BEC Incident Response

Business Email Compromise Wire Recovery Starts Now

Business email compromise caused $2.77 billion in FBI-reported losses across 21,442 complaints in 20241. If your organization wired funds based on a fraudulent email, the first 24-72 hours determine whether recovery is possible. In 2024 the FBI IC3 Recovery Asset Team froze approximately $561 million of $848 million in attempted fraud transfers, a 66% success rate1.

CMMC Registered Practitioner Org | BBB A+ Since 2003 | 30+ Years Experience
Two Paths Forward

Choose What You Need

I Need Expert BEC Response Now

  • Wire recovery coordination with banks and FBI IC3
  • Email header forensics and attacker attribution
  • Full M365/Google Workspace security audit
  • CMMC Registered Practitioner with 30+ years experience

I Want to Handle This Myself

  • BEC identification and response guides
  • Email security checklists and templates
  • Incident response templates for non-technical teams
  • Access via Training Academy
Act Now

5 Steps After a BEC Attack

Recovery rates drop dramatically after 24 hours. Follow these steps immediately.

01

Contact your bank and request an immediate wire recall

02

Preserve the fraudulent email as .eml (do not forward)

03

File an FBI IC3 complaint at ic3.gov within 72 hours

04

Audit all email accounts for hidden forwarding rules

05

Engage an incident response team for full forensics

Understand the Attack

Anatomy of a Business Email Compromise Attack

Business email compromise is financial fraud built on top of email trust. The FBI Internet Crime Complaint Center recorded $2.77 billion in reported BEC losses across 21,442 complaints in 20241, and what makes the category so costly is that the final act rarely involves malware at all. By the time the fraudulent payment request lands, the technical intrusion is finished; what remains looks, to the person wiring the money, exactly like a normal day at work.

The intrusion phase comes first. Attackers get into a business mailbox through credential phishing, password reuse exposed in an unrelated breach, or increasingly through adversary-in-the-middle phishing kits that proxy the real login page and capture the session token, defeating basic multi-factor authentication in the process. Some campaigns skip the break-in entirely and rely on lookalike domains, registering an address one character away from a real vendor or executive and counting on nobody reading carefully.

Then comes the quiet phase, and it is the part victims consistently underestimate. An attacker inside a mailbox does not announce themselves. They read. They learn the billing cycle, the names on the finance team, which customers owe money, how the CEO phrases requests, and what a legitimate invoice from each vendor looks like. They set up mailbox rules that forward copies of relevant threads to themselves and auto-delete the replies that would give the game away. This surveillance can run for weeks while the attacker waits for the highest-value moment, typically a real, expected payment they can redirect.

The Strike

The fraudulent request, when it comes, is engineered to survive scrutiny. It often arrives inside a hijacked legitimate thread, quoting the genuine history, at the moment a real payment is due. The only change is the destination account, explained by a plausible story: new bank, updated remittance details, an accountant on leave. Common variants include executive impersonation pressing urgency on a wire, vendor email compromise redirecting genuine invoices, and payroll diversion quietly rerouting direct deposits. Each works because the recipient has no visible reason to doubt a message that is, in every respect except the account number, real.

Why the Aftermath Is Bigger Than the Wire

Recovering the money is the urgent problem, but it is not the only one. A compromised mailbox is a data breach: the attacker had access to every message and attachment in it, potentially including customer records, credentials, and contract terms. The persistence mechanisms they planted, forwarding rules, rogue OAuth application grants, registered devices, and altered recovery settings, survive a simple password change. And whoever they impersonated may have been used to defraud your customers and vendors too, which makes scoping the intrusion honestly a matter of protecting relationships as well as systems. This is why Petronella Technology Group, Inc. treats every BEC case as an intrusion investigation with a financial recovery component, never as a wire problem alone.

