Business Email Compromise Response: What to Do in the First 24 Hours After a Fraudulent Payment Request

By Ron Samson

A fraudulent payment request is an incident, not an accounting exception

Business email compromise (BEC) succeeds because it exploits trusted business processes: an executive approval, a vendor invoice, a payroll change, or an urgent wire instruction. The message may come from a spoofed domain, a compromised supplier mailbox, or an internal account that has already passed multifactor authentication. In every case, the first 24 hours determine whether a suspicious request becomes a contained near miss, a recoverable financial loss, or a wider security breach.

The FBI’s Internet Crime Complaint Center has consistently identified BEC as one of the costliest cybercrime categories. The loss is not limited to the initial transfer. Organizations also face recovery costs, payment delays, legal review, business disruption, vendor friction, insurance notifications, and the possibility that attackers still control email accounts or endpoint sessions.

A disciplined response needs finance, IT, security, legal, leadership, and the bank working from the same facts. This guide provides a practical first-day response plan for organizations that receive, approve, or send a fraudulent payment request.

The first rule: stop the money and preserve the evidence

Do not begin with a long email investigation while a payment remains in motion. The immediate priorities are financial containment, account containment, and evidence preservation. Assign one incident owner who can coordinate decisions and document timestamps. That person should have authority to escalate to the CFO, CIO, general counsel, insurer, bank relationship manager, and external incident-response partner.

💡 Critical distinction: A recalled wire is not a recovered wire. Record the bank’s case number, the receiving institution, recall status, payment method, beneficiary details, and the exact time each action occurred.

If the request was received but not paid, immediately pause the invoice, vendor-master change, payroll update, purchase order, or disbursement workflow. If money was sent, contact the originating financial institution using a known phone number, not any number supplied in the suspicious message. Request a recall, freeze, or reversal through the bank’s fraud team. For U.S. organizations, report the incident to the FBI IC3 and ask law enforcement whether the Financial Fraud Kill Chain process may apply.

Business Email Compromise Response: What to Do in the First 24 Hours After a Fraudulent Payment Request
Rapid coordination helps limit financial loss and preserve investigative evidence.

0–60 minutes: contain the payment, mailbox, and access path

The first hour is about preventing additional harm. Finance should call the bank and stop related payments. Security and IT should assess whether the sender account, recipient account, or both may be compromised. Avoid deleting the message or forwarding it broadly; that can alter evidence, create confusion, and expose malicious links to more employees.

Time window Required action Primary owner
0–15 minutes Pause payment, call the bank, preserve the original email and transaction details. Finance lead
15–30 minutes Open an incident, identify affected identities, and begin mailbox containment. Security and IT
30–60 minutes Verify vendors out of band, search for related messages, notify decision makers. Incident owner

For an internal mailbox suspected of compromise, revoke active sessions, reset the password, require MFA re-registration where appropriate, and review authentication activity before restoring normal access. Disable suspicious inbox rules, forwarding rules, delegates, OAuth application grants, and recently created aliases. Do not assume a password reset alone removes persistence. Attackers commonly establish forwarding rules or consent to malicious applications so they can continue watching financial conversations.

For an external vendor or partner mailbox, do not treat a reply to the same thread as verification. Use a known contact from the executed contract, vendor master file, customer relationship system, or previously verified phone number. Confirm bank-account changes and payment instructions verbally using a documented callback procedure.

Hour 1–4: determine whether this is fraud, compromise, or both

BEC investigations fail when teams focus only on the email’s wording. The question is not simply whether the message looked malicious; it is whether an identity, mailbox, device, payment workflow, or supplier relationship has been manipulated. Build a concise timeline that connects the financial request to security events.

  • Export the message in its original format, including full headers, message IDs, attachments, URLs, and timestamps.
  • Identify the sending domain and compare it with the legitimate domain character by character.
  • Review sign-in logs for impossible travel, unfamiliar IP addresses, new devices, legacy authentication, and repeated MFA prompts.
  • Search mailboxes for similar subjects, payment terms, bank-account changes, executive impersonation, and vendor names.
  • Check endpoint telemetry for browser credential theft, remote-access tools, malware, or unusual cloud-session activity.
  • Review recent changes to vendor records, approval thresholds, payment templates, and accounts-payable access.

This is where security operations maturity matters. Email, identity, endpoint, firewall, and cloud logs often sit in separate tools, owned by separate teams. A capable SOC correlates these signals and distinguishes a spoofed request from a compromised Microsoft 365 or Google Workspace account. Organizations without round-the-clock coverage should consider how Managed SOC Services can provide continuous monitoring, alert triage, and escalation when finance fraud intersects with identity compromise.

Preserve evidence in a restricted case repository. Capture screenshots of the payment request and bank portal status, but also keep source data. Record who accessed the mailbox, who changed credentials, which rules were removed, and when the bank was contacted. Those details support recovery, cyber-insurance requirements, legal review, and later process improvements.

Hour 4–8: scope the blast radius before attackers reuse trust

Once immediate containment is underway, expand the search. BEC actors often spend days or weeks reading correspondence before sending a request at the most credible moment. That dwell time means other conversations may be compromised even when only one fraudulent invoice has been identified.

📧

Mailbox scope

Search sent items, deleted items, forwarding rules, delegates, and conversations involving finance leaders, vendors, payroll, and legal teams.

🔑

Identity scope

Review privileged roles, MFA changes, OAuth consents, conditional-access exclusions, service accounts, and recently enrolled devices.

