8 minutes reading time

BEC (CEO Fraud): Real Scenarios from Türkiye and a Defense Guide

Why do BEC attacks—no virus, no link, pure persuasion—slip past filters? CEO fraud, invoice, payroll and attorney scams; Türkiye field scenarios and a people+process+technology defense.

The accounting manager of an export manufacturer received a familiar email from the Italian supplier she had worked with for three years: "We've changed our bank account; please send all future payments to the new IBAN." The email carried the supplier's real letterhead, real signature block, and even a quoted history of previous correspondence. The accounting manager sent that month's EUR 92,000 payment to the new account. The money had evaporated by the time the supplier called three days later asking, "Why haven't you paid us?"

This is a classic BEC (Business Email Compromise) attack. No virus, no malicious link, no suspicious attachment. Just an email written to the right person, at the right time, in the right tone. That's precisely why most technical filters can't see it.

In this article we cover the concrete forms BEC takes in Türkiye, the anatomy of an attack, and why SPF/DKIM/DMARC alone aren't enough. We close with how to defend using the people + process + technology trio.

 


 

1. What Is BEC, and How Is It Different from Phishing?

 

Ordinary phishing is mass and opportunistic: thousands of people receive the same fake "your parcel is waiting" email. BEC, by contrast, is targeted and patient. The attacker first studies the victim, maps the org chart, learns correspondence habits, and then writes to a single person — usually someone with authority over money movement.

According to FBI IC3 data, BEC has for years been the cybercrime category causing the highest financial loss — more than ransomware. The reason is simple: in BEC there's no file to encrypt or data to exfiltrate; the money itself is the target, and once a wire goes out, recovery is very hard.

 

2. The Four Forms of BEC We See in Türkiye

 

2.1 CEO/Executive Fraud

 

The best-known form. An attacker impersonating the "CEO" or "General Manager" requests an urgent and confidential transfer from the finance team. Pressure is usually applied: "I'm in a meeting, can't call, handle this quietly." The target is the reflexive obedience to hierarchical authority.

 

2.2 Vendor/Invoice Fraud

 

The opening scenario above. A real supplier's account is compromised or impersonated; the IBAN in the payment instruction is changed. Türkiye's export- and import-heavy structure makes this form especially risky — foreign-currency, high-value, cross-border transfers are the hardest payments to recall.

 

2.3 Payroll Diversion

 

The attacker impersonates an employee and emails HR: "I've changed my salary account." Because amounts are low, detection comes late; it can be attempted for dozens of employees at once.

 

2.4 Attorney Impersonation

 

Under the pretext of a "confidential acquisition/merger," a supposed lawyer or advisor imposes urgency and secrecy. Telling the victim "don't share this with anyone" is meant to disable natural control mechanisms (second approval, confirmation call).

 

3. The Anatomy of a BEC Attack

 

A typical attack we see in the field goes through these steps:

  1. Reconnaissance: The attacker works out who the CFO, accounting manager, and CEO are via LinkedIn and the company website. The vast majority of BEC cases we've seen in Türkiye were prepared by scraping the target's public LinkedIn org structure.
  2. Timing: A period is chosen when the executive is traveling or on leave and the auto-reply is on. The "boss is unreachable" situation makes a confirmation call difficult.
  3. Identity spoofing: Three techniques are used together — display name spoofing (correct display name, fake email address), look-alike domain (e.g., kinetlkbilisim.net — "l" instead of "i"), and reply-to manipulation (replies go to a different address).
  4. Social pressure: Urgency ("this has to close today"), secrecy ("don't tell anyone"), authority ("I requested it"). This trio is designed to stop the victim from thinking critically.
  5. Money movement and loss: The transfer happens; the money is quickly split across several accounts and withdrawn. Inter-bank recall processes are slow; cross-border, they're often impossible.