The Variants We See Most

Although every case has its own texture, most BEC incidents land in a handful of recognizable patterns, and knowing which one you are inside changes the response:

  • Vendor email compromise. The intrusion is in a supplier's mailbox, and your organization receives a genuine-looking invoice or bank-detail change on a real thread. The money is lost on your side even though the breach began on theirs, and both tenants need review.
  • Executive impersonation. A spoofed or compromised leadership account presses urgency onto someone with payment authority: a confidential acquisition, a deadline, a request to handle it quietly. The pressure to skip verification is the attack.
  • Payroll diversion. HR receives a routine-looking request from an employee's account to update direct deposit details. The paycheck quietly reroutes to an attacker-controlled account, often unnoticed until payday.
  • Thread hijacking after full mailbox takeover. The most damaging pattern: the attacker replies inside real conversations from the real account, with history quoted and tone matched, redirecting a payment both sides expected to happen.

Each variant leaves different forensic fingerprints in the tenant logs and calls for a different mix of recall urgency, counterparty notification, and containment, which is why the investigation starts by establishing precisely which pattern, or combination, you are dealing with.

Our Response

What We Deliver in a BEC Engagement

Wire Recovery Coordination

We work with your bank, the receiving institution, and FBI IC3 Recovery Asset Team to maximize the chance of recovering transferred funds.

Email Forensics and Attribution

Full email header analysis, DMARC/SPF/DKIM verification, sending infrastructure mapping, and documentation for law enforcement referral.

M365 / Google Workspace Audit

Comprehensive review of mail flow rules, OAuth apps, conditional access, and MFA gaps. We find and remove every persistence mechanism. Learn more

Prevention and Hardening

DMARC enforcement, conditional access policies, legacy protocol blocking, out-of-band wire verification, and BEC-specific employee training.

The Recovery Window

Why the First 72 Hours Decide the Outcome

Wire recovery is a race against laundering. The receiving account in a BEC scheme is almost never the final destination; it belongs to a money mule, and the funds are typically split, forwarded onward, withdrawn, or converted to cryptocurrency within days. Once that dispersal happens, the money is functionally gone. Before it happens, there is a genuine window in which banks and the FBI can freeze funds in place, and the 2024 numbers show the window is real: the FBI IC3 Recovery Asset Team froze approximately $561 million of $848 million in attempted fraud transfers, a 66% success rate, on qualifying complaints that reached it in time1.

Working that window well means doing several things in parallel rather than in sequence. Your bank needs the recall request and the fraud designation immediately, with the exact amount, date, beneficiary name, account, and receiving institution. The FBI IC3 complaint needs to be filed with the same precision, because accurate transaction details are what allow the federal process, working with the receiving bank, to move against the funds. Domestic transfers and international ones follow different paths with different odds, which is one more reason the details must be right the first time. Meanwhile the compromised mailbox has to be contained, because attackers watch for recall attempts and have been known to send counter-messages from the victim's own account to keep the fraud alive.

What you should not do matters just as much. Do not forward the fraudulent email around the company, which alters headers and spreads confusion; export it intact as a .eml file. Do not wipe or reset the affected account before evidence is preserved. And do not assume a single fraudulent wire is the whole incident; in our casework it frequently is not, and the same access that produced one redirected payment has often touched others still in flight. When you call (919) 348-4912, we run the bank, IC3, and containment tracks simultaneously so no part of the window is spent waiting on another.

What to Have Ready When You Call

You do not need a complete picture to start; delay costs more than gaps. But the first hour goes faster if someone can pull together the wire confirmation with the exact amount, date, and beneficiary details, the fraudulent email preserved as it sits in the mailbox, the name of your bank contact if one is already engaged, and a short timeline of who noticed what, when. Decision-makers matter too: recall requests, fraud designations, and containment steps in the mail tenant each need someone with authority to say yes quickly. If your organization has cyber insurance, have the policy or broker contact identified early, since prompt notice protects the claim while the technical work proceeds.

