
A business email compromise response starts within minutes, not days: contact your bank to request a wire recall before touching anything else if funds moved, then preserve the compromised mailbox without resetting the password, isolate the account, and bring in a forensic investigator and counsel in parallel. The single biggest determinant of whether stolen funds are ever recovered is elapsed time between the fraudulent transfer and the bank’s recall request — every hour that passes narrows the window.
Business email compromise rarely announces itself clearly. It surfaces as a vendor calling to ask why an invoice went unpaid, a controller noticing a wire went to an account that doesn’t match the usual payee, or an employee mentioning they “confirmed” a payment change over email that the CFO never sent. By the time anyone recognizes what happened, the clock has already been running. This guide is a response playbook — what to do in the first hours and days, who needs to be involved, how wire recovery actually works, and how to prevent a repeat — written for the executive, controller, or IT lead who just discovered a BEC incident and needs to act now, not read a technical forensics manual first.
What is business email compromise, and why does response speed matter this much?
Business email compromise is a fraud scheme where an attacker compromises or convincingly spoofs a business email account, then uses that access or impersonation to redirect a payment, request a fraudulent wire, or manipulate an employee into an unauthorized transaction — typically by impersonating an executive, a vendor, or a known business partner in an otherwise ordinary-looking email thread. The FBI’s Internet Crime Complaint Center tracks BEC as one of the most financially damaging categories of cybercrime it receives complaints about, precisely because a single successful attempt can move a large sum in one transaction.
Speed matters because wire transfers move through a banking system with brief, real windows for interception. Once funds land in the receiving account and are withdrawn or layered through additional transfers, recovery odds drop sharply and continue dropping by the hour. Every part of the response below is sequenced around that reality: the fastest possible actions come first, even before the full picture of what happened is understood.
What are the first actions in the opening hours of a suspected BEC?
Work through these in order. Do not wait to complete a full investigation before starting the recovery and containment steps — they run in parallel with, not after, figuring out exactly what happened.
- If money moved, call your bank immediately. Ask for an emergency wire recall or reversal and, if available, a Hold Harmless Letter or Letter of Indemnity to support it. This is the single highest-leverage action available and it is time-critical.
- File a complaint with the FBI’s Internet Crime Complaint Center (IC3) the same day. A prompt, detailed IC3 report can support the financial fraud kill chain process that flags a fraudulent wire for interception at the receiving institution.
- Do not reset the compromised account’s password yet. Isolate it — disable sign-in or force a session lockout through your email admin console if possible — but preserve the account state so a forensic investigator can capture mailbox rules, sign-in logs, and connected application grants before anything changes.
- Identify and notify everyone who touched the fraudulent request. Accounts payable, the employee who processed the transfer, and anyone copied on the thread, so they stop any related in-flight actions (a second, follow-up wire is a common second stage).
- Engage a digital forensics team. To determine how the account was accessed, whether mailbox rules or forwarding were added, whether other accounts are affected, and to build a defensible record for the bank, insurer, and any resulting legal process.
- Loop in legal counsel early, not after the technical picture is complete, so notification obligations and privilege considerations are assessed from the start rather than retrofitted later.
- Notify your cyber-insurance carrier, if you carry a policy, as soon as you have a credible incident — most policies require prompt notice and specify approved forensic and legal vendors, and using an unapproved vendor first can complicate reimbursement.
- Reset credentials and revoke sessions and tokens only after evidence preservation is confirmed, then enforce multi-factor authentication on the affected account and any account that shares a password with it.

How does wire recovery actually work, and how much does time matter?
When a fraudulent wire is reported quickly, the originating bank can request that the receiving bank place a hold on the funds before they are withdrawn — this coordinated process is sometimes referred to as the financial fraud kill chain. It depends entirely on speed and on both banks’ internal processes; it is not automatic and it is not guaranteed. The table below describes, qualitatively, how the realistic outlook shifts as time passes — treat it as a planning framework, not a statistical guarantee, since actual recovery depends on the receiving bank, the destination account’s status, and how quickly the funds were moved onward.
| Time since fraudulent transfer | Realistic outlook | What to prioritize |
|---|---|---|
| Same business day | Best realistic chance of a hold before withdrawal | Bank call and IC3 report immediately, in parallel, without waiting for a full internal investigation |
| Within 24-48 hours | Still meaningfully worth pursuing, odds falling as funds may have moved through additional accounts | Same actions, plus start documenting the incident for insurance and legal review |
| Beyond 72 hours | Recovery becomes considerably less likely as funds are typically dispersed or withdrawn | Still file the report and pursue recovery channels, but shift primary focus to containment, forensics, and preventing repeat loss |
The practical lesson is not to wait for certainty. Businesses regularly lose recoverable time deliberating internally about whether the transfer was “really” fraudulent before calling the bank. Report it as soon as it looks wrong; a false alarm costs a phone call, while a delayed real one costs the money.
Who needs to be involved in the response, and who owns what?
