USG: according to the definitions used by fedpol (which the NCSC also follows), BEC fraud and CEO fraud are distinct phenomena: in the fedpol classification, BEC involves an actual email compromise (i.e. the scammers have or have had access to the genuine email account), whereas CEO fraud normally does not.