Business email compromise analysis
Someone hacked our business email. What happened?
A customer received an email you did not send. A supplier's bank details changed. Someone followed payment instructions and the money went to the wrong account. GDF analyzes business email, Microsoft 365 account activity and available records to help your business understand what happened, which accounts were involved and what the evidence can support.
If money was transferred, contact your bank immediately. Ask its fraud team to contact the receiving institution. Report the incident to the FBI's Internet Crime Complaint Center at IC3. Do not wait for a forensic report before contacting the bank. Recovery is not guaranteed. FBI guidance
Someone hacked my Microsoft 365 and sent emails
You may first hear about it from a customer asking why your company sent a strange message. Or your team may find unfamiliar messages, missing email or a forwarding rule nobody recognizes.
The message alone does not prove someone entered your account. A criminal can also imitate your address or use a similar-looking domain. Analysis starts by comparing the messages with the account records that are available.
The practical questions are straightforward:
- Did someone access our account, or did they impersonate us?
- Which messages were sent, forwarded or changed?
- What can we establish about the timing and accounts involved?
Someone changed an invoice and we transferred funds
A payment request may look convincing because it follows a real conversation. Preserve the original messages, invoice versions, payment instructions and transaction records. Keep the original email files where possible, not just screenshots or pasted text.
Verify any further payment instructions by calling a known contact using a number you already trust. Do not rely on the phone number in the suspicious message. FBI guidance
GDF can compare the available email and account evidence with your payment timeline. The purpose is to explain what the records show and where gaps remain. An unfamiliar IP address alone does not identify the person responsible.
We changed the password. Is that enough?
Have your authorized IT administrator or response team review the account promptly. Microsoft's guidance includes securing access, revoking active sessions and reviewing account settings and forwarding rules. A password change alone is not a complete review of the ways an attacker may retain access. Microsoft guidance
Coordinate evidence preservation with containment. Do not leave an account exposed while waiting to collect perfect records. Record what your team changed and when, so those actions can be distinguished from the suspicious activity.
What does BEC analysis involve?
Business email compromise, or BEC, describes scams that misuse trusted business communications. Some involve a compromised mailbox; others use impersonation.
Depending on the matter and available records, analysis may include:
- Original emails, message headers and relevant attachments.
- Microsoft 365 and identity sign-in records.
- Available mailbox activity, forwarding rules and account changes.
- A timeline connecting email activity with invoice or payment events.
- A written explanation of findings, supporting records and limitations.
The scope depends on the accounts you are authorized to provide, available logging and the questions you need answered. Missing records can limit the conclusions. For more detail, see Email and Microsoft 365 Forensics.
Talk with GDF about what happened
Tell us whether suspicious email was sent, payment details changed or money was transferred, and how to reach you. Keep passwords, access tokens, bank details and evidence out of the initial contact form. Arrange secure sharing separately.