Business email compromise (BEC) succeeds because it exploits trusted business processes: an executive approval, a vendor invoice, a payroll change, or an urgent wire instruction. The message may come from a spoofed domain, a compromised supplier mailbox, or an internal account that has already passed multifactor authentication. In every case, the first 24 hours determine whether a suspicious request becomes a contained near miss, a recoverable financial loss, or a wider security breach.
The FBI’s Internet Crime Complaint Center has consistently identified BEC as one of the costliest cybercrime categories. The loss is not limited to the initial transfer. Organizations also face recovery costs, payment delays, legal review, business disruption, vendor friction, insurance notifications, and the possibility that attackers still control email accounts or endpoint sessions.
A disciplined response needs finance, IT, security, legal, leadership, and the bank working from the same facts. This guide provides a practical first-day response plan for organizations that receive, approve, or send a fraudulent payment request.
Do not begin with a long email investigation while a payment remains in motion. The immediate priorities are financial containment, account containment, and evidence preservation. Assign one incident owner who can coordinate decisions and document timestamps. That person should have authority to escalate to the CFO, CIO, general counsel, insurer, bank relationship manager, and external incident-response partner.
If the request was received but not paid, immediately pause the invoice, vendor-master change, payroll update, purchase order, or disbursement workflow. If money was sent, contact the originating financial institution using a known phone number, not any number supplied in the suspicious message. Request a recall, freeze, or reversal through the bank’s fraud team. For U.S. organizations, report the incident to the FBI IC3 and ask law enforcement whether the Financial Fraud Kill Chain process may apply.
The first hour is about preventing additional harm. Finance should call the bank and stop related payments. Security and IT should assess whether the sender account, recipient account, or both may be compromised. Avoid deleting the message or forwarding it broadly; that can alter evidence, create confusion, and expose malicious links to more employees.
| Time window | Required action | Primary owner |
|---|---|---|
| 0–15 minutes | Pause payment, call the bank, preserve the original email and transaction details. | Finance lead |
| 15–30 minutes | Open an incident, identify affected identities, and begin mailbox containment. | Security and IT |
| 30–60 minutes | Verify vendors out of band, search for related messages, notify decision makers. | Incident owner |
For an internal mailbox suspected of compromise, revoke active sessions, reset the password, require MFA re-registration where appropriate, and review authentication activity before restoring normal access. Disable suspicious inbox rules, forwarding rules, delegates, OAuth application grants, and recently created aliases. Do not assume a password reset alone removes persistence. Attackers commonly establish forwarding rules or consent to malicious applications so they can continue watching financial conversations.
For an external vendor or partner mailbox, do not treat a reply to the same thread as verification. Use a known contact from the executed contract, vendor master file, customer relationship system, or previously verified phone number. Confirm bank-account changes and payment instructions verbally using a documented callback procedure.
BEC investigations fail when teams focus only on the email’s wording. The question is not simply whether the message looked malicious; it is whether an identity, mailbox, device, payment workflow, or supplier relationship has been manipulated. Build a concise timeline that connects the financial request to security events.
This is where security operations maturity matters. Email, identity, endpoint, firewall, and cloud logs often sit in separate tools, owned by separate teams. A capable SOC correlates these signals and distinguishes a spoofed request from a compromised Microsoft 365 or Google Workspace account. Organizations without round-the-clock coverage should consider how Managed SOC Services can provide continuous monitoring, alert triage, and escalation when finance fraud intersects with identity compromise.
Preserve evidence in a restricted case repository. Capture screenshots of the payment request and bank portal status, but also keep source data. Record who accessed the mailbox, who changed credentials, which rules were removed, and when the bank was contacted. Those details support recovery, cyber-insurance requirements, legal review, and later process improvements.
Once immediate containment is underway, expand the search. BEC actors often spend days or weeks reading correspondence before sending a request at the most credible moment. That dwell time means other conversations may be compromised even when only one fraudulent invoice has been identified.
Search sent items, deleted items, forwarding rules, delegates, and conversations involving finance leaders, vendors, payroll, and legal teams.
Review privileged roles, MFA changes, OAuth consents, conditional-access exclusions, service accounts, and recently enrolled devices.
Flag pending payments, recent bank-detail modifications, urgent approvals, unusual beneficiaries, and transactions approved outside normal workflows.
Search for lateral targeting. If an executive mailbox was accessed, attackers may impersonate that person toward subsidiaries, customers, law firms, payroll providers, and banks. If a vendor account was compromised, your organization may be one of many customers receiving fraudulent remittance instructions. Alert the relevant parties with factual, limited information: what was observed, what they should verify, and a trusted callback channel.
Use the CISA phishing guidance and your incident-response plan to determine notification requirements. Legal counsel should assess contractual duties, privacy exposure, securities obligations, and jurisdiction-specific breach rules. Avoid speculative statements. Early communications should be accurate, time-stamped, and approved through the incident command structure.
