Business Email Compromise β the highest ROI attack in 2026. Less risk, more payout than ransomware.
Code:
Average payout per successful BEC: $50,000 - $250,000
Detection rate: ~30%
Prosecution rate: <5% (international)
Time to execute: 1-10 days preparation + 1 hour to send wire
Phase 1: Target Research
- Find mid-size companies (50-500 employees) β big enough to have money, small enough to have weak security
- Identify CEO/CFO/Finance Director via LinkedIn
- Map their email format: first.last@company.com or flast@company.com
- Check if company domain has DMARC/DKIM/SPF (use MXToolbox)
Phase 2: Initial Access
- Phish the target or an employee in finance
- Use a lookalike domain: c0mpany.com instead of company.com (zero replaced with O)
- Send from spoofed email with proper header manipulation
- Or compromise an actual vendor account they pay regularly
Phase 3: The Ask
- Wire transfer request to "urgent vendor payment"
- Amount should be realistic β not too high, not too low
- Use urgency: "Need this processed before end of business day"
- Include invoice attachment (looks professional)
- Provide banking details for a drop account you control
Phase 4: Cashing Out
- Wire hits your drop account
- Immediately move to crypto (BTC/USDT) via exchange or P2P
- CoinJoin / Wasabi Wallet to break chain
- Transfer to cold storage or cash out via local BTC meetups
- Lookalike domain ($10 on Namecheap/GoDaddy)
- Email spoofing script (Python + SMTP)
- Professional invoice template (customizable)
- Drop bank account (see Bank Drop thread)
- BTC mixer (Wasabi Wallet or similar)