The Investigation

What a Full Business Email Compromise Forensic Response Covers

Scoping the intrusion. The first investigative question is how far the attacker reached: which accounts they controlled, when access began, and what they read or took. We reconstruct that from tenant audit logs, sign-in records, and message trace data in Microsoft 365 or Google Workspace, mapping attacker sessions by address, device, and behavior. The answer routinely changes the incident's shape; a case that walks in as one bad wire often turns out to be a months-long mailbox compromise with several affected threads.

Evicting the attacker completely. Password resets alone do not end a BEC intrusion. We enumerate and remove every persistence mechanism: inbox forwarding and deletion rules, delegated permissions, rogue OAuth application grants with mailbox scopes, attacker-registered MFA methods and devices, and altered recovery settings. Sessions are revoked tenant-wide, legacy authentication protocols are disabled, and conditional access is tightened so the same entry path is closed, not just the current session.

Attribution and evidence. Full header analysis of the fraudulent messages, DMARC, SPF, and DKIM verification, and mapping of the sending infrastructure establish how the fraud was executed and support the law enforcement referral. Everything is preserved and documented to an evidentiary standard by a team that includes a North Carolina licensed digital forensic examiner, because bank disputes, insurance claims, and any litigation with counterparties will all turn on the quality of this record.

Assessing the data exposure. Finally, we determine what the mailbox access exposed: personal information, customer data, credentials, financial records. That assessment feeds the notification decisions your counsel must make and the honest conversations with any vendors and customers who received fraudulent messages from your domain. Organizations with regulatory obligations, from HIPAA to CMMC, get the exposure mapped against their specific compliance requirements as part of our broader security practice.

Prevention

Building a BEC-Resistant Organization

Every BEC engagement ends with the same client question: how do we make sure this never happens again? The durable answer combines technical controls with payment process discipline, because either alone leaves the door open:

  • Phishing-resistant authentication. Enforce MFA everywhere, and move finance, executives, and administrators to phishing-resistant methods such as hardware security keys, which adversary-in-the-middle kits cannot proxy.
  • Close the legacy doors. Block legacy authentication protocols that bypass MFA entirely, restrict or review OAuth application consent, and alert on new inbox rules and forwarding changes, the classic first move of a mailbox intruder.
  • DMARC at enforcement. A reject policy on your domains stops attackers from sending as you, protecting your customers and vendors from impersonation that damages your relationships even when it costs you nothing directly.
  • Out-of-band payment verification. Any new payee, changed bank detail, or unusual payment request gets verified by voice at a known number before money moves. This single procedural rule defeats the finale of nearly every BEC variant, including ones that start with a perfectly compromised mailbox.
  • Train the people who move money. Generic phishing awareness is not enough. Finance and executive teams need training built around BEC scenarios: hijacked threads, vendor detail changes, and urgency pressure from apparent leadership.

We implement this stack as a package after incidents, and, for organizations that would rather skip the incident, as a standalone hardening engagement beginning with a Microsoft 365 security audit that finds the gaps a BEC crew would use.

FAQ

Frequently Asked Questions

What is business email compromise (BEC)?

BEC is a cybercrime where attackers gain access to or spoof a business email account to trick employees into transferring funds or sensitive data. The FBI reported $2.77 billion in BEC losses across 21,442 complaints in 2024, one of the costliest cybercrime categories in the IC3 Annual Report1.

Can wired funds be recovered after a BEC attack?

Recovery is possible but time-sensitive. In 2024 the FBI IC3 Recovery Asset Team froze approximately 66% of attempted fraud dollars on complaints that were filed quickly1. Contact your bank for a wire recall, file at ic3.gov, and call us at (919) 348-4912.

How do BEC attacks work?

Attackers compromise an email account through phishing or credential stuffing, then monitor email traffic to identify payment patterns. When the timing is right, they send a convincing email requesting a wire transfer to a fraudulent account.

How do I prevent BEC attacks?

Enforce MFA on all email accounts, deploy DMARC with a reject policy, block legacy authentication, and require out-of-band verification for wire transfers. We provide M365 security audits and employee training to close these gaps.

What does Petronella Technology Group do for BEC recovery?

