Business Email Compromise Response
Investigating a compromised mailbox, removing malicious access, and helping recover from any resulting fraud attempt.
Who this is for: Businesses dealing with a compromised mailbox, a fraudulent wire request, or suspicious forwarding rules right now.
The Problem
A compromised mailbox rarely announces itself, it’s usually discovered because a vendor or client calls asking about an email nobody actually sent.
Our Solution
We investigate the mailbox, find and remove malicious forwarding rules and OAuth grants, trace what was actually accessed, and help coordinate recovery from any resulting fraud attempt.
What's included
- Microsoft 365 and Google Workspace compromise investigation
- Malicious forwarding-rule detection and removal
- OAuth grant review and revocation
- Credential-theft investigation
- Financial-fraud investigation and bank coordination
- Email preservation for evidence
See our case study on a business email compromise that almost redirected a $40,000 wire transfer for what this investigation actually involves.
Benefits
- Malicious access removed, not just the visible symptom
- A clear picture of exactly what was accessed
- Coordinated guidance for recovering from an attempted fraud
Our Process
Investigate
Determine how the mailbox was compromised.
Remove Access
Revoke malicious forwarding rules and OAuth grants.
Trace Impact
Determine what was actually accessed or sent.
Recover
Coordinate with your bank if funds were involved.
Harden
Close the gap so it can’t happen again.
Proven results: See the full case study on how this was caught before a $40,000 wire transfer went out. See the write-up →
Frequently asked questions
How do I know if our email has been compromised?
Unexpected forwarding rules, login alerts from unfamiliar locations, or a vendor or client reporting a suspicious email from you are the most common signs.
Can you help if money has already been sent?
We can help investigate and coordinate with your bank and law enforcement quickly, time matters significantly for any chance of recovery.
Especially relevant for
Related services
Incident Response
24/7 breach containment, forensic timeline, and recovery when every minute counts.
fingerprintDigital Forensics
Reconstructing exactly what happened, with evidence handling that holds up for insurers, regulators, and legal proceedings.
gpp_badRansomware Response
Containment, a fact-based pay-or-restore decision, and recovery, for a ransomware incident happening right now.
Not sure if this is the right fit?
Tell us what's worrying you. We'll tell you what actually needs fixing first.