Back to Blog
Threat IntelligencePhishingBusiness Email CompromiseBECSocial EngineeringDeepfakeThreat IntelligenceCybersecurity Indonesia

Modern Phishing & BEC: When MFA Alone No Longer Protects Your Organization

Global BEC losses have surpassed USD 55 billion, and modern phishing now bypasses MFA through Adversary-in-the-Middle techniques, QR codes, and a USD 25.6 million deepfake video call. Complete guide: BEC variants, attack anatomy, real cases, detection, and layered defenses that actually work.

Cloudsphere Research Team

Threat Intelligence & Security Research

July 8, 2026
15 min read

Quick Answer

Business Email Compromise (BEC) is email fraud that impersonates an executive, vendor, or colleague to direct fund transfers — with cumulative global losses exceeding USD 55 billion (FBI IC3, 2013–2023). Modern phishing now bypasses OTP-based MFA through Adversary-in-the-Middle (AiTM) techniques that steal session cookies, QR codes (quishing), and deepfakes — as in the 2024 Arup case worth USD 25.6 million. Effective defense combines out-of-band verification for payment changes, phishing-resistant FIDO2/passkey authentication, an enforcing DMARC policy, and dual approval for large transfers.

Phishing Evolution in the AI Era

Phishing in 2026 is nearly unrecognizable from its classic tells. Emails with broken grammar and blurry logos have been replaced by generative-AI-written messages — typo-free, contextual, and personalized from LinkedIn data and prior breaches. Fake login pages are now pixel-perfect replicas of the real thing, complete with valid TLS certificates.

More worrying still: modern phishing no longer stops at password theft. Phishing-as-a-Service (PhaaS) platforms such as Tycoon 2FA and EvilProxy sell the ability to steal login sessions that have already passed MFA — making 'we already use MFA' no longer a guarantee of safety.

Phishing = The Most Reported Cybercrime

Phishing has consistently been the crime type with the highest number of reports to the FBI's IC3 for years, while BEC tops the charts in financial losses per incident — with cumulative global losses exceeding USD 55 billion (FBI, 2013–2023).

What Is BEC & Its Variants

Business Email Compromise (BEC) is fraud that impersonates a trusted party — an executive, a vendor, or a colleague — via email to direct fund transfers or data disclosure. Unlike mass phishing, BEC is highly targeted and often contains no malware or malicious links at all, allowing it to slip past traditional email security filters.

CEO Fraud

Impersonation

Attackers impersonate a director or C-level executive and instruct finance staff to make an 'urgent and confidential' transfer — exploiting authority and subordinates' reluctance to verify.

Vendor Email Compromise

Compromised Account

A real vendor's email account is hacked, and the attacker sends a legitimate invoice with the bank account swapped. The hardest variant to detect because it comes from a genuinely authentic address and thread.

Invoice / Payment Fraud

Financial

Fake invoices or 'payment account updates' sent from lookalike domains (cloudsphere.id vs cloudsphere-id.com), targeting accounts payable teams right before payment dates.

Payroll Diversion

HR

Attackers impersonate an employee and ask HR to change the salary destination account to one the attacker controls — small losses per incident, but extremely frequent.

Attorney Impersonation

Impersonation

Posing as a lawyer or consultant in a 'confidential transaction' (acquisition, legal dispute) that demands secrecy and speed — pressuring victims not to consult others.

Data Theft BEC

Data

It's not money being requested but data — for example, the entire workforce's payroll and tax records from HR, later used for identity fraud and follow-on attacks.

Modern Attack Techniques: AiTM, Quishing, Deepfakes

A wave of new techniques has rendered conventional defenses — including OTP-based MFA — insufficient. The following four techniques dominate today's phishing landscape.

OTP-Based MFA Is No Longer Enough

Modern AiTM kits are specifically designed to bypass SMS OTPs and authenticator apps. Only phishing-resistant methods — FIDO2/passkeys and hardware security keys — are immune to these relay attacks by design.

01

Adversary-in-the-Middle (AiTM) — Stealing Sessions, Not Passwords

Victims are directed to a reverse proxy (Evilginx, Tycoon 2FA, EvilProxy) that relays traffic to the real login site in real time. The victim genuinely logs in — including entering their MFA code — while the attacker copies the authenticated session cookie. With that cookie, the attacker gets in without needing the password or MFA.

