24/7 INCIDENT RESPONSE
(877) 259-0509

BUSINESS EMAIL COMPROMISE & EMAIL ACCOUNT INVESTIGATIONS

Business Email Compromise
Built on Evidence.

Cyber Centaurs investigates business email compromise and suspected email-account intrusions to determine how unauthorized access occurred, reconstruct account and mailbox activity, identify persistence or forwarding mechanisms, evaluate potential data exposure, and develop defensible findings for organizations and counsel.

WHEN TO ENGAGE

When Email Activity
No Longer Makes Sense.

Business email compromise often becomes visible only after fraudulent messages, payment instructions, unusual authentication, or unexpected mailbox behavior is discovered. Investigation can help reconstruct the activity that occurred before and after the compromise became apparent.

Suspicious or Unauthorized Logins

Fraudulent Payment Instructions

Unexpected Inbox or Forwarding Rules

Messages Sent Without User Knowledge

MFA or Authentication Anomalies

Suspected Email or Cloud Data Access

RESPONSE OBJECTIVES

Secure the Account.
Preserve the Record.

A business email compromise response should reduce ongoing unauthorized access while preserving the identity, mailbox, cloud, endpoint, and security evidence needed to understand what occurred.

Contain Access

Support actions to revoke unauthorized sessions, address compromised credentials, review persistence, and reduce continued threat-actor access.

Preserve Evidence

Protect authentication records, mailbox audit data, email content, cloud activity, endpoint evidence, security telemetry, and other relevant sources.

Reconstruct Activity

Develop a timeline of unauthorized access, mailbox changes, message activity, persistence mechanisms, cloud access, and related threat-actor actions.

Establish Impact

Determine the supported scope of affected accounts, communications, sensitive information, fraudulent activity, and potential data exposure.

BEC INVESTIGATION EVIDENCE

Evidence Across Identity,
Email & Cloud.

Business email compromise investigations often require evidence from identity systems, mailbox records, cloud applications, endpoints, security tools, and business communications. Correlating those sources can help distinguish legitimate user activity from unauthorized access. Related response work may involve data breach investigation and incident response.

Identity & Authentication

sign-in activity

IP information

MFA events

session activity

conditional access

identity-provider records

Mailbox Activity

mailbox audit records

message activity

folder activity

deleted items

mailbox access

Inbox & Forwarding Rules

inbox rules

forwarding

redirects

hidden rules

mail-flow changes

persistence indicators

Email & Communications

message headers

sent messages

attachments

fraudulent threads

impersonation activity

communications history

Cloud & Applications

Microsoft 365

Entra ID

OAuth applications

OneDrive

SharePoint

other cloud activity

Endpoint & Security Evidence

browser artifacts

credential activity

endpoint logs

EDR / XDR

phishing artifacts

INVESTIGATIVE QUESTIONS

What Did the Threat Actor
Do With the Account?

A compromised mailbox is only one part of the incident. The investigation should establish how unauthorized access developed, what actions occurred within the account, what information may have been exposed, and whether access extended into other systems or cloud resources.

How Did Unauthorized Access Occur?

Evaluate available evidence concerning phishing, credential compromise, session or token theft, malicious applications, password reuse, or other potential access mechanisms.

When Did the Compromise Begin?

Correlate authentication, mailbox, cloud, endpoint, and security activity to establish the supported timeline of unauthorized access.

What Mailbox Changes Were Made?

Identify forwarding rules, inbox rules, redirects, deleted messages, mailbox configuration changes, or other activity associated with persistence or concealment.

What Messages or Data Were Accessed?

Evaluate available evidence concerning mailbox activity, attachments, cloud storage, sensitive communications, and other information potentially exposed through the compromised identity.

Were Fraudulent Communications Sent?

Reconstruct message activity associated with impersonation, payment instructions, vendor fraud, altered threads, or other unauthorized communications.

Did the Compromise Extend Beyond Email?

Evaluate evidence of cloud-resource access, connected applications, additional account compromise, endpoint activity, or other systems associated with the affected identity.

BEC INVESTIGATION PROCESS

Reconstruct the Access.
Establish the Impact.

The investigative process is structured to secure the affected identity, preserve available evidence, reconstruct unauthorized activity, determine scope, and communicate supported findings clearly.

01

Triage & Secure

Identify affected accounts, understand actions already taken, assess current access, and support immediate containment priorities.

02

Preserve & Collect

Collect relevant identity, mailbox, cloud, endpoint, security, and communication evidence before retention or remediation changes the available record.

03

Analyze Account Activity

Examine authentication, sessions, mailbox activity, forwarding rules, communications, cloud access, and other evidence associated with unauthorized use.

04

Correlate & Determine Scope

Develop timelines, identify affected accounts and resources, evaluate fraudulent activity and potential data exposure, and distinguish confirmed findings from unresolved questions.

05

Report & Advise

Document supported findings, evidentiary limitations, impact, and recommendations relevant to remediation, recovery, counsel, leadership, insurers, or other authorized stakeholders.

FRAUDULENT COMMUNICATIONS

Reconstruct the Messages
Behind the Fraud.

