Business Email Compromise Investigation: How to Investigate a Compromised Business Email Account
A payment request arrives from a familiar executive.
A vendor sends new banking instructions.
An employee receives an email that appears to come from a colleague asking for an urgent wire transfer.
Everything looks legitimate.
The names are correct. The email conversation appears familiar. The request may even reference a real invoice, project or business relationship.
Then the company discovers that the money went somewhere it was never supposed to go.
This is one way business email compromise (BEC) can unfold.
Business email compromise can be particularly difficult to investigate because the attacker may not rely on obvious malware or visibly suspicious messages. In some cases, the attacker gains access to a legitimate mailbox, studies existing conversations and waits for an opportunity to manipulate a payment or impersonate someone the recipient already trusts.
When that happens, simply changing the email password is not enough to explain the incident.
A business email compromise investigation examines the mailbox, authentication activity, security changes, communications, financial timeline and other available digital evidence to determine what happened and assess the scope of the compromise.
What Is Business Email Compromise?
Business email compromise is a form of fraud in which email, impersonation or compromised business accounts are used to deceive people into transferring money, changing payment information, disclosing sensitive information or taking another unauthorized action.
Not every BEC incident involves an attacker directly accessing a real mailbox.
There are several possible scenarios.
An attacker may compromise an employee’s actual email account.
They may impersonate an executive using a deceptive email address.
They may compromise a vendor’s account and send fraudulent payment instructions from a legitimate conversation.
They may register a domain designed to resemble the company’s real domain.
Or they may combine several techniques.
An investigation therefore needs to establish which scenario actually occurred.
How Business Email Accounts Become Compromised
There is no single BEC attack method.
Phishing is one possibility.
An employee may receive a message directing them to a fake login page. If credentials are entered, the attacker may use them to access the real mailbox.
Password reuse can create another path if credentials exposed elsewhere are still valid.
Other incidents can involve stolen sessions, compromised devices, weak account recovery, social engineering or other forms of unauthorized access.
Investigators should not assume the attack method before examining the evidence.
The objective is to determine which explanation is supported by the available records.
Why BEC Can Be Difficult to Detect
A sophisticated attacker may try to avoid disrupting normal business activity.
Instead of immediately changing the password and locking the legitimate user out, the attacker may quietly observe the mailbox.
That access can reveal:
- Existing customers and vendors
- Invoice schedules
- Payment procedures
- Employee responsibilities
- Executive relationships
- Ongoing transactions
- Writing styles and signatures
- Internal business terminology
This information can make fraudulent communications substantially more convincing.
The attacker may wait until a genuine transaction is approaching and then intervene at exactly the right moment.
A Real Email Account vs. Email Impersonation
This distinction is critical.
Imagine an employee receives payment instructions appearing to come from a vendor.
There are at least two broad possibilities.
In the first, the vendor’s actual mailbox was compromised.
In the second, the attacker created an address or domain that merely resembled the vendor.
Those scenarios require different investigative approaches.
If the real mailbox was accessed, account logs and security settings may contain important evidence.
If the attacker used an impersonation domain, domain-registration information, email headers and message characteristics may become more important.
A BEC investigation should determine which type of incident occurred rather than treating every fraudulent business email as an account takeover.
Warning Signs of Business Email Compromise
Some BEC incidents become obvious only after a fraudulent payment is discovered.
Others produce earlier warning signs.
A company may notice unfamiliar login alerts, unexpected authentication requests, new forwarding rules, unexplained deleted messages or unusual changes to account-security settings.
Employees may receive unexpected requests involving payment changes, gift cards, confidential documents or urgent transfers.
A vendor may suddenly request that payment be sent to a different bank account.
But warning signs should be interpreted in context.
A legitimate vendor can change banks.
An employee can travel and generate unfamiliar login activity.
The investigation needs evidence—not assumptions.
Email Login Activity
Authentication records can be one of the most important evidence sources in an email compromise investigation.
Depending on the email environment and available records, investigators may examine sign-in activity, timestamps, devices, applications and other security information.
An unfamiliar login may deserve attention.
But an IP address or location shown in a security record should not automatically be interpreted as the attacker’s physical location.
VPNs, proxies, mobile networks, cloud infrastructure and other systems can complicate geolocation.
Login evidence becomes much more useful when correlated with other activity.
For example, an unfamiliar authentication event followed minutes later by the creation of a forwarding rule is more significant than the login viewed by itself.
Forwarding Rules and Mailbox Rules
Mailbox rules deserve careful examination during a suspected BEC incident.
An attacker with access to an email account may create rules designed to hide or redirect communications.
For example, messages from a specific customer could potentially be moved into another folder, marked as read or forwarded elsewhere.
This can allow the attacker to interfere with a legitimate conversation while reducing the chance that the account owner notices.
Investigators should examine available mailbox rules and determine when suspicious changes occurred where the records permit it.
Removing a malicious rule may stop ongoing activity.
But documenting it first can be important when an investigation is underway.
Deleted and Hidden Messages
Attackers may attempt to remove evidence of their activity.
Messages can be deleted or moved to unexpected folders.
