Glossary›Business email compromise (BEC) in capital calls
Business email compromise (BEC) in capital calls
Business email compromise (BEC) is a form of fraud in which an attacker gains access to, or credibly impersonates, a legitimate corporate email account to manipulate financial transactions. In private fund administration, BEC is the primary technical mechanism through which payment instructions for capital calls and distributions are intercepted and redirected to fraudulent accounts.
Unlike opportunistic phishing attacks, BEC attacks targeting fund capital calls are typically researched, patient, and precisely timed to coincide with genuine capital call events, making them difficult to detect through routine email security controls alone.
How it works
A BEC attack in the fund context follows a recognisable pattern. The attacker first gains access to email communications, either by compromising an actual account (through credential theft, malware, or phishing) or by registering a lookalike domain that is visually indistinguishable from the legitimate sender. They then monitor email traffic, identify an upcoming capital call or distribution event, and intervene at the moment when payment instructions are being communicated.
The intervention typically takes one of two forms. In the GP impersonation variant, the attacker sends a capital call notice to LPs (or to the fund administrator acting on behalf of LPs) with the GP's correct fund and legal entity details but substituted bank account information. In the fund administrator impersonation variant, the attacker contacts a GP or LP directly, citing a "system migration," "banking change," or "routine update," and instructs them to redirect payments to a new account.
Because BEC exploits trusted communication channels rather than technical vulnerabilities in banking systems, it bypasses most conventional security controls. Firewalls, anti-virus software, and even email security gateways cannot prevent a BEC attack that uses a correctly registered lookalike domain or a genuinely compromised account. The attack is defeated by process controls, not technology controls alone: specifically, by removing email as an authoritative channel for payment instructions.
The fund administration context amplifies BEC risk in several ways. Capital calls occur on irregular schedules, so recipients do not have a learned expectation of "when" to expect them. Amounts are large and vary between calls. Counterparties (LPs, GPs, administrators) are geographically distributed and interact primarily by email and document portal. And the operational culture of institutional finance, where questioning a payment instruction from a senior counterparty carries social friction, creates a bias toward processing instructions rather than escalating anomalies.
"Payment instructions never travel by email" is the operational principle that addresses BEC structurally. When bank account details are held in a verified registry, authenticated at onboarding, and only modifiable through a controlled, multi-factor verification process, the email channel is removed from the payment instruction chain entirely. An attacker who sends a fraudulent capital call notice by email cannot redirect payments, because the payment system does not reference email-delivered instructions. It references only the verified registry.
Worked example
Harborfield Capital Management is preparing to issue a EUR 28 million capital call for its third vintage fund. Six weeks before the call, an attacker registers the domain harborfield-capital.eu (the legitimate domain is harborfieldcapital.eu) and configures it to impersonate the fund manager's CFO.
Three days before the call, the attacker sends emails to all fourteen LPs in the fund's register, attaching a professionally formatted capital call notice with correct fund name, call reference number, and LP commitment amounts. The call reference matches the sequence of previous calls. The only alteration is the beneficiary bank account in the payment details section, which is replaced with an account at a different bank controlled by the attacker.
Eight of the fourteen LPs process the payment without independent verification. EUR 16 million is transferred before the real fund manager issues the genuine call and the discrepancy is identified. By the time the fraud is confirmed, the funds have been moved through multiple accounts.
If the LPs had been operating within a verified payment infrastructure, they would have received the capital call notice through an authenticated channel, and the payment instruction would have referenced the verified account on file rather than the account in the email attachment. The fraudulent email would have been irrelevant.
Frequently asked questions
How do attackers obtain the information needed to construct a convincing capital call notice? Capital call notices reference information that is partially available from public sources (fund name, vintage, fund manager details) and partially derivable from prior correspondence if an email account has been compromised. Attackers who conduct surveillance over an extended period can observe the format, frequency, and reference numbering of genuine calls, making their fraudulent notice structurally indistinguishable from a real one. LP commitment amounts are typically not public, but can be inferred or obtained through a compromised LP or administrator account.
Is BEC covered by cyber insurance in a fund administration context? Coverage depends on policy terms. Most cyber insurance policies cover BEC-related losses where the policyholder's own systems or employees were directly manipulated. Coverage becomes contested when the fraud involves a third-party counterparty (for example, an LP that wires to a fraudulent account because the fund manager's domain was impersonated, without any compromise of the fund manager's own systems). Fund administrators and GPs should review their policies for social engineering and funds-transfer fraud coverage specifically.
What is the difference between a compromised account and a spoofed domain in BEC? A compromised account attack uses the attacker's access to a real corporate email account. It is harder to detect because the email originates from a legitimate server and passes standard authentication checks (SPF, DKIM, DMARC). A spoofed domain attack uses a lookalike domain registered by the attacker. It is detectable in principle through email header inspection, but many recipients do not inspect headers and the visual presentation may be identical to a legitimate email.
How should a fund administrator respond to a suspected BEC attack in progress? Immediate steps are: suspend any pending payments that may have been affected; contact all counterparties directly using pre-registered phone numbers, not email or phone numbers in the suspicious communication; notify the relevant bank's fraud team to attempt recall of any payments already executed; notify law enforcement (Action Fraud in the UK, INTERPOL for cross-border cases); and conduct a review of email system access logs to determine whether an account was genuinely compromised.
Does multi-factor authentication prevent BEC? Multi-factor authentication (MFA) on email accounts significantly raises the cost of credential-based account compromise and should be mandatory across all fund administration systems. However, MFA does not prevent lookalike domain attacks, and it does not prevent an attacker who has physically or socially compromised a legitimate account holder. MFA is a necessary control, but not a sufficient one.
Related terms
APP fraud (authorised push payment fraud), Confirmation of Payee, IBAN verification in private fund payments, Maker-checker in fund administration, Straight-through processing (STP) in fund payments, Capital call
Related pages
How fund administrators should protect capital call payments from wire fraud, Swelv for fund administrators