
In many cases, there is no malicious link. No attachment. Nothing that immediately appears suspicious.
The success of BEC attacks is not based on exploiting technical vulnerabilities. It is based on exploiting trust.
Attackers take the time to understand how organizations operate, who approves payments, who communicates with vendors, and which requests appear routine.
That is why even organizations with mature security programs continue to fall victim to these attacks.
Ultimately, the question is no longer whether an email contains malware.
The real question is whether an employee can recognize a manipulation attempt disguised as legitimate business activity.
And as attackers become better at understanding business processes, the line between genuine communication and fraud becomes increasingly difficult to see.
That is exactly why BEC attacks continue to grow, even in a world where organizations have more security tools than ever before.
