A fraudulent payment request can cross several business units before anyone recognizes it. Treasury sees a changed beneficiary, IT sees an unfamiliar sign-in, and a supplier sees an apparently ordinary reply. The response needs one chronology connecting those records. Treat the first day as coordinated work by finance, identity administrators and evidence specialists, not a mailbox cleanup assigned to one help-desk technician.
Assign decisions to three workstreams
Finance should use verified contact details to reach the financial institution immediately if money may have moved. Preserve the transaction reference, beneficiary information, approval trail and any recall correspondence. The FBI recommends contacting the bank and reporting business email compromise to IC3. Neither step guarantees recovery.
Identity administrators contain active access under the response lead's direction. Their scope includes affected accounts, active sessions, authentication methods, consented applications, delegates and forwarding rules. Record each change and its time. Evidence collection should run alongside containment where practical, but an urgent protective action should not wait for a perfect export.
The evidence team preserves native messages and headers, cloud activity, relevant endpoint records and the accounting history. Use a trusted communication channel outside the suspected account. Name a coordinator who can reconcile conflicting times and ownership across subsidiaries, providers and outside counsel.
Follow the payment instruction through the business
Start with the original invoice or request, then compare each version and recipient. Identify where the beneficiary, amount or approval language changed. A genuine mailbox takeover and an external look-alike address require different explanations. Do not assume that every participant whose name appears in the thread had a compromised account.
- Match message identifiers and headers to the finance team's retained copies.
- Compare supplier-master changes with identity and administrator events.
- Check related shared mailboxes, delegates and business applications.
- Record the collection period and retention limits for each source.
- Preserve counterparty records through the client's approved request process.
Make the first-day handoff usable
The next shift needs a status table, not a confident story assembled from incomplete logs. Separate confirmed transfers, attempted transfers, affected identities, actions completed and unanswered questions. A successful sign-in establishes an account event; it does not by itself identify the person operating the account. Missing audit events may reflect missing coverage rather than absence of activity.
For technical response and collection scope, see incident response and the cloud source-map checklist. Counsel directs legal and notification decisions. GDF supplies the technical record.
Source guidance
FBI business email compromise guidance and Microsoft's compromised-account response guidance.