02

Quishing — Phishing via QR Code

Malicious QR codes are embedded in emails, posters, or PDF documents. Because the URL hides behind an image, email gateways struggle to scan it — and victims scan it with personal phones outside corporate network protection.

03

Deepfake Voice & Video — Next-Generation Vishing

AI voice cloning needs only seconds of sample audio to imitate an executive. In the Arup case (2024), an employee was deceived in a video conference where every participant was a deepfake — and transferred USD 25.6 million.

04

AI-Generated Spear Phishing at Mass Scale

LLMs let attackers generate thousands of personalized spear-phishing emails — referencing real project names, colleagues, and business context harvested through OSINT — in minutes, in any language, including natural Indonesian.

Anatomy of a BEC Attack — Step-by-Step

A successful BEC is a weeks-long operation, not a single email. Understanding its stages helps you identify the best intervention points before money moves.

01

Research & Target Selection

Attackers map the org structure from LinkedIn, the company website, and data breaches: who the CFO is, who works in AP, which vendors are used, and what communication patterns look like.

02

Initial Access — Credential Phishing or Lookalike Domain

Two main paths: compromising a real mailbox (via AiTM phishing) to monitor from within, or registering a lookalike domain to impersonate from outside.

03

Silent Monitoring & Mailbox Rules

Once inside a mailbox, attackers read invoice and payment threads for weeks. They plant hidden inbox rules that automatically divert specific replies so the victim never notices the conversation has been hijacked.

04

Injection at the Perfect Moment

Right before a real payment falls due, the attacker inserts a 'bank account update' email into the genuine thread — with perfect context, writing style, and timing.

05

Transfer & Rapid Laundering

Funds are wired to money mule accounts, then split and moved across accounts and borders within hours. Reporting speed determines the odds of recovery.

Real Cases & Losses

BEC victims are not naive organizations — this list includes tech giants and global corporations with mature security teams. That is the proof that BEC attacks processes and people, not technology.

Arup — 2024

Deepfake

An employee of the global engineering firm in Hong Kong joined a video conference where every 'colleague and the CFO' was a deepfake. The result: 15 transfers totaling ~USD 25.6 million to attacker accounts.

Facebook & Google — 2013–2015

Invoice Fraud

A single Lithuanian individual impersonated hardware vendor Quanta Computer and billed fake invoices for two years — extracting over USD 120 million from two tech giants.

Toyota Boshoku — 2019

Vendor Fraud

Toyota's European subsidiary was deceived into changing a payment destination through convincing fake email instructions — losing roughly USD 37 million in a single transaction.

Ubiquiti Networks — 2015

CEO Fraud

Executive and vendor impersonation fraud led the finance team to transfer USD 46.7 million to overseas accounts. Part of the funds were recovered thanks to rapid reporting.

Government of Puerto Rico — 2020

Public Sector

Emails from a compromised employee account directed government agencies to change payment accounts — over USD 2.6 million was sent before the fraud was uncovered.

Indonesian Businesses

Indonesia

The 'vendor invoice with changed bank account' scheme and executive impersonation via WhatsApp/email are rampant against Indonesian companies — many go unreported to protect reputations, making real figures far larger than recorded ones.

Latest Statistics

The numbers below underline the scale of the problem: phishing is the favorite entry point, and BEC is the costliest cybercrime that rarely makes headlines.

$55B+

Cumulative global BEC losses 2013–2023

FBI IC3

$2.7B+

Reported BEC losses per year in the US alone

FBI IC3 2024

#1

Phishing: the most reported cybercrime type

FBI IC3

~$4.9M

Average cost of a breach originating from phishing

IBM Cost of a Data Breach

1,000+%

Surge in QR-code-based phishing since the technique took off

Email Security Industry Research

<60 sec

Median time for a victim to click a phishing link after opening the email

Verizon DBIR

Why These Attacks Get Through

BEC and modern phishing are designed to exploit how organizations work: hierarchy, deadlines, and trust in routine. Technology is only half the problem — the other half lives in process and psychology.

