Business email compromise can begin with a stolen session, credential capture, OAuth consent, forwarding rule, vendor impersonation, or a compromised third party. Payment fraud often unfolds across several mailboxes and systems. A coordinated first day reduces further loss and preserves the evidence needed to understand the route.

Identity control, payment-channel protection, evidence capture, and scoping overlap during the first day. The sequence changes as new facts emerge.

Control identities and payment channels

Use a trusted channel to reach the mailbox owner, finance team, counterparties, bank, insurer, counsel, and response lead. Secure affected identities, revoke sessions and application grants, remove malicious rules, review delegates, and reset credentials under an approved sequence. Do not rely on the suspect mailbox to validate wire instructions or communicate containment.

If a transfer may have occurred, contact the financial institution immediately through a verified number and report the event to the FBI Internet Crime Complaint Center. Those steps do not replace counsel's advice or the organization's notification process, and recovery is not guaranteed.

Preserve cloud records before retention closes

Collect native messages, headers, message trace, mailbox audit, sign-ins, authentication changes, inbox and transport rules, delegates, application consent, security alerts, device records, and relevant administrator actions while each source is still available. In Microsoft 365, availability varies by workload, license, audit configuration, retention policy, event age, and provider changes. Preserve the full payment conversation, attachments, external correspondence, bank details, call records, and accounting-system events.

  • Record each response action with actor and time.
  • Identify first suspicious access and last confirmed malicious activity.
  • Search for rules, delegates, OAuth grants, look-alike domains, and altered threads.
  • Scope other identities, shared mailboxes, and counterparties.
  • Assess what available records support about message or file access, export, or download.

Test the explanation before closing

A password reset does not remove every session or malicious application. A suspicious IP address does not identify a person. Audit events may show an account or application action without proving which person directed it, and the absence of an event may reflect retention or logging limits. The final chronology should distinguish confirmed events, likely explanations, unresolved alternatives, mailbox activity, payment manipulation, containment, and what available records support about data access. GDF provides 24/7 technical response and does not provide legal advice.

Primary and public sources