However, the absence of a message from the inbox does not necessarily mean all evidence of the communication is gone.
Other sources may include the recipient’s mailbox, sent items, archived information, backups, security records or related communications.
Deleted-message recovery itself has limitations, particularly across modern applications and cloud environments.
The broader objective is to reconstruct the communication using the strongest evidence that remains.
Email Headers Can Provide Important Evidence
An original email contains technical information that a screenshot does not fully preserve.
Email headers can provide details relating to message routing, servers, timestamps and authentication.
This information can sometimes help distinguish a message sent through a legitimate account from one sent through a deceptive or unrelated infrastructure.
Headers are not magical attribution tools.
They need technical interpretation and should be considered alongside other evidence.
But when a suspicious email is important, preserving the original message is generally preferable to keeping only a screenshot.
Lookalike Domains
Some BEC incidents use domains designed to resemble legitimate businesses.
A difference may be extremely small.
An attacker might replace a character, add a word or register a domain that visually resembles the genuine one.
When recipients are already expecting an invoice or payment instruction, these differences can be easy to overlook.
An investigation may compare the suspicious domain with the legitimate domain, examine the message headers and document other available information associated with the impersonation.
This is another reason the original email should be preserved.
Invoice and Payment Manipulation
Payment diversion is one of the most financially damaging outcomes associated with BEC.
Consider a company expecting to pay a supplier.
A legitimate email conversation already exists.
Shortly before payment, new instructions arrive:
“We’ve changed banks. Please use the attached account information for this invoice.”
If the request comes from a compromised mailbox—or appears inside a convincing imitation of the existing conversation—the employee may have little reason to suspect fraud.
The investigation then needs to determine how the attacker entered the communication and when the payment instructions changed.
Build the Financial Timeline
When money has been transferred, the email investigation should be correlated with the financial timeline.
Important timestamps may include when the suspicious message was received, when payment instructions changed, when the transfer was authorized, when the bank processed it and when the fraud was discovered.
For example:
9:14 AM — Unfamiliar mailbox login
9:22 AM — New forwarding rule created
10:07 AM — Legitimate vendor email received
10:19 AM — Fraudulent banking instructions sent
11:02 AM — Employee approves payment
1:36 PM — Transfer processed
A timeline like this can reveal relationships that are difficult to understand when each event is viewed separately.
What to Do When a Fraudulent Transfer Has Just Occurred
If a business discovers a suspected fraudulent bank transfer, speed matters.
Contact the financial institution through a verified channel as quickly as possible and report the suspected fraud.
Ask what immediate options are available for attempting to stop, recall or flag the transfer.
If the fraudulent instructions supposedly came from a vendor or business partner, verify the situation using a known telephone number or another independently established communication method—not contact information contained only in the suspicious message.
At the same time, preserve relevant email and account evidence where practical.
Financial response and digital investigation can proceed together.
Preserve Evidence Before It Disappears
Important evidence may exist across several systems.
Preserve suspicious emails in their original form when possible, along with relevant attachments, screenshots, security alerts, authentication records, payment instructions and financial documents.
Record exact dates and times.
If a business uses a managed email environment, relevant administrative or audit records may also exist.
Avoid deleting suspicious messages simply because they are dangerous or unwanted.
Evidence preservation can become important for internal investigation, financial institutions, insurers, legal counsel or law enforcement.
Don’t Assume Changing the Password Ends the Incident
Changing a compromised password is important.
But it does not necessarily remove every form of unauthorized access.
An attacker may have modified recovery settings, created forwarding rules, connected another application or established another mechanism that allows continued access.
The exact possibilities depend on the email system.
A proper investigation therefore reviews the wider account configuration rather than stopping after a password reset.
Determine Whether Other Accounts Were Compromised
Email frequently functions as the recovery channel for other services.
Once a mailbox is compromised, an attacker may attempt to access additional accounts.
These can include cloud platforms, financial accounts, social media, business applications and cryptocurrency services.
Review security notifications and password-reset activity around the incident timeframe.
A BEC investigation can therefore expand into a broader account takeover or cyber investigation when the evidence shows that other systems were affected.
Was an Employee’s Computer Compromised?
Not necessarily.
An attacker can access a cloud-based mailbox without installing malware on the employee’s computer.
This distinction matters.
A compromised email account does not automatically mean the endpoint itself was hacked.
However, if there is evidence suggesting credential-stealing malware, malicious attachments or other endpoint activity, examination of the relevant device may become appropriate.
The investigation should determine whether device forensics is actually necessary instead of assuming every BEC case requires it.
Business Email Compromise and Mobile Phones
Smartphones can also contain relevant evidence.
Employees may receive authentication prompts, security notifications or suspicious communications on mobile devices.
A phone may contain email applications, browser activity or other artifacts related to the incident.
But again, the device should be examined because evidence indicates it is relevant—not merely because it exists.
This keeps the investigation focused and proportionate.
BEC and Multi-Factor Authentication
Multi-factor authentication can significantly improve account security, but investigators should avoid assuming its presence makes unauthorized access impossible.
The relevant question is how authentication was configured and what the records show.