No Malicious Payload

BEC emails are pure text — no malware, no suspicious links. There is nothing for antivirus to 'detect'; the danger is the instruction itself.

Authority & Urgency

An order from 'the CEO' marked urgent and confidential pressures victims to act first and verify later. Hierarchical structures make subordinates reluctant to question.

Perfect Context

Attackers who monitor a mailbox for weeks know exactly which invoice is due and how each party writes — their fake email is as convincing as the real ones.

Fragile Payment Processes

Many organizations allow vendor bank account changes via email alone, with no separate-channel verification. Once the email is trusted, no safety net remains.

Channels Beyond Oversight

Attacks are shifting to WhatsApp, SMS (smishing), and phone calls (vishing) — channels unprotected by email gateways and rarely covered in security training.

AI Erases the Classic Tells

Typos, odd grammar, and generic greetings — the signals old awareness training taught — have all but vanished from AI-written phishing.

Detection & Indicators

Though difficult, BEC and modern phishing leave traces. The combination of technical detection and process vigilance below offers the best odds of catching them before losses occur.

AreaIndicators to Look ForTool/Control
Email AuthenticationSPF/DKIM/DMARC failures, lookalike domains (homoglyphs, different TLDs), reply-to differing from senderEmail Gateway / DMARC Monitoring
Mailbox AnomaliesNew inbox rules moving/deleting mail, automatic external forwarding, logins from unusual locations/ISPsMicrosoft 365 / Google Workspace Audit Log
Sessions & AuthenticationSuccessful MFA logins from different IPs in close succession (a sign of session tokens stolen via AiTM)Identity Protection / SIEM
Content & ContextBank account change requests, urgency + secrecy, requests to move the conversation to WhatsApp/personal channelsTraining + Verification Procedures
InfrastructureNewly registered domains resembling your company or vendors, TLS certificates for suspicious subdomainsBrand Monitoring / dnstwist / CT Logs
FinancialA vendor 'changing' bank accounts right before a large payment, destination accounts at unusual banks/countriesAP Procedures + Callback Verification

Layered Prevention

No single control stops BEC. Effective defense combines verification processes that cannot be bypassed, phishing-resistant authentication, and well-trained people.

  • Out-of-Band Verification for Payment Changes

    Every vendor bank account change or transfer request above a set threshold MUST be verified through a separate channel — a call to a number already on file (never the one in the email). Make it a procedure, not a suggestion.

  • FIDO2 / Passkeys for Critical Accounts

    Deploy phishing-resistant authentication at minimum for executives, finance, IT admins, and email accounts — the only MFA immune to AiTM by design.

  • DMARC with an Enforcing Policy

    Publish SPF, DKIM, and DMARC with a quarantine/reject policy so your domain cannot be spoofed — and monitor the reports to detect abuse.

  • Dual Approval for Large Transfers

    Separate duties: the person entering a payment differs from the one approving it. No single person — including the CEO — can order a large transfer alone via email.

  • Phishing Simulations & Continuous Training

    Test employees with realistic simulations (including QR codes and BEC pretexts), then turn results into training — not punishment. Focus on verification procedures, not just 'don't click links'.

  • Mailbox Hardening & Monitoring

    Disable external auto-forwarding, alert on new inbox rules and anomalous logins, and apply conditional access based on location and device.

  • Monitor Lookalike Domains

    Use tools like dnstwist and Certificate Transparency monitoring to detect registrations resembling your domains or key vendors' — then file takedowns early.

  • A Financial Incident Response Plan

    If a transfer has already happened: contact the bank within hours for a funds recall, report to law enforcement, and activate the incident playbook. Speed is the number one factor in fund recovery.

The Indonesian Context

Indonesia is an attractive target for phishing and BEC operators: Southeast Asia's largest digital economy, extremely high adoption of WhatsApp for business communication, and uneven payment verification practices. Executive impersonation via WhatsApp and the 'wedding invitation APK' scheme that steals banking credentials show how attackers adapt global techniques to the local context.

Under the now fully enforceable PDP Law, phishing incidents that lead to personal data breaches also carry regulatory consequences — the 3×24-hour notification obligation and potential administrative sanctions add a compliance dimension to what used to be 'merely' a security problem.

