BUSINESS EMAIL COMPROMISE & EMAIL ACCOUNT INVESTIGATIONS
Business Email Compromise
Built on Evidence.
Cyber Centaurs investigates business email compromise and suspected email-account intrusions to determine how unauthorized access occurred, reconstruct account and mailbox activity, identify persistence or forwarding mechanisms, evaluate potential data exposure, and develop defensible findings for organizations and counsel.
24/7 Incident Response
WHEN TO ENGAGE
When Email Activity
No Longer Makes Sense.
Business email compromise often becomes visible only after fraudulent messages, payment instructions, unusual authentication, or unexpected mailbox behavior is discovered. Investigation can help reconstruct the activity that occurred before and after the compromise became apparent.
Suspicious or Unauthorized Logins
Fraudulent Payment Instructions
Unexpected Inbox or Forwarding Rules
Messages Sent Without User Knowledge
MFA or Authentication Anomalies
Suspected Email or Cloud Data Access
RESPONSE OBJECTIVES
Secure the Account.
Preserve the Record.
A business email compromise response should reduce ongoing unauthorized access while preserving the identity, mailbox, cloud, endpoint, and security evidence needed to understand what occurred.
Contain Access
Support actions to revoke unauthorized sessions, address compromised credentials, review persistence, and reduce continued threat-actor access.
Preserve Evidence
Protect authentication records, mailbox audit data, email content, cloud activity, endpoint evidence, security telemetry, and other relevant sources.
Reconstruct Activity
Develop a timeline of unauthorized access, mailbox changes, message activity, persistence mechanisms, cloud access, and related threat-actor actions.
Establish Impact
Determine the supported scope of affected accounts, communications, sensitive information, fraudulent activity, and potential data exposure.
BEC INVESTIGATION EVIDENCE
Evidence Across Identity,
Email & Cloud.
Business email compromise investigations often require evidence from identity systems, mailbox records, cloud applications, endpoints, security tools, and business communications. Correlating those sources can help distinguish legitimate user activity from unauthorized access. Related response work may involve data breach investigation and incident response.
Identity & Authentication
sign-in activity
IP information
MFA events
session activity
conditional access
identity-provider records
Mailbox Activity
mailbox audit records
message activity
folder activity
deleted items
mailbox access
Inbox & Forwarding Rules
inbox rules
forwarding
redirects
hidden rules
mail-flow changes
persistence indicators
Email & Communications
message headers
sent messages
attachments
fraudulent threads
impersonation activity
communications history
Cloud & Applications
Microsoft 365
Entra ID
OAuth applications
OneDrive
SharePoint
other cloud activity
Endpoint & Security Evidence
browser artifacts
credential activity
endpoint logs
EDR / XDR
phishing artifacts
INVESTIGATIVE QUESTIONS
What Did the Threat Actor
Do With the Account?
A compromised mailbox is only one part of the incident. The investigation should establish how unauthorized access developed, what actions occurred within the account, what information may have been exposed, and whether access extended into other systems or cloud resources.
How Did Unauthorized Access Occur?
Evaluate available evidence concerning phishing, credential compromise, session or token theft, malicious applications, password reuse, or other potential access mechanisms.
When Did the Compromise Begin?
Correlate authentication, mailbox, cloud, endpoint, and security activity to establish the supported timeline of unauthorized access.
What Mailbox Changes Were Made?
Identify forwarding rules, inbox rules, redirects, deleted messages, mailbox configuration changes, or other activity associated with persistence or concealment.
What Messages or Data Were Accessed?
Evaluate available evidence concerning mailbox activity, attachments, cloud storage, sensitive communications, and other information potentially exposed through the compromised identity.
Were Fraudulent Communications Sent?
Reconstruct message activity associated with impersonation, payment instructions, vendor fraud, altered threads, or other unauthorized communications.
Did the Compromise Extend Beyond Email?
Evaluate evidence of cloud-resource access, connected applications, additional account compromise, endpoint activity, or other systems associated with the affected identity.
BEC INVESTIGATION PROCESS
Reconstruct the Access.
Establish the Impact.
The investigative process is structured to secure the affected identity, preserve available evidence, reconstruct unauthorized activity, determine scope, and communicate supported findings clearly.
01
Triage & Secure
Identify affected accounts, understand actions already taken, assess current access, and support immediate containment priorities.
02
Preserve & Collect
Collect relevant identity, mailbox, cloud, endpoint, security, and communication evidence before retention or remediation changes the available record.
03
Analyze Account Activity
Examine authentication, sessions, mailbox activity, forwarding rules, communications, cloud access, and other evidence associated with unauthorized use.
04
Correlate & Determine Scope
Develop timelines, identify affected accounts and resources, evaluate fraudulent activity and potential data exposure, and distinguish confirmed findings from unresolved questions.
05
Report & Advise
Document supported findings, evidentiary limitations, impact, and recommendations relevant to remediation, recovery, counsel, leadership, insurers, or other authorized stakeholders.
FRAUDULENT COMMUNICATIONS
Reconstruct the Messages
Behind the Fraud.