If an account protected by multi-factor authentication was accessed without authorization, the investigation may need to consider the specific authentication events, account settings and surrounding activity.
Do not disable useful security controls simply to preserve an investigation.
Containment remains important.
Can an IP Address Identify the Attacker?
Usually not by itself.
Authentication records may reveal an IP address associated with suspicious activity.
That can be useful technical evidence.
But the address may belong to a VPN, cloud service, mobile provider, corporate network, proxy or compromised device.
An IP address should therefore be treated as an investigative indicator rather than automatic proof of identity.
Reliable attribution generally requires corroborating evidence.
Can BEC Investigations Identify the Attacker?
Sometimes an investigation produces useful attribution leads.
These may include email addresses, domains, account identifiers, telephone numbers, financial destinations, IP information or other technical indicators.
But each has limitations.
A fraudulent email address may use a fake identity.
A domain can be registered using privacy services or inaccurate information.
A bank account may involve another person or organization whose role still needs to be established.
Technical evidence should not be stretched beyond what it actually proves.
Business Email Compromise vs. CEO Fraud
The terms sometimes overlap, but they should not automatically be treated as identical.
CEO fraud generally involves impersonating a senior executive to convince an employee to perform an action such as transferring money or purchasing gift cards.
BEC is broader.
It can involve compromised executives, employees, vendors, attorneys, customers or other trusted business relationships.
The common element is the abuse of business communication and trust to facilitate fraud or unauthorized activity.
Vendor Email Compromise
In some incidents, the victim company’s email environment may be completely secure.
The compromised account belongs to a vendor.
That distinction can be difficult to recognize because the fraudulent instructions may arrive from a legitimate address inside an existing conversation.
Investigators may need cooperation from both organizations to reconstruct what occurred.
This is another reason businesses should avoid assuming the company that sent the money was necessarily the organization whose mailbox was compromised.
Evidence Across Multiple Organizations
BEC investigations can involve evidence held by several parties.
The victim business may hold internal emails and payment records.
A vendor may hold the compromised mailbox.
An email provider may retain security records.
Banks may hold transaction information.
Other service providers may possess relevant logs.
No single investigator necessarily has direct access to all of these sources.
A good investigation should clearly distinguish between evidence that has been examined and records that may exist elsewhere but require appropriate legal or organizational processes to obtain.
Business Email Compromise and Cryptocurrency
Although traditional BEC frequently involves bank transfers, cryptocurrency can also appear in business fraud.
If cryptocurrency is requested or transferred, preserve wallet addresses, transaction hashes, exchange communications and related account records.
Blockchain evidence may help document subsequent movement of the assets.
But tracing a cryptocurrency transaction does not automatically identify the person controlling the destination, and it does not guarantee recovery.
The email compromise and blockchain activity should be investigated as connected but distinct evidence streams.
What Should a BEC Investigation Determine?
A useful investigation should move beyond saying:
“The email account was hacked.”
It should attempt to determine when unauthorized access began, which mailbox or identity was involved, how the attacker interacted with communications, whether rules or settings were changed, which fraudulent messages were sent, what financial activity followed and whether additional accounts or systems were affected.
The answers depend on the evidence available.
Some questions may remain unresolved.
Those limitations should be documented rather than replaced with assumptions.
Reporting the Findings
A business email compromise investigation may need to support internal decision-making, insurance claims, financial recovery efforts, legal counsel or law-enforcement reporting.
The findings should therefore be understandable.
A useful report can document the incident timeline, relevant email activity, security changes, fraudulent communications, financial events, evidence sources and limitations.
Technical evidence should support the explanation rather than overwhelm it.
The objective is to make the incident understandable to someone who was not present when it occurred.
How Cyb3rsect Approaches Business Email Compromise Investigations
Cyb3rsect approaches BEC investigations by reconstructing the incident across the systems that matter.
The investigation begins with the business communication.
Was the message sent from a legitimate compromised mailbox?
Was a lookalike domain used?
Did the attacker enter an existing conversation?
When did suspicious account activity begin?
Were mailbox rules or security settings changed?
The investigation then follows the consequences.
Were payment instructions altered?
Did money move?
Were other accounts accessed?
Is relevant evidence available from an employee’s device, email environment or other digital systems?
The objective is not to force every case into the same explanation.
It is to determine what the available evidence supports.
If a mailbox was compromised, the evidence should demonstrate why that conclusion is reasonable.
If the incident involved external impersonation instead, that distinction matters.
If the available records cannot establish how the attacker obtained access, the investigation should say so.
Business Email Compromise Is an Evidence Problem as Well as a Security Problem
A company can secure a compromised mailbox and still not understand the incident.
The password can be changed.
Fraudulent rules can be removed.
Sessions can be revoked.
But important questions may remain:
When did the attacker gain access?
What did they see?
Which messages did they send or manipulate?
How did the fraudulent payment occur?
Were other accounts affected?
What evidence supports those conclusions?
That is why serious BEC incidents may require both security response and investigation.
Cyb3rsect provides cyber investigation and digital forensic support for businesses dealing with business email compromise, unauthorized mailbox access, account takeover, payment diversion and other cyber incidents involving digital evidence.