Risk Factors Distinct to Indonesia

Business communication via WhatsApp that is easy to impersonate, a hierarchical culture that makes staff reluctant to verify a superior's orders, vendor payment practices often based on email alone, and low incident reporting due to reputational concerns — all of which make BEC in Indonesia both underreported and highly effective.

97%+

Indonesian internet users on WhatsApp — the favorite channel for executive impersonation

Industry Surveys

Top 10

Indonesia consistently ranks among the most phishing-targeted countries in Asia Pacific

Regional Security Vendor Reports

3×24 hrs

The PDP Law's mandatory notification window when phishing leads to a personal data breach

Law No. 27/2022

The best defense against phishing and BEC is testing it before attackers do. Cloudsphere helps your organization measure human and process resilience through phishing simulations and comprehensive Security Assessments.

Frequently Asked Questions

What is Business Email Compromise (BEC)?

BEC is fraud that impersonates a trusted party — an executive, a vendor, or a colleague — via email to direct fund transfers or data disclosure. Unlike mass phishing, BEC is highly targeted and often contains no malware or malicious links at all, allowing it to slip past traditional email security filters. Its variants include CEO fraud, vendor email compromise, invoice fraud, payroll diversion, attorney impersonation, and data theft BEC.

How much money is lost to BEC attacks?

Cumulative global BEC losses exceeded USD 55 billion during 2013–2023 according to the FBI's IC3, with reported losses of over USD 2.7 billion per year in the US alone. Real cases include Facebook & Google (over USD 120 million), Ubiquiti Networks (USD 46.7 million), Toyota Boshoku (roughly USD 37 million), and Arup (about USD 25.6 million via deepfake). The average cost of a breach originating from phishing is around USD 4.9 million (IBM).

Why is MFA alone not enough to protect against phishing?

Adversary-in-the-Middle (AiTM) kits such as Evilginx, Tycoon 2FA, and EvilProxy use a reverse proxy that relays traffic to the real login site — the victim genuinely logs in, including entering their MFA code, while the attacker copies the authenticated session cookie. With that cookie, the attacker gets in without needing the password or MFA. Only phishing-resistant methods — FIDO2/passkeys and hardware security keys — are immune to these relay attacks by design.

How can BEC attacks be detected?

Look for indicators such as SPF/DKIM/DMARC failures and lookalike domains, new inbox rules moving mail or automatic external forwarding, and successful MFA logins from different IPs in close succession (a sign of session tokens stolen via AiTM). On the process side, watch for bank account change requests right before large payments, the combination of urgency and secrecy, and requests to move the conversation to WhatsApp or personal channels.

How can organizations prevent phishing and BEC?

Apply layered defenses: mandatory out-of-band verification for every vendor bank account change (a call to a number already on file, never the one in the email), FIDO2/passkeys for critical accounts, DMARC with a quarantine/reject policy, and dual approval for large transfers. Add continuous phishing simulations, mailbox hardening (disable external auto-forwarding, alert on new inbox rules), lookalike domain monitoring with dnstwist, and a financial incident response plan. If a transfer has already happened, contact the bank within hours — speed is the number one factor in fund recovery.

What are the BEC and phishing risks for companies in Indonesia?

Indonesia is an attractive target: Southeast Asia's largest digital economy, over 97% of internet users on WhatsApp — the favorite channel for executive impersonation — and Indonesia consistently ranks among the top 10 most phishing-targeted countries in Asia Pacific. Executive impersonation via WhatsApp and the vendor-invoice-with-changed-bank-account scheme are rampant yet underreported. Under the PDP Law, phishing that leads to a personal data breach also carries a 3×24-hour notification obligation and potential administrative sanctions.

About the Author

Cloudsphere Research Team

Threat Intelligence & Security Research

Cloudsphere's security research team tracking the threat landscape — new attack techniques, APT campaigns, and threat intelligence trends — distilled into practical guides.

Share Article

Related Topics

PhishingBusiness Email CompromiseBECSocial EngineeringDeepfakeThreat IntelligenceCybersecurity Indonesia