 

4. Why SPF, DKIM, and DMARC Alone Aren't Enough

 

SPF, DKIM, and DMARC are authentication protocols that make it harder to impersonate your domain, and they absolutely must be configured correctly. (We recommend our email sending and authentication article on this.) But many forms of BEC fall outside the scope of these protocols:

  • Look-alike domain: The attacker doesn't spoof your domain; they use a similar domain (kinetlkbilisim.net) that they own. That domain passes its own SPF/DKIM/DMARC records — because it genuinely belongs to them.
  • Display name spoofing: The email address may be entirely foreign (like gmail.com), but the display name reads "General Manager." Authentication protocols don't inspect the display name.
  • Compromised real account: If the supplier's account is genuinely taken over, the email comes from a real, authenticated account — all protocols pass successfully.

In short, DMARC is necessary to protect your domain but doesn't solve the social-engineering side of BEC. That requires a contextual, behavioral analysis layer.

 

5. Defense: People + Process + Technology

 

People

Everyone with money-movement authority should recognize BEC scenarios. Regular, realistic phishing/BEC simulations (Security Awareness Training) build this reflex. The key message: the trio "urgency + secrecy + unusual payment instruction" is always a reason to pause.

Process

A bulletproof rule, independent of technology: bank/IBAN changes and transfers above a certain amount are not processed without confirmation through a second channel independent of email (a call-back to a pre-registered phone number). This single rule prevents the majority of BEC losses we see in the field.

Technology

Check Point Harmony Email & Collaboration approaches BEC specifically with a behavioral AI engine:

  • It learns internal correspondence patterns: a CFO's recent writing style with a CEO, vocabulary, typical file types are modeled. Deviations are flagged.
  • It detects look-alike and newly registered domains ("this domain was registered 4 days ago and closely resembles yours").
  • It shows the user a visible warning banner for mismatches between display name and real email address ("the display name belongs to your CEO but the address is a Gmail account").
  • It flags cases where the reply-to address differs from the sender address.

This detects, via contextual signals, emails that contain no technical harm and that classic rule-based filters can't catch. For a broader architectural discussion, see our why Microsoft 365's built-in email security falls short article.

 


 

Frequently Asked Questions

 

I set DMARC to "reject" — am I protected from BEC?

 

DMARC reject prevents email being sent by spoofing your domain — that's very valuable. But BEC attacks using a look-alike domain (the attacker's own similar domain) and display name spoofing fall outside DMARC's scope. DMARC is necessary but not sufficient on its own.

 

Why do BEC attacks target export companies in Türkiye more?

 

Because in export/import companies, foreign-currency, high-value, cross-border transfers are a routine workflow. A request like a supplier IBAN change doesn't look unusual there. And cross-border transfers are the hardest money movements to recall.

 

Isn't training my employees enough?

 

Training is critical but not sufficient alone. A well-crafted BEC email can catch even the most careful employee in a tired or busy moment. That's why people + process (second-channel confirmation) + technology (behavioral AI) layers must work together.

 

Does Check Point Harmony really catch BEC when there's nothing malicious inside?

 

Yes, because the approach looks not for a "malicious element" in the content but for a contextual anomaly: deviation in writing style, domain age, display name/address mismatch, reply-to manipulation. These signals flag BEC even with no link or attachment in the email.

 

We've been hit by a BEC attack — what should we do?

 

First, contact your bank immediately to attempt a recall of the transfer — the first hours are critical. Then notify law enforcement. On the technical side, if an account was compromised, reset passwords, enforce MFA, and check for unauthorized mailbox rules in the inbox. We can support you through this process.

 


 

What Should You Do Now?

 

If your company has teams with money-movement authority and you've seen at least one "odd" payment request in the past year, it's worth measuring what your current protection does against BEC.

We offer two free steps:

  1. Field Audit: We report your domain's SPF/DKIM/DMARC status, look-alike domain risks, and your BEC exposure surface.
  2. 14-Day Check Point Trial (monitor mode): Without touching your existing protection, we report the BEC attempts the behavioral AI catches.

Schedule an intro meeting

 


 

About this article: Kinetik Bilişim is the Türkiye partner of Check Point Software Technologies at the Advanced Partner 2026 level and holds the Email Solution Specialization accreditation. Field scenarios are shared in anonymized form from cases we've seen among our enterprise customers in Türkiye. No details belonging to any specific customer have been shared. BEC definitions align with the FBI IC3 and MITRE ATT&CK frameworks.