Business email compromise analysis

Someone hacked our business email. What happened?

A customer received an email you did not send. A supplier's bank details changed. Someone followed payment instructions and the money went to the wrong account. GDF analyzes business email, Microsoft 365 account activity and available records to help your business understand what happened, which accounts were involved and what the evidence can support.

Bagged hard drive beside a forensic write blocker.

If money was transferred, contact your bank immediately. Ask its fraud team to contact the receiving institution. Report the incident to the FBI's Internet Crime Complaint Center at IC3. Do not wait for a forensic report before contacting the bank. Recovery is not guaranteed. FBI guidance

Someone hacked my Microsoft 365 and sent emails

You may first hear about it from a customer asking why your company sent a strange message. Or your team may find unfamiliar messages, missing email or a forwarding rule nobody recognizes.

The message alone does not prove someone entered your account. A criminal can also imitate your address or use a similar-looking domain. Analysis starts by comparing the messages with the account records that are available.

The practical questions are straightforward:

  • Did someone access our account, or did they impersonate us?
  • Which messages were sent, forwarded or changed?
  • What can we establish about the timing and accounts involved?

Someone changed an invoice and we transferred funds

A payment request may look convincing because it follows a real conversation. Preserve the original messages, invoice versions, payment instructions and transaction records. Keep the original email files where possible, not just screenshots or pasted text.

Verify any further payment instructions by calling a known contact using a number you already trust. Do not rely on the phone number in the suspicious message. FBI guidance

GDF can compare the available email and account evidence with your payment timeline. The purpose is to explain what the records show and where gaps remain. An unfamiliar IP address alone does not identify the person responsible.

We changed the password. Is that enough?

Have your authorized IT administrator or response team review the account promptly. Microsoft's guidance includes securing access, revoking active sessions and reviewing account settings and forwarding rules. A password change alone is not a complete review of the ways an attacker may retain access. Microsoft guidance

Coordinate evidence preservation with containment. Do not leave an account exposed while waiting to collect perfect records. Record what your team changed and when, so those actions can be distinguished from the suspicious activity.

What does BEC analysis involve?

Business email compromise, or BEC, describes scams that misuse trusted business communications. Some involve a compromised mailbox; others use impersonation.

Depending on the matter and available records, analysis may include:

  • Original emails, message headers and relevant attachments.
  • Microsoft 365 and identity sign-in records.
  • Available mailbox activity, forwarding rules and account changes.
  • A timeline connecting email activity with invoice or payment events.
  • A written explanation of findings, supporting records and limitations.

The scope depends on the accounts you are authorized to provide, available logging and the questions you need answered. Missing records can limit the conclusions. For more detail, see Email and Microsoft 365 Forensics.

Talk with GDF about what happened

Tell us whether suspicious email was sent, payment details changed or money was transferred, and how to reach you. Keep passwords, access tokens, bank details and evidence out of the initial contact form. Arrange secure sharing separately.

Discuss an Email Compromise Call 1-800-868-8189

Talk with an examiner

Discuss your matter and next step

Tell us the systems, evidence and deadline. We can review relevant experience, potential conflicts and the scope before engagement.

Since 1992 · 24/7 dispatch · Court-tested experts

Or call 1-800-868-8189

Email or phone is required. A submission does not create an engagement. For an active incident, please call. Read what we send with the request.

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.