Digital Forensics
Business Email Compromise Investigation and Email Forensics
Find out how the attacker got in, what they read, which rules and apps they planted, and whether they are still there, with evidence your bank, insurer and attorney can use.
When you need a business email compromise investigation
Money just left your account? Before anything else, contact your bank and ask for a recall of the wire, then file a complaint at ic3.gov with the full transaction details. Then use our urgent intake form.
A business email compromise investigation starts the moment someone notices a payment went to the wrong place, a vendor says they never changed their bank details, or a customer asks why your mailbox sent them an invoice they did not expect. The goal is to establish facts: which account was compromised, how, what the attacker saw and sent, and whether access has been fully shut off.
This service sits within our digital forensics services practice and pairs with cyber incident response when the attacker reached beyond email. It also covers email forensics questions that are not BEC at all, such as whether a message was altered, spoofed or really sent from the address it claims.
The scale is real. The FBI’s Internet Crime Complaint Center counted 24,768 business email compromise complaints in its 2025 annual report, with reported losses of about 3.05 billion, the second-highest loss category after investment fraud. The same report defines BEC as a scam aimed at people and businesses that regularly pay suppliers by wire, carried out by compromising email accounts and other channels such as phone numbers and virtual meeting apps.
Wire recall comes first
Forensics does not get money back. Speed with the bank does. The IC3 2025 report says that when you discover a fraudulent transfer, time is of the essence: contact your financial institution immediately and request a recall, and file a complaint at ic3.gov regardless of the amount. The IC3 Recovery Asset Team reported 3,900 Financial Fraud Kill Chain incidents in 2025 with a 58 percent success rate in freezing funds. Report first, preserve the evidence, then start the business email compromise investigation.
What we deliver
Each engagement is scoped in writing. These are the service packages we combine for BEC and email forensics work:
BEC investigation allowance
A fixed block of examiner hours for the initial investigation and containment: sign-in review, inbox rules, forwarding, OAuth app consents and attacker activity. New evidence can expand scope, with your approval.
Email header and metadata analysis
Routing, timestamps, Authentication-Results, message IDs and other properties examined for spoofing, lookalike domains and anomalies. Billed hourly with a short minimum. Header analysis does not prove who typed a message.
Cloud tenant collection setup
One Microsoft 365 or Google Workspace tenant: access validation and an agreed export workflow, charged once per tenant. Custom engineering beyond the agreed setup is quoted.
Mailbox extraction
One Microsoft 365, Google Workspace, Exchange or supported mailbox exported, inventoried and validated, up to a stated volume. Extra volume is quoted.
Findings for bank, insurer and counsel
A plain-language summary of how access was gained, what was exposed, and the timeline, written for the people who need to act on it. Formal expert reports are separate.
Ongoing email security management
After the incident, optional monthly management of mail filtering and routine quarantine administration, priced per mailbox per month.
What a BEC investigation examines
Attackers who get into a mailbox tend to leave the same footprints. The table lists the main sources and what each answers.
| Evidence | Question it answers | Why speed matters |
|---|---|---|
| Sign-in logs | Where and when the attacker signed in, and from what device or IP address | As of October 2026, Microsoft Entra keeps sign-in logs for 7 days on the free tier and 30 days on P1 or P2 |
| Unified audit log | Mail items accessed, rules created, messages sent and deleted | Audit (Standard) records are kept 180 days by default |
| Inbox rules and forwarding | Whether replies are being hidden, moved or forwarded outside | Rules keep working until removed, and users often delete them first |
| OAuth app consents | Whether a malicious app was granted mail or file access | A password reset alone does not cut off an app the user consented to |
| Message headers | Spoofed sender, lookalike domain, or a message that really came from your tenant | Original messages get deleted or forwarded and lose headers |
| Payment thread | Which messages changed the bank details and who received them | Needed for the bank recall and the insurance claim |
Microsoft’s own guidance describes illicit consent grants, where users are tricked into granting a malicious app access, and recommends disabling such an app rather than deleting it so it cannot come back. We check for both rules and consents on every BEC engagement.
How an engagement runs
- Report and request. You contact your bank and IC3, then submit the request online with the affected mailboxes, dates and payment details.
- Preservation. We tell you what not to delete, help you export or extend logs that are about to expire, and confirm scope and billing in writing.
- Tenant access and collection. With an administrator’s authorization, we validate access and collect mailboxes, audit logs and sign-in records using a documented, repeatable workflow.
- Analysis. Sign-ins, rules, forwarding, consents, header analysis and the payment thread are correlated into one timeline.
- Containment checks. We confirm whether the attacker still has a path in and list what must be revoked or reset.