💳

Financial scope

Flag pending payments, recent bank-detail modifications, urgent approvals, unusual beneficiaries, and transactions approved outside normal workflows.

Search for lateral targeting. If an executive mailbox was accessed, attackers may impersonate that person toward subsidiaries, customers, law firms, payroll providers, and banks. If a vendor account was compromised, your organization may be one of many customers receiving fraudulent remittance instructions. Alert the relevant parties with factual, limited information: what was observed, what they should verify, and a trusted callback channel.

Use the CISA phishing guidance and your incident-response plan to determine notification requirements. Legal counsel should assess contractual duties, privacy exposure, securities obligations, and jurisdiction-specific breach rules. Avoid speculative statements. Early communications should be accurate, time-stamped, and approved through the incident command structure.

Hour 8–12: eradicate persistence and validate controls

Eradication means removing the attacker’s ability to regain access, not simply closing the visible ticket. Review every authentication method associated with affected identities. Reset passwords, revoke refresh tokens and sessions, remove unauthorized MFA methods, disable malicious OAuth applications, and rotate credentials for affected service accounts. If endpoint compromise is plausible, isolate the device and conduct a full endpoint investigation.

Endpoint visibility is especially important when BEC begins with an infostealer, browser-session theft, or remote-access compromise. Security teams should examine browser extensions, saved credentials, downloaded files, command-line activity, remote-management tools, and EDR detections. Organizations using Falcon should ensure their monitoring partner can investigate identity-linked endpoint events, not merely close alerts. Managed CrowdStrike support can help teams tune detections, investigate suspicious behavior, and coordinate containment across endpoint and identity workflows.

Validate mail controls as well. Confirm SPF, DKIM, and DMARC alignment for your domains, then examine whether lookalike domains are being used against your organization. Strengthen external email tagging, impersonation protection, attachment detonation, URL analysis, and rules governing automatic forwarding. These controls reduce exposure, but they do not replace payment verification because a legitimate account can still send a fraudulent instruction.

Hour 12–24: recover safely and turn findings into decisions

By the end of the first day, leadership needs a clear operational picture: whether funds moved, whether accounts were compromised, what systems were affected, what business processes remain paused, and what evidence supports each conclusion. A useful executive update is concise and decision-oriented. It should identify confirmed facts, open questions, risk to additional payments, customer or vendor impacts, and the next review time.

Do not restore every normal process immediately. Reinstate payment activity only after finance confirms beneficiary information through an independent channel and security confirms that relevant identities have been remediated. For high-value transactions, require dual authorization and a documented callback to a known number. For vendor-bank changes, impose a cooling-off period and separate the requester, verifier, and approver roles.

The incident should also produce measurable improvements. Track time to bank notification, time to account containment, number of related messages found, affected identities, transaction exposure, and recovery outcome. These metrics reveal whether technology and staffing support the response objectives your business expects. They also make budget discussions more concrete than generic warnings about phishing.

💡 Operational lesson: Payment controls must assume that email can be compromised. Independent verification is a financial control, not an optional security awareness step.

Build a response capability before the next request arrives

The strongest BEC response programs are rehearsed before a real transfer is at risk. Finance knows whom to call at the bank. IT knows how to revoke sessions quickly. Security has access to email, identity, endpoint, and network telemetry. Legal and communications know their roles. Vendors understand that bank-detail changes require an out-of-band confirmation.

Run tabletop exercises that include realistic complications: an executive traveling internationally, a vendor requesting a new bank account, a payment approved near a weekend, a compromised mailbox with forwarding rules, or an attacker who has already accessed multiple invoices. Test the decision path, not just the technical checklist. Can the team reach the bank after hours? Who can stop a payment? Who authorizes customer notification? Where is evidence retained?

Detection and response capacity is the other practical decision. Internal teams may have strong tools but limited overnight coverage, fragmented log sources, or no dedicated incident lead. Managed Detection and Response can provide the investigative discipline needed to connect endpoint, identity, and email signals, while escalating actionable findings to the people who can protect the business process.

Clearnetwork helps organizations operate, monitor, tune, investigate, and respond across cybersecurity technologies and programs. That includes improving alert quality, defining escalation paths, integrating security operations with finance and IT, and helping teams move from isolated tools to repeatable incident outcomes.

Make your BEC response faster than the fraudster’s timeline

Assess your monitoring, identity controls, payment-verification process, and incident escalation model before the next urgent wire request arrives.

Request a cybersecurity assessment

Frequently asked questions

Should we delete the fraudulent email after reporting it?

No. Preserve the original message, headers, attachments, URLs, and screenshots before removing it from active inboxes. Security teams need the artifacts to identify spoofing, mailbox compromise, malicious links, related recipients, and indicators that can be blocked across the organization.

What if the fraudulent payment request came from a legitimate vendor email address?

Treat it as a likely vendor-account compromise until independently verified. Call a known contact using a trusted number, confirm bank details through the established vendor-management process, and tell the vendor what you observed. Do not rely on replies within the compromised thread.

Does MFA prevent business email compromise?

MFA significantly reduces password-based account takeover, but it does not eliminate BEC. Attackers can use stolen sessions, adversary-in-the-middle phishing, compromised devices, malicious OAuth applications, or legitimate third-party mailboxes. Layered identity controls and independent payment verification remain essential.

When should we involve an external security provider?

Engage outside expertise when you cannot confidently scope the incident, investigate identity and endpoint activity, maintain continuous monitoring, or coordinate technical response while finance manages a potentially time-sensitive payment recall. Early support can reduce uncertainty when every hour affects recovery options.


About

Ron Samson