Business email compromise analysis
Someone hacked our business email. What happened?
A customer received an email you did not send. A supplier's bank details changed. Someone followed payment instructions and the money went to the wrong account. GDF analyzes compromised Microsoft 365 and Google Workspace environments to establish what happened, assess which accounts and information were affected, and identify how access was gained where the evidence allows. We help your team address security weaknesses and give counsel the technical findings needed to assess reporting obligations.
Coordinate response and evidence preservation
Confirm the incident contact, available examiner and authorized containment responsibilities before agreeing timing. Security actions and evidence preservation proceed together, with account changes and unavailable records logged.
Exposure analysis starts with the affected accounts, accessible messages or files, activity period and observed actions. Identify the reviewed population and its exclusions, separate confirmed access from potential exposure and have counsel evaluate notification or reporting duties. A message in a mailbox is not by itself proof it was read or extracted.
Use this page to decide the next incident questions. The linked Business Email Takeover Forensics service describes the detailed examination and reporting engagement.
Primary references: Microsoft audit activity definitions (opens in a new tab).
If money was transferred, contact your bank immediately. Ask its fraud team to contact the receiving institution. Report the incident to the FBI's Internet Crime Complaint Center at IC3. Do not wait for a forensic report before contacting the bank. Recovery is not guaranteed. FBI guidance
Reviewed by Joseph Caruso. .
Someone hacked my Microsoft 365 and sent emails
You may first hear about it from a customer asking why your company sent a strange message. Or your team may find unfamiliar messages, missing email or a forwarding rule nobody recognizes.
The message alone does not prove someone entered your account. A criminal can also imitate your address or use a similar-looking domain. Analysis starts by comparing the messages with the account records that are available.
The practical questions are straightforward:
- Did someone access our account, or did they impersonate us?
- Which messages were sent, forwarded or changed?
- What can we establish about the timing and accounts involved?
Someone changed an invoice and we transferred funds
A payment request may look convincing because it follows a real conversation. Preserve the original messages, invoice versions, payment instructions and transaction records. Keep the original email files where possible, not just screenshots or pasted text.
Verify any further payment instructions by calling a known contact using a number you already trust. Do not rely on the phone number in the suspicious message. FBI guidance
GDF can compare the available email and account evidence with your payment timeline. The purpose is to explain what the records show and where gaps remain. An unfamiliar IP address alone does not identify the person responsible.
We changed the password. Is that enough?
A password reset is only one part of responding to a compromised business email account. Day-to-day IT support and cloud compromise response require different skills. Your IT department or managed service provider knows your environment, but you should confirm that the response team has experience analyzing and securing Microsoft 365 or Google Workspace after an attack.
GDF works with your IT team to examine how access was obtained, identify ways an attacker may retain access, and address the weaknesses involved. Depending on the platform and available evidence, that includes reviewing active sessions, authentication methods, application permissions, forwarding rules, administrator changes and relevant security policies. Restoring email service does not, by itself, establish that unauthorized access has ended.
Containment and evidence preservation should proceed together. Do not leave an account exposed while waiting to collect perfect records. Keep a record of response actions and when they occurred.
Microsoft account-compromise response guidance and Google Workspace account-security guidance.
How did this happen?
Was it a phishing email, a targeted message aimed at a particular employee, or a phone call from someone pretending to be IT support? Did someone disclose credentials, approve an unexpected sign-in request or grant access to an unfamiliar application?
GDF compares available messages, account activity, security settings and relevant device records with what employees experienced. We work to identify the initial access method and the conditions that allowed the compromise to continue. When records are missing or inconclusive, we explain what is established and what remains a possible explanation.
The findings should lead to specific changes. Depending on the cause, that may mean stronger authentication, tighter application permissions, better account-recovery and help-desk verification procedures, or independent verification of payment changes. The objective is to address the route used in this incident and reduce the chance of a repeat.
The FBI describes phishing and help-desk impersonation techniques.
Did the attacker access personal or patient information?
A compromised mailbox can contain personal information, patient information, attachments and links to other business records. Identifying sensitive content and establishing whether an attacker accessed it are separate parts of the analysis.
GDF examines the available evidence of email access, forwarding, downloads and other activity. Within the agreed scope, we review relevant messages and attachments for personally identifiable information (PII) and protected health information (PHI), and document the information and individuals potentially affected. Logging, retention and other gaps may limit what can be established.
We provide counsel with findings, timelines, a scoped inventory and clearly stated uncertainties to support incident assessment and reporting. Counsel determines the applicable notification requirements, recipients and deadlines. The goal is accurate, evidence-based reporting that meets those obligations without unnecessarily expanding the affected population beyond what the assessment supports. Missing evidence is not proof that information was untouched.
For organizations subject to HIPAA, the breach-notification assessment follows applicable requirements. GDF supplies technical evidence to support that assessment; the analysis does not guarantee that notification can be avoided. HHS breach-notification guidance.
Help employees recognize the next attempt
Ongoing education should reach every level of the business, including executives, finance staff and people who handle account recovery. Use practical examples of targeted email, fake support calls, unexpected authentication prompts and changed payment instructions.
Give employees a clear way to report a concern promptly, even if they already clicked a link or approved a request. Reinforce independent verification of sensitive requests through a trusted contact method. Use lessons from the incident to improve procedures and future training.
Education supports stronger security policies and technical controls. It should be part of an ongoing program, not a one-time response to an attack. NIST guidance on phishing awareness.
What does BEC analysis involve?
Business email compromise, or BEC, describes scams that misuse trusted business communications. Some involve a compromised mailbox; others use impersonation.
Depending on the matter and available records, analysis may include:
- Original emails, message headers and relevant attachments.
- Microsoft 365 or Google Workspace sign-in, account and available audit records.
- Mailbox activity, forwarding rules, application permissions and security-setting changes.
- Analysis of how access began, how it continued and what controls need attention.
- A timeline connecting account activity with email, invoice or payment events.
- Review of relevant messages and attachments for sensitive personal or patient information.
- Technical findings and an affected-information inventory for counsel's reporting assessment.
- A written explanation of findings, supporting records, recommended corrections and evidence limitations.
The scope depends on the accounts and records you are authorized to provide, available logging and the questions you need answered. Missing records can limit the conclusions. For more detail, see Email and Microsoft 365 Forensics.
Talk with GDF about what happened
Tell us whether suspicious email was sent, payment details changed or money was transferred, and how to reach you. Keep passwords, access tokens, bank details and evidence out of the initial contact form. Arrange secure sharing separately.