End-to-end BEC incident response: wire recovery coordination, email header forensics, full M365/Google Workspace security audit, removal of malicious forwarding rules and OAuth apps, attacker attribution, employee training, and ongoing monitoring. Call (919) 348-4912.

We had MFA enabled. How did the attacker still get in?

Most commonly through adversary-in-the-middle phishing, where the victim signs in through a proxy of the real login page and the attacker captures the authenticated session token, satisfying the MFA prompt in the process. Other routes include legacy protocols that skip MFA, stolen session cookies from an infected device, and attacker-registered MFA methods added after an initial compromise. Part of our audit is determining exactly which path was used, because each one implies a different fix.

Do we need to notify customers, vendors, or regulators?

Possibly, and the decision should be made with counsel on the basis of evidence rather than assumption. Notification duties depend on what data the mailbox actually exposed, which laws and contracts govern your organization, and whether third parties received fraudulent messages from your accounts. Our exposure assessment gives your attorneys the factual record those decisions require. Practically, vendors and customers who were sent fraudulent payment instructions should be warned quickly regardless, before they act on them.

Will insurance cover a BEC loss?

Frequently there is coverage under cyber, crime, or social engineering fraud provisions, but policies differ sharply in triggers, sublimits, and control requirements, and insurers examine whether verification procedures were followed. Notify your broker promptly, since late notice can imperil a valid claim, and preserve the incident evidence they will request. We produce the forensic documentation that supports the claim; interpreting the policy belongs with your broker and counsel. Organizations reviewing their posture before an incident can start with our cyber insurance readiness assessment.

The fraudulent email came from a vendor's real address. Whose incident is it?

Operationally, both parties'. Vendor email compromise means the intrusion lives in the vendor's tenant, but the financial loss and the recovery race are yours, and your own tenant still needs to be checked, since attackers who profile a payment relationship sometimes hold access on both sides. Liability between the parties is a legal question that turns heavily on the evidence, which is another reason header analysis and preserved originals matter from hour one.

How long does a BEC investigation take?

Containment, the recall request, and the IC3 filing happen on day one. The forensic investigation, scoping access, evicting persistence, completing attribution, and assessing data exposure, typically runs one to three weeks depending on tenant size and how long the attacker was inside. Hardening work follows on its own schedule. You receive a written report suitable for banks, insurers, law enforcement, and counsel at the end.

The money is already gone. Is an investigation still worth it?

Yes, because the wire was the symptom and the access was the disease. Until the intrusion is scoped and evicted, you do not know whether more payments are queued for redirection, what data left the mailbox, or whether your accounts are being used to defraud others. The investigation also produces the record that supports insurance recovery and limits liability disputes, which for many victims recovers more value than the wire recall itself.

A BEC case is won or lost twice: once in the first 72 hours with the banks, and again over the following weeks in the tenant, where the intrusion actually lives.

BEC engagements are led by Craig Petronella, founder and principal of Petronella Technology Group, Inc., serving clients since 2002. Craig is a CMMC Registered Practitioner and a North Carolina licensed digital forensic examiner (License #604180) with an MIT certification in artificial intelligence and more than 30 years of cybersecurity and incident response experience. The same team delivers emergency incident response and digital forensics, so your evidence is handled to the standard that banks, insurers, and courts expect.

CMMC Registered PractitionerNC Licensed Digital Forensic Examiner #604180MIT AI Certificate30+ Years Experience
Time Is Critical

Every Hour Reduces Recovery Odds

The FBI IC3 Recovery Asset Team's 2024 results, approximately $561 million frozen of $848 million in attempted fraud, came from complaints reported fast, typically within 72 hours1. After that window, funds are typically laundered and converted to cryptocurrency. Act now.

Citations

  1. Federal Bureau of Investigation, Internet Crime Complaint Center, 2024 Annual Report. Business Email Compromise statistics ($2.77 billion in reported losses, 21,442 complaints) and Recovery Asset Team results (approximately $561 million frozen of $848 million in attempted fraud, a 66% success rate). ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf