BEC isn't a one-off — once your inbox has been used for fraud, you're a known target. Warning contacts on a different channel and adding a phishing-resistant 2FA method are the long-term protection.
Why a hardware key matters here
BEC almost always starts with phishing or session-token theft. A hardware key or passkey defeats both — even if they get the password, they can't log in.
Was this guide helpful?
Know someone who needs this? Send them the guide.
JD
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers