Security operations INTELLIGENCE
Emerging threat report: Business email compromise
Date of publication: Tuesday 7th July 2026.
Our Security Operations Centre (SOC) has identified a rise in Business Email Compromise activity, which sees attackers increasingly exploiting session-theft and rogue device registration techniques to blend into normal operations undetected.
This emerging technical threat report outlines what is being observed on the frontlines, alongside critical recommendations to support organisations in mitigating this attack vector.
.png?width=1200&name=Copy%20of%20Copy%20of%205039%20TPR%20Webinar%20(2).png)
Business email compromise (BEC) is becoming more effective and increasingly difficult to detect.
Recent observations from the CSA Cyber SOC point to a clear shift in attacker behaviour, with threat actors moving beyond traditional technical exploits and focusing instead on identity, trust and active user sessions.
For security and technical teams, the nature of risk is changing.
When malicious activity mirrors legitimate use, compromise becomes harder to spot and gaps across access, identity and email controls become easier to miss.
Shaped by current SOC intelligence and real-world activity, this report highlights where this shift is most visible and priorities for immediate attention.
Inside, you'll find:
- Insight into recent business email compromise activity
- A view of how attacker behaviour is changing
- Key areas to review across identity, access and email security
Access the report to gain a clearer view of where your current controls may be exposed, and where to focus next to strengthen resilience.