Eradication means removing the attacker’s ability to regain access, not simply closing the visible ticket. Review every authentication method associated with affected identities. Reset passwords, revoke refresh tokens and sessions, remove unauthorized MFA methods, disable malicious OAuth applications, and rotate credentials for affected service accounts. If endpoint compromise is plausible, isolate the device and conduct a full endpoint investigation.
Endpoint visibility is especially important when BEC begins with an infostealer, browser-session theft, or remote-access compromise. Security teams should examine browser extensions, saved credentials, downloaded files, command-line activity, remote-management tools, and EDR detections. Organizations using Falcon should ensure their monitoring partner can investigate identity-linked endpoint events, not merely close alerts. Managed CrowdStrike support can help teams tune detections, investigate suspicious behavior, and coordinate containment across endpoint and identity workflows.
Validate mail controls as well. Confirm SPF, DKIM, and DMARC alignment for your domains, then examine whether lookalike domains are being used against your organization. Strengthen external email tagging, impersonation protection, attachment detonation, URL analysis, and rules governing automatic forwarding. These controls reduce exposure, but they do not replace payment verification because a legitimate account can still send a fraudulent instruction.
By the end of the first day, leadership needs a clear operational picture: whether funds moved, whether accounts were compromised, what systems were affected, what business processes remain paused, and what evidence supports each conclusion. A useful executive update is concise and decision-oriented. It should identify confirmed facts, open questions, risk to additional payments, customer or vendor impacts, and the next review time.
Do not restore every normal process immediately. Reinstate payment activity only after finance confirms beneficiary information through an independent channel and security confirms that relevant identities have been remediated. For high-value transactions, require dual authorization and a documented callback to a known number. For vendor-bank changes, impose a cooling-off period and separate the requester, verifier, and approver roles.
The incident should also produce measurable improvements. Track time to bank notification, time to account containment, number of related messages found, affected identities, transaction exposure, and recovery outcome. These metrics reveal whether technology and staffing support the response objectives your business expects. They also make budget discussions more concrete than generic warnings about phishing.
The strongest BEC response programs are rehearsed before a real transfer is at risk. Finance knows whom to call at the bank. IT knows how to revoke sessions quickly. Security has access to email, identity, endpoint, and network telemetry. Legal and communications know their roles. Vendors understand that bank-detail changes require an out-of-band confirmation.
Run tabletop exercises that include realistic complications: an executive traveling internationally, a vendor requesting a new bank account, a payment approved near a weekend, a compromised mailbox with forwarding rules, or an attacker who has already accessed multiple invoices. Test the decision path, not just the technical checklist. Can the team reach the bank after hours? Who can stop a payment? Who authorizes customer notification? Where is evidence retained?
Detection and response capacity is the other practical decision. Internal teams may have strong tools but limited overnight coverage, fragmented log sources, or no dedicated incident lead. Managed Detection and Response can provide the investigative discipline needed to connect endpoint, identity, and email signals, while escalating actionable findings to the people who can protect the business process.
Clearnetwork helps organizations operate, monitor, tune, investigate, and respond across cybersecurity technologies and programs. That includes improving alert quality, defining escalation paths, integrating security operations with finance and IT, and helping teams move from isolated tools to repeatable incident outcomes.
Assess your monitoring, identity controls, payment-verification process, and incident escalation model before the next urgent wire request arrives.
No. Preserve the original message, headers, attachments, URLs, and screenshots before removing it from active inboxes. Security teams need the artifacts to identify spoofing, mailbox compromise, malicious links, related recipients, and indicators that can be blocked across the organization.
Treat it as a likely vendor-account compromise until independently verified. Call a known contact using a trusted number, confirm bank details through the established vendor-management process, and tell the vendor what you observed. Do not rely on replies within the compromised thread.
MFA significantly reduces password-based account takeover, but it does not eliminate BEC. Attackers can use stolen sessions, adversary-in-the-middle phishing, compromised devices, malicious OAuth applications, or legitimate third-party mailboxes. Layered identity controls and independent payment verification remain essential.
Engage outside expertise when you cannot confidently scope the incident, investigate identity and endpoint activity, maintain continuous monitoring, or coordinate technical response while finance manages a potentially time-sensitive payment recall. Early support can reduce uncertainty when every hour affects recovery options.
Map who owns 24/7 monitoring, containment, tooling and reporting across MSSP, managed SOC and MDR—then…
Reduce portfolio company cyber risk in 100 days: validate MFA, backups and exploited vulnerabilities, assign…
Cut SIEM false positives without losing threat coverage: use evidence, layered tuning, deduplication, and expiring…
Prove ransomware recovery in 90 days: secure identities, test immutable backups, contain threats, and clarify…
Choose EDR, managed EDR or MDR with confidence: compare 24/7 monitoring, human triage, containment authority…
Catch Microsoft 365 identity attacks faster by correlating risky sign-ins, inbox rules and MFA changes—then…