- Findings. A written summary for leadership, the bank, your insurer and counsel, with a formal report or expert testimony if needed.
Authority, consent and legal limits
We investigate only mailboxes and tenants the client controls or has written authority to examine. A tenant administrator or company officer authorizes collection. We do not log in to a vendor’s, customer’s or attacker’s mailbox, and we do not hack back. If the fraud involves another company’s systems, we document what your evidence shows and leave their systems to them and to law enforcement.
Email header analysis shows how a message traveled and what authentication results the receiving server recorded, using fields such as the Authentication-Results header defined in RFC 8601. It can show a message was spoofed or sent through your own tenant. It cannot by itself prove which person typed it. A BEC can also trigger breach notification duties if personal information was exposed. Your attorney decides those questions. This is general information, not legal advice.
How it is priced
- Business email compromise investigation. A fixed block of examiner hours for initial investigation and containment. If new evidence widens the case, we ask before we go past the allowance.
- Header and metadata analysis. Hourly, with a short minimum, for single messages or small sets.
- Collection. A one-time setup per tenant, plus a per-mailbox charge with a stated volume cap. Extra volume is quoted.
- Quoted separately. Software licenses, breach notification support, legal work, formal expert reports, testimony and ongoing email security management.
The main cost drivers are the number of compromised mailboxes, how long the attacker had access, log retention on your licenses and how quickly you need answers. Changes are made by written change order.
Mistakes to avoid after a business email compromise
- Do not wait on the bank. Request the recall and file with IC3 first. The investigation can start in parallel.
- Do not delete the mailbox or the rules. Disable suspicious rules and apps instead, and screenshot them. Deleting removes evidence.
- Do not stop at a password reset. Revoke sessions, review MFA methods and check app consents too.
- Do not forward the fraudulent emails around. Forwarding strips original headers. Preserve the originals in place.
- Do not reply to the attacker. Use a known phone number from your own records to verify any payment change with a vendor.
- Do call your insurer early. Many cyber policies have notice requirements and preferred vendor rules.
Afterward, email authentication with DMARC, SPF and DKIM and identity and access security cut the odds of a repeat.
Who this is for
- Business owners and CFOs
- Law firms
- Title and escrow companies
- Accounting and finance teams
- IT providers and MSPs
- Insurers and breach coaches
Frequently asked questions
What should I do first after a fraudulent wire transfer?
Contact your bank immediately and request a recall of the funds, then file a complaint at ic3.gov with the full transaction details. The FBI’s 2025 IC3 report says time is of the essence. Then preserve the mailbox and request a business email compromise investigation.
Can a BEC investigation get our money back?
No investigation can promise recovery. Recovery depends mainly on how fast the bank and law enforcement act on the recall. Our findings support that process, your insurance claim and any legal action.
How do you know if the attacker still has access?
We review recent sign-ins, active sessions, MFA methods, mailbox rules, forwarding settings and OAuth app consents. Any of these can keep access open after a password change.
Can email header analysis prove who sent a message?
It can show the path a message took, which servers handled it and whether it passed SPF, DKIM and DMARC checks. It can show spoofing or a send from your own tenant. It cannot by itself prove which person wrote it.
How long do Microsoft 365 logs last?
As of October 2026, Microsoft documents 180 days for Audit (Standard) records, and 7 or 30 days for Entra sign-in logs depending on license. That is why preservation should start the same day.
Do you work with Google Workspace too?
Yes. We collect and examine Microsoft 365, Google Workspace, Exchange and other supported mailboxes with the tenant owner’s authorization.
Do we need a lawyer involved?
Often it helps, especially if personal information was exposed or a lawsuit is likely. Counsel can direct the investigation and decide on notification duties. We work with your attorney or on your behalf.
Related guides
- Business email compromise forensics guide
- Business email compromise response guide
- Wire fraud recovery: the first 24 hours
- Corporate email investigation and forensics
- Phishing-resistant MFA and stopping MFA bypass
- Forensic evidence cyber insurers need
- Cyber incident response service
- Microsoft 365 and SaaS security
- Cloud account extraction service
We collect only from tenants and mailboxes the client controls or is authorized to examine, and we never hack back. This is general information, not legal advice.
Sources: FBI IC3 2025 Annual Report, Microsoft app consent playbook, Microsoft: malicious Outlook rules, Microsoft Purview audit retention, Microsoft Entra log retention, RFC 8601.
Get answers before the logs expire
Request this service online and choose business email compromise on the form. It routes straight to our cyber and forensics lead, the specialist who handles these cases, so there is no phone tag and preservation can start the same day. If money just moved or the attacker is still active, use our urgent intake form after you contact your bank.