Business Email Compromise (BEC)
Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.
Why it matters to you
The control that works is out-of-band verification of any payment change, on a number you already had. Everything upstream of that is detection; this is the step that stops the loss.
Where we meet it
The access is bought before the fraud is committed, and it is sold as mailbox access rather than as a password. That gap is the interval a defender can still act in.
Connected terms
Mailbox access
A working login to a corporate or personal mailbox, sold as access rather than as a password. The buyer reads, replies and resets other accounts from inside a mailbox its owner is still using.
Lookalike domain
A domain registered to be misread as someone else's: a swapped character, an extra hyphen, a different suffix. The cheapest piece of infrastructure in this economy and the one most often pointed at a brand.
Cashout
The last mile: turning stolen access, cards or balances into money the criminal keeps. Gift cards, crypto, mule accounts, reshipping, each with its own fee and its own specialists.
Read elsewhere
Where this term stops being vocabulary
Dragnet is where you watch it happen to you
Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.
More from the playbook
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Callback phishing
An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.
Checker
A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.
ClickFix
A lure that tells the visitor the page is broken and asks them to fix it: copy this, press these keys, paste, run. The victim performs the delivery by hand, so nothing was downloaded and nothing was blocked.