A BEC incident cuts across departments that don’t normally coordinate under time pressure, and assigning ownership in advance — ideally before an incident, in a written plan — prevents the confusion that costs the most time. At minimum, a response needs: a financial lead (controller or CFO) to manage the bank relationship and recall request; an IT/security lead to isolate the account and coordinate with the forensic investigator; legal counsel to assess notification obligations and manage privilege; an executive sponsor with authority to approve urgent decisions like engaging outside forensics on short notice; and a single point of contact who talks to the insurance carrier so the claim narrative stays consistent. Smaller businesses without a full bench for each role should still name a single incident owner who pulls in outside counsel and a forensic firm rather than trying to run all of this internally.
Do you have a legal obligation to notify customers, employees, or regulators?
Whether a BEC incident triggers a legal notification requirement depends on what data was actually exposed (customer records, employee PII, protected health or financial information) and which state, federal, or contractual breach-notification rules apply to your business and the data involved — a BEC that only resulted in a fraudulent wire, with no downstream data exposure, may not trigger the same obligations as one where an attacker had mailbox access to sensitive customer records. This determination should be made by counsel reviewing the specific facts, not assumed either way internally; this is general information, not legal advice, and getting the notification timeline wrong carries its own regulatory exposure.
How do you work effectively with your cyber-insurance carrier?
Notify the carrier as soon as you have a credible incident, not after your internal investigation concludes — late notice is a common reason for disputed claims. Ask early whether your policy requires using a panel-approved forensic or legal vendor; engaging your own preferred provider before checking this can create reimbursement friction later, even if the work itself is excellent. Keep a clean, time-stamped record of every action taken from the moment of discovery: who was notified, when the bank was called, when IC3 was filed, and what the forensic team found, since claims adjusters and underwriters will ask for exactly this timeline. Loss of business income, forensic costs, and the fraudulent transfer itself may be covered under different parts of a policy, so have counsel or your broker walk through what’s actually claimable rather than assuming.
When do you need a forensic investigator versus handling it internally?
Bring in a forensic investigator whenever a wire transfer was involved, when the compromised account had access to other sensitive systems or data, when you need a defensible record for insurance or potential litigation, or when you simply don’t have in-house expertise to determine how the account was accessed and whether the exposure is contained. A forensic investigation answers questions an internal password reset cannot: whether mailbox forwarding rules or malicious OAuth application grants were added, whether the attacker still has a foothold elsewhere in your environment, and how the initial access actually happened, so the same vulnerability isn’t exploited again next month.
What records should you keep as the incident unfolds?
Start a written incident log the moment you suspect a BEC and keep it current in real time, not reconstructed afterward from memory. Record the exact time the fraud was discovered and by whom, every call made to the bank with names and reference numbers, the time the IC3 report was filed and its confirmation number, every internal notification and to whom, and every action the forensic team takes with a timestamp. This log becomes the backbone of three separate downstream needs at once: the insurance claim, any law-enforcement follow-up, and a legal record if litigation with a vendor, bank, or counterparty ever results. Businesses that skip this step in the chaos of the first day routinely struggle later to reconstruct a clean timeline, which weakens both the insurance claim and any recovery effort. Assign one person, typically the incident owner, to keep this log current rather than leaving it to whoever remembers at the end of the week.
How do you prevent the next business email compromise?
The controls that stop most BEC attempts are procedural as much as technical, and none of them are exotic:
- Dual control on wire transfers and vendor banking-detail changes — require a second employee’s independent sign-off above a defined dollar threshold.
- Verbal callback verification for any request to change payment or banking details, placed to a known phone number on file, never one provided in the email itself.
- Phishing-resistant multi-factor authentication on every email and financial-system account, with hardware security keys prioritized for finance and executive accounts.
- Domain and email-authentication hardening — DMARC, SPF, and DKIM configured and enforced, to reduce look-alike domain spoofing.
- Regular, realistic phishing simulation targeted at finance and executive-adjacent staff specifically, not just a generic annual training module.
- A written, rehearsed BEC response plan naming the roles above, tested at least annually so the first real incident isn’t also the first time anyone has walked through the steps.
What if the BEC targeted an employee instead of a wire transfer?
Not every BEC incident involves money moving. Some attacks use a compromised or spoofed executive account to request gift cards, redirect payroll direct-deposit details, or extract sensitive employee data such as W-2 forms during tax season. The response principles are the same — isolate without destroying evidence, preserve logs, involve legal counsel to assess notification obligations — but the urgency shifts slightly: payroll redirection fraud still has a narrow window to intercept the next pay cycle before funds land in the attacker’s account, so contact your payroll provider immediately alongside the other steps. A tax-data exposure incident carries its own notification considerations distinct from a financial-fraud incident, since the affected individuals are your own employees rather than an external vendor or bank, which is exactly the kind of nuance counsel should weigh in on early rather than after the fact.
Frequently asked questions
Direct answers to the questions that come up most in the first calls after a suspected BEC incident.
About Honeybadger Solutions
Honeybadger Solutions is an Arizona-licensed security and investigations firm providing in-house digital forensics, cybersecurity, and financial investigation response to businesses nationwide and internationally. When a business email compromise hits, our team moves in parallel on containment, forensic evidence preservation, and financial-fraud reporting under one accountable command, coordinating directly with your bank, counsel, and insurance carrier instead of leaving you to manage each relationship alone.
Offices: Casa Grande (HQ), Phoenix, and Oro Valley, Arizona.
Phone: 602-725-2818
24/7 incident response: call immediately if you suspect a fraudulent wire or compromised account.