BEC: The First 24 Hours
What to do, and what not to do, after a suspected email compromise

Field Checklist Free to Use

Business email compromise is a race. The attacker is reading your mail, working your vendors, and moving toward a payment. What you do in the first 24 hours decides whether this is a contained incident or a six-figure loss.

Hour 0–2: Take Back the Account

Containment first. Every minute the attacker holds the mailbox, they are learning more and getting closer to money movement.

Action What It Does Why It Can't Wait
Reset & Revoke Reset the password AND revoke all active sessions and refresh tokens. A reset alone does not kick the attacker out. Attackers persist through stolen session tokens long after a password change.
Kill Mailbox Rules Review and disable inbox rules: forwarding, auto-delete, and "move to RSS Feeds" style hiding rules. Rules silently divert the victim's mail so the fraud stays invisible.
Re-enroll MFA Remove registered MFA methods the attacker may have added, then re-enroll the legitimate user. Attacker-registered authenticators survive password resets.
Review OAuth Grants Check for newly consented applications on the account and revoke anything unrecognized. Malicious app consents give persistent mailbox access with no login required.
Block Known Bad Block sender domains, lookalike domains, and indicators from the phish that started it. The same lure is usually running against the rest of your organization.

If Money Moved: Act in Minutes, Not Hours

Wire recalls are won or lost fast. If a fraudulent payment went out, this happens before anything else.

1

Call Your Bank

Contact the bank's fraud department immediately and request a recall / SWIFT recall on the transfer. Speed matters more than paperwork.

2

File with IC3

File at ic3.gov and request the FBI's Financial Fraud Kill Chain. Most effective within 72 hours for wires over $50,000.

3

Notify Counsel & Carrier

Engage legal counsel and your cyber insurance carrier early. Late notice can jeopardize coverage.

Do / Don't

The most expensive BEC mistakes are self-inflicted in the first day.

Do

  • Preserve everything: export the phishing email with full headers, message trace, audit logs, and sign-in logs before they age out.
  • Assume more than one mailbox: check sign-in logs across the tenant for the same source IPs and user agents.
  • Communicate out-of-band: coordinate response by phone or a clean channel, not the compromised tenant.
  • Verify payment changes by voice: call vendors on a known number before honoring any banking-detail change.

Don't

  • Don't tip off the attacker: no confrontational emails from the compromised mailbox while they still have access.
  • Don't mass-delete the phishing campaign before evidence is preserved.
  • Don't stop at one account: a single "reset and done" response is how repeat losses happen.
  • Don't announce broadly until scope is known. Premature notice creates legal exposure and panic.

Hour 2–24: Scope It

Once the account is contained, establish what the attacker saw, touched, and set up. This determines your legal obligations and whether the incident is actually over.

Question Where the Answer Lives
How did they get in? Original phish, sign-in logs, MFA prompts. Phishing kit, token theft, or password reuse.
How long were they in? Unified audit log and sign-in history, first anomalous login to containment.
What did they read or take? Mailbox audit records: items accessed, searches run, attachments opened, mail forwarded.
Who else got the lure? Message trace across the tenant: same sender, subject, or URL pattern.
Is notification required? Counsel's call, driven by what data was in the mailbox and which regulations apply.

Log retention is shorter than you think. Export now, analyze later. See Cloud Log Sources That Save Cases.

When to Call Us

Money moved, executives are involved, or you can't establish scope. Olympus Cyber leads BEC response end-to-end: containment, forensics, recall coordination, and defensible reporting for legal, insurance, and the board.
🚨 Emergency IR