



Business Email Compromise (BEC) has quietly become one of the most expensive cyber threats facing Indian enterprises in 2026. It rarely makes the headlines that ransomware does, yet a single well-timed fraudulent invoice or a spoofed “CEO” payment request can drain crores in minutes — with no malware, no breached firewall, and no obvious alarm. For finance, manufacturing, and services companies running lean security teams, BEC is the attack that slips through precisely because it targets people, not systems.
At PJ Networks, we see the same pattern across clients: the technical perimeter is reasonably hardened, but the email and identity layer is wide open. This playbook breaks down why BEC works, what changed in 2026, and the layered defense Indian enterprises can put in place — including the compliance obligations under the DPDP Act and CERT-In rules that now sit on top of the incident itself.
BEC is social engineering wearing a business suit. Instead of exploiting a software vulnerability, the attacker exploits trust, authority, and urgency. A typical chain looks like this:
None of this trips a traditional firewall, because nothing malicious crosses the wire. That is exactly why email security, identity, and human process — not just network controls — decide whether BEC succeeds.
Two shifts have made BEC dramatically more effective this year. First, generative AI has eliminated the broken-English tell that once gave phishing away. Fraudulent emails now mirror your house style, sign-off, and even past thread context. Second, voice and video deepfakes have moved from novelty to operational tooling — a finance manager may receive a follow-up “call” that sounds convincingly like the person who supposedly sent the email.
The defensive takeaway is blunt: you can no longer train staff to “spot the fake” by looks alone. Verification has to become a process, enforced by technology, not a judgment call made under pressure.
A familiar scenario. A mid-sized manufacturer’s accounts team receives an email from a long-standing supplier: “We’ve changed banks — please update our account details for this month’s payment.” The thread history is real, the signature is perfect, the amount is routine. The only thing wrong is one letter in the reply-to domain. The payment of ₹42 lakh clears before anyone calls the supplier to confirm. The supplier never sees a rupee. This is not a hypothetical — variations of it land in Indian finance inboxes every week.
Most successful impersonation attacks exploit domains that have no enforced DMARC policy. Publishing SPF and DKIM is only half the job — without a DMARC policy set to quarantine or reject, spoofed mail still lands in inboxes. We routinely find Indian enterprises stuck on p=none, which monitors but blocks nothing. Moving to enforcement is the single highest-leverage control against domain spoofing.
A modern secure email gateway such as FortiMail inspects inbound mail for impersonation patterns, look-alike domains, malicious links, and anomalous sender behavior — catching the messages that authentication alone won’t. Crucially, it also scans outbound mail, which helps contain a mailbox that has already been compromised.
BEC frequently begins with a stolen password. Phishing-resistant multi-factor authentication on every mailbox and admin account turns a harvested credential into a dead end. Pairing this with Zero Trust Network Access (ZTNA) ensures that even valid credentials only grant access to what a role genuinely needs — limiting how far an attacker can move if they do get in.
The strongest single process control is also the cheapest: any change to bank details, or any payment above a defined threshold, must be verified through a second channel — a phone call to a known number, never the one in the email. Bake this into finance SOPs so it is mandatory, not optional.
BEC leaves subtle fingerprints: an impossible-travel login, a new inbox forwarding rule, a mailbox accessed from an unfamiliar geography at 3 a.m. A 24/7 Security Operations Centre correlates these signals and flags account takeover before the fraudulent payment goes out. For most Indian enterprises, a managed SOC is far more cost-effective than staffing this in-house around the clock.
A BEC incident in India is no longer just a financial loss — it is a regulatory event. If personal data is exposed in the compromise, the Digital Personal Data Protection (DPDP) Act obligations are triggered. Separately, CERT-In’s directions require reporting of cyber incidents within six hours of detection. That clock is unforgiving, and organizations without a prepared incident response plan routinely miss it. Your BEC response plan and your compliance reporting plan must be the same document, rehearsed in advance.
In our assessments across Indian enterprises, the same gaps recur. If any of these describe your organization, BEC has a clear path in:
p=none: You’re monitoring spoofing but doing nothing to stop it.You don’t need a year-long program to materially reduce BEC risk. A focused 30-day sprint moves the needle:
quarantine; enable MFA on all mailboxes and admin accounts.PJ Networks delivers this as an integrated managed service: FortiMail-based email security, FortiGate and ZTNA for identity-first access, and a 24/7 NOC/SOC that watches for account takeover the moment it begins. We help Indian enterprises move from a monitor-only posture to enforced controls — and we keep your incident response and CERT-In reporting rehearsed, so a bad day stays a manageable one.
If your finance team could action a convincing fraudulent payment request today without a mandatory second-channel check, BEC is an open risk worth closing now. Talk to PJ Networks about an email security and identity assessment for your organization.