BEC incidents frequently involve more than unauthorized access. Threat actors may monitor legitimate conversations, impersonate employees or vendors, manipulate payment instructions, or use compromised accounts to make fraudulent communications appear authentic.
Executive Impersonation
Unauthorized messages sent as executives or other trusted employees.
Vendor Impersonation
Fraudulent communications involving suppliers, customers, partners, or other business relationships.
Payment Instruction Changes
Altered banking details, invoices, wire instructions, ACH information, or payment requests.
Thread Hijacking
Use of legitimate email conversations to insert fraudulent instructions into existing business communications.
Mailbox Monitoring
Evidence that a threat actor may have observed communications before acting or selecting a fraudulent opportunity.
Fraud Timeline
Correlation of unauthorized access, communications, payment activity, and other evidence to reconstruct relevant events.
BREACH IMPACT
Beyond the Fraudulent
Email.
A business email compromise can expose more than payment information. Depending on the affected account, unauthorized access may involve sensitive communications, attachments, personal information, cloud files, business records, or other confidential data.
Mailbox Exposure
Evaluate the available record for evidence concerning unauthorized mailbox access and activity.
Attachments & Sensitive Communications
Identify relevant messages, attachments, and information sources implicated by the investigation where evidence permits.
Cloud-Connected Data
Assess associated OneDrive, SharePoint, applications, or other cloud resources accessible through the compromised identity.
Supported Scope
Document confirmed findings, potential exposure, evidentiary limitations, and questions that cannot be resolved from available records.
WHY CYBER CENTAURS
Technical Depth.
Investigative Judgment.
A compromised mailbox leaves evidence across more than email.
Cyber Centaurs combines incident response, digital forensics, identity investigation, and cloud-forensic expertise to reconstruct business email compromise activity and provide organizations and counsel with findings grounded in the available technical record.
Identity & Cloud Investigation
Technical analysis across authentication, Microsoft 365, mailbox, cloud, application, and associated evidence sources.
Evidence-Driven Analysis
Findings are developed through collection, preservation, correlation, and validation of available records rather than assumptions about threat-actor activity.
Fraud & Activity Reconstruction
Authentication, mailbox, communication, cloud, and business evidence are correlated to reconstruct relevant activity and timelines.
Support for Leadership & Counsel
Technical findings are communicated clearly to executives, legal counsel, insurers, IT teams, financial stakeholders, and other authorized participants.
BUSINESS EMAIL COMPROMISE FAQ
Practical Questions
After an Email Compromise.
Business email compromise investigations often begin after fraudulent activity has already occurred and important facts remain unknown. These questions address common considerations at the beginning of the response.
What should we do after discovering a compromised email account?
Take reasonable steps to secure the affected account, revoke unauthorized sessions, reset credentials where appropriate, review MFA and persistence mechanisms, and preserve relevant identity, mailbox, cloud, endpoint, and security records. Avoid unnecessary deletion or cleanup of evidence before investigative priorities have been evaluated.
Can you determine how the attacker accessed the email account?
Cyber Centaurs evaluates available evidence concerning phishing, credential compromise, suspicious authentication, session or token activity, malicious applications, password reuse, endpoint compromise, and other potential access mechanisms. Whether a specific initial-access method can be conclusively established depends on the records available.
Can you determine how long the attacker had access?
Authentication records, mailbox activity, cloud logs, security telemetry, endpoint artifacts, and other evidence may help establish the supported timeline of unauthorized activity. Retention periods and missing records can limit how far back the investigation can reliably reconstruct events.
Can you determine which emails the attacker read?
The ability to establish specific message access depends on the email platform, audit configuration, licensing, retention, and available logs. The investigation can evaluate available mailbox and cloud evidence and report what the retained records do and do not support.
Can you identify malicious forwarding or inbox rules?
Yes. BEC investigations commonly examine forwarding rules, inbox rules, redirects, mailbox settings, mail-flow changes, and other configuration activity that may have been used for persistence, monitoring, concealment, or unauthorized message handling.
Can you investigate fraudulent wire or ACH instructions?
Cyber Centaurs can reconstruct relevant email, account, authentication, communication, and timeline evidence associated with fraudulent payment instructions. Banks and law enforcement should also be contacted promptly when financial transfers are involved.
Can a compromised email account create a reportable data breach?
Potentially. The answer depends on the information accessible through the account, what evidence supports concerning unauthorized access, applicable legal or contractual requirements, and other circumstances. Cyber Centaurs provides technical findings; organizations should work with qualified counsel regarding legal notification obligations.
Can you investigate Microsoft 365 business email compromise?
Yes. Depending on available evidence, investigations may include Microsoft 365, Exchange Online, Entra ID, authentication activity, mailbox audit records, forwarding rules, cloud storage, application access, and other relevant sources.
CONFIDENTIAL INQUIRY
Speak With an
Incident Response Investigator.
Tell us briefly about the suspected email compromise, affected accounts, fraudulent activity, and the assistance you need. A member of the Cyber Centaurs team will review your inquiry and follow up directly.
Confidential inquiry. Please do not submit credentials, sensitive emails, financial information, or evidence through this form.