BEC incidents frequently involve more than unauthorized access. Threat actors may monitor legitimate conversations, impersonate employees or vendors, manipulate payment instructions, or use compromised accounts to make fraudulent communications appear authentic.

Executive Impersonation

Unauthorized messages sent as executives or other trusted employees.

Vendor Impersonation

Fraudulent communications involving suppliers, customers, partners, or other business relationships.

Payment Instruction Changes

Altered banking details, invoices, wire instructions, ACH information, or payment requests.

Thread Hijacking

Use of legitimate email conversations to insert fraudulent instructions into existing business communications.

Mailbox Monitoring

Evidence that a threat actor may have observed communications before acting or selecting a fraudulent opportunity.

Fraud Timeline

Correlation of unauthorized access, communications, payment activity, and other evidence to reconstruct relevant events.

BREACH IMPACT

Beyond the Fraudulent
Email.

A business email compromise can expose more than payment information. Depending on the affected account, unauthorized access may involve sensitive communications, attachments, personal information, cloud files, business records, or other confidential data.

Mailbox Exposure

Evaluate the available record for evidence concerning unauthorized mailbox access and activity.

Attachments & Sensitive Communications

Identify relevant messages, attachments, and information sources implicated by the investigation where evidence permits.

Cloud-Connected Data

Assess associated OneDrive, SharePoint, applications, or other cloud resources accessible through the compromised identity.

Supported Scope

Document confirmed findings, potential exposure, evidentiary limitations, and questions that cannot be resolved from available records.

WHY CYBER CENTAURS

Technical Depth.
Investigative Judgment.

A compromised mailbox leaves evidence across more than email.

Cyber Centaurs combines incident response, digital forensics, identity investigation, and cloud-forensic expertise to reconstruct business email compromise activity and provide organizations and counsel with findings grounded in the available technical record.

Identity & Cloud Investigation

Technical analysis across authentication, Microsoft 365, mailbox, cloud, application, and associated evidence sources.

Evidence-Driven Analysis

Findings are developed through collection, preservation, correlation, and validation of available records rather than assumptions about threat-actor activity.

Fraud & Activity Reconstruction

Authentication, mailbox, communication, cloud, and business evidence are correlated to reconstruct relevant activity and timelines.

Support for Leadership & Counsel

Technical findings are communicated clearly to executives, legal counsel, insurers, IT teams, financial stakeholders, and other authorized participants.

BUSINESS EMAIL COMPROMISE FAQ

Practical Questions
After an Email Compromise.

Business email compromise investigations often begin after fraudulent activity has already occurred and important facts remain unknown. These questions address common considerations at the beginning of the response.

What should we do after discovering a compromised email account?

Take reasonable steps to secure the affected account, revoke unauthorized sessions, reset credentials where appropriate, review MFA and persistence mechanisms, and preserve relevant identity, mailbox, cloud, endpoint, and security records. Avoid unnecessary deletion or cleanup of evidence before investigative priorities have been evaluated.

Can you determine how the attacker accessed the email account?

Cyber Centaurs evaluates available evidence concerning phishing, credential compromise, suspicious authentication, session or token activity, malicious applications, password reuse, endpoint compromise, and other potential access mechanisms. Whether a specific initial-access method can be conclusively established depends on the records available.

Can you determine how long the attacker had access?

Authentication records, mailbox activity, cloud logs, security telemetry, endpoint artifacts, and other evidence may help establish the supported timeline of unauthorized activity. Retention periods and missing records can limit how far back the investigation can reliably reconstruct events.

Can you determine which emails the attacker read?

The ability to establish specific message access depends on the email platform, audit configuration, licensing, retention, and available logs. The investigation can evaluate available mailbox and cloud evidence and report what the retained records do and do not support.

Can you identify malicious forwarding or inbox rules?

Yes. BEC investigations commonly examine forwarding rules, inbox rules, redirects, mailbox settings, mail-flow changes, and other configuration activity that may have been used for persistence, monitoring, concealment, or unauthorized message handling.

Can you investigate fraudulent wire or ACH instructions?

Cyber Centaurs can reconstruct relevant email, account, authentication, communication, and timeline evidence associated with fraudulent payment instructions. Banks and law enforcement should also be contacted promptly when financial transfers are involved.

Can a compromised email account create a reportable data breach?

Potentially. The answer depends on the information accessible through the account, what evidence supports concerning unauthorized access, applicable legal or contractual requirements, and other circumstances. Cyber Centaurs provides technical findings; organizations should work with qualified counsel regarding legal notification obligations.

Can you investigate Microsoft 365 business email compromise?

Yes. Depending on available evidence, investigations may include Microsoft 365, Exchange Online, Entra ID, authentication activity, mailbox audit records, forwarding rules, cloud storage, application access, and other relevant sources.

CONFIDENTIAL INQUIRY

Speak With an
Incident Response Investigator.

Tell us briefly about the suspected email compromise, affected accounts, fraudulent activity, and the assistance you need. A member of the Cyber Centaurs team will review your inquiry and follow up directly.

Confidential inquiry. Please do not submit credentials, sensitive emails, financial information, or evidence through this form.

ACTIVE EMAIL COMPROMISE

(877) 259-0509

24/7 Incident Response