Fewer BEC attacks do not necessarily mean less financial risk as attackers shift tactics toward higher-value payment fraud.
By JT Newby
Yes. A decline in the number of business email compromise (BEC) attacks does not necessarily reduce an organization’s financial exposure. Fortra Intelligence & Research Experts (FIRE) observed a 16% month-over-month decline in overall BEC activity in August 2026, while wire-transfer attacks rose 16% and the average amount requested per wire-transfer attack increased to $51,453. The practical lesson is simple: security teams should measure the methods, amounts, and infrastructure behind BEC attempts, not just their total volume.

- Overall BEC volume fell 16% in August 2026, but wire-transfer attacks increased 16% from July.
- The average wire-transfer request climbed 17%, from $44,100 in July to $51,453 in August.
- Gift cards remained the leading cash-out method, accounting for 47.4% of observed BEC attacks.
- Free webmail providers were used in 66% of observed attacks, complicating reputation-based detection.
- Organizations need payment controls that treat email as an untrusted request channel, even when an attempt looks familiar.
BEC is often discussed as a volume problem: more malicious emails should mean more risk. August data points to a more complicated picture. The overall number of attacks observed by FIRE declined, but the attacks that sought wire transfers became more common and more expensive. A security program that declares success solely because inbox detections are up or incident counts are down can miss this change in risk.
Wire transfers accounted for 16.2% of observed BEC cash-out methods in August. Yet they are uniquely consequential because the attacker is attempting to move money directly through a legitimate payment process. Sixty percent of requested wire amounts fell between $10,000 and $50,000, while 28% were between $50,000 and $100,000. Even a relatively small number of successful requests can therefore create material loss.
“A lower BEC attack count can conceal a higher-value fraud problem when attackers shift toward wire requests that resemble normal business activity.
—Fortra Intelligence & Research Experts analysis
BEC succeeds by exploiting the trust and urgency built into ordinary operations. A message that appears to come from an executive, vendor, payroll contact, or finance colleague can be more effective than a generic phishing email because it asks for an action employees already perform. The attacker does not need to compromise every recipient. They need one person to approve or execute a payment before the request is independently verified.
The mix of cash-out methods seen in August shows why controls cannot focus only on one payment channel. Gift cards remained the most prevalent method, representing 47.4% of observed attacks. Advanced-fee fraud followed at 27.8%, and wire transfers at 16.2%. Amazon made up 40.9% of requested gift cards, followed by Apple Store at 27.3% and Uber Eats at 13.6%. These requests can look operationally minor, but they are also a familiar test of whether an employee will bypass normal verification.
Cryptocurrency-related scams were less common in the August data, but they illustrate the same pressure tactic. FIRE identified 14 such scams involving 12 unique Bitcoin wallet addresses. Requested amounts ranged from $943.84 to $120,000, with an average request of $16,178.85. Fraudsters can vary the cash-out route while keeping the social-engineering approach the same: create urgency, invoke authority, and move the conversation away from established processes.
The technical origin of a BEC email can be as important as its wording. In August, 66% of observed attacks came from email addresses hosted on free webmail providers, compared with 34% from maliciously registered domains. This matters because a free webmail account may not carry the obvious signals associated with a newly created lookalike domain, while a malicious domain can be rotated or abandoned quickly.
Among 727 maliciously registered domains identified during the month, Google was the most prevalent provider, accounting for 67%, followed by Microsoft and Italiaonline. The report also found that NameCheap, NameSilo, and Wild West Domains collectively represented 42% of free webmail-based attacks. Those observations are valuable for detection and investigation, but they should not be treated as a complete block list. Attackers can change providers, accounts, and domains faster than most organizations can update static controls.
Geographic signals should likewise be interpreted carefully. The United States accounted for 51% of observed attacker locations and Nigeria for 18%, based on IP addresses collected through beacons in engagements with BEC actors. The report notes that overt VPNs and proxies were removed, but an IP address may still be used indirectly as a proxy. Location can inform triage; it should not be the sole basis for a fraud decision.
The most effective response is to make financial verification independent of the email request. Finance and payroll teams should use a known phone number, established vendor portal, or in-person confirmation to validate changes to payment instructions, payroll details, and urgent transfer requests. The person making the request should never be the only channel used to confirm it.
Organizations should also define approval thresholds that reflect business impact, not only transaction type. August’s data shows that the requested amount for wire-transfer attacks rose even as total activity fell. A second approver, a mandatory cooling-off period for new bank details, and a documented out-of-band check can help prevent a single rushed decision from becoming an irreversible transfer.
Finally, security teams should feed BEC observations back into training and detection. Train employees on the exact requests that matter in their roles, including gift cards, payroll changes, vendor banking updates, and executive payment requests. Monitor for unusual sender-recipient relationships, sudden urgency, new reply-to addresses, and changes in payment instructions. The goal is not to make every employee a threat analyst; it is to give them a reliable pause-and-verify habit when money or credentials are involved.
The August report does not assign a single cause, but its findings show that attackers can change tactics and pursue higher-value payment requests even when total observed activity declines. Volume is one indicator, not a full measure of exposure.
Anyone who can approve payments, change payroll information, manage vendors, purchase gift cards, or act on executive requests should receive role-specific training and a clear escalation path.
Use an out-of-band verification process based on contact details already on file. Do not confirm a payment change through the email thread that requested it.
No. The August observations show that attackers use free webmail frequently, but legitimate people use those services too. Treat sender infrastructure as a signal that informs verification, not as proof by itself.
August’s BEC data is a reminder that fewer attacks can still create greater financial risk. Organizations that combine email defenses with independent payment verification, role-specific training, and risk-based approvals are better positioned to stop a convincing request before money moves.

About the Author:
JT Newby is a Principal Threat Research Lead at Fortra. In this role, JT is responsible for the Active Defense team within FIRE. He focuses on Business Email Compromise (BEC) and emerging threats, developing detection and mitigation strategies, and delivering actionable intelligence through customer reports and internal tools.






