Under attack right now? Active incident line — +1 480-999-0030 · Report an incident

Field guide · Incident response

The first hour of a business email compromise.

What to do, in order, and the well-intentioned mistakes that destroy evidence, alert the attacker, or forfeit a wire recall.

You just found out. Maybe a client called about wire instructions your firm never sent, or a vendor asked why you requested a change to their banking details. However it surfaces, you are now in the first hour of a business email compromise. What you do next matters more than anything you'll do in the following month.

If money moved: call your bank before you do anything else on this list. Ask for a wire recall and a fraud notification on the transfer. Then file at ic3.gov. The FBI's Recovery Asset Team can freeze domestic transfers, but their success rate drops by the hour. Everything else below can wait ten minutes; this cannot.

First, understand what you're dealing with

Business email compromise is not a virus. In most cases the attacker simply signed in with stolen credentials and has been quietly reading. In one case we worked, the attacker had been inside the mailbox for six weeks before anyone noticed. They set up inbox rules to hide their tracks, learned who authorized payments, and waited for the right time to send fraudulent emails to hundreds of clients and other contacts.

With BEC, the evidence is in logs and mailbox settings, not on a hard drive, and the attacker may still be watching the mailbox while you're trying to figure out what's going on.

The first hour, in order

1. Contain the account without destroying the scene

  • Verify the account information in case the attacker has registered a new recovery address or multi-factor authentication device
  • Reset the password of the affected account.
  • Revoke all active sessions. A password reset alone does not disconnect an attacker who is already signed in.
  • Disconnect any compromised devices from the network. A disconnected device can no longer leak information, and an attacker can no longer control it.
  • Document and screenshot inbox rules before removing them. Attackers create rules that auto-delete or forward mail; these rules are evidence, and they're often the reason nobody noticed for weeks. Document them, then disable.
  • Contain first, harden later.

2. Preserve, don't clean

The instinct after a break-in is to clean up. With a BEC, cleaning up destroys evidence. Until someone qualified has reviewed and preserved the logs:

  • Do not delete the phishing email, the fraudulent messages, or anything the attacker sent or touched.
  • Do not wipe or reinstall any machine.
  • Do not let anyone check the mailbox: every action writes over the audit trail of what the attacker did.
  • Write down the timeline: who noticed what, when, and what has been done since. Memory degrades quickly under stress.

3. Move sensitive conversations off of email

Until you know which accounts are affected, assume the attacker can read your email. Coordinate the response by phone or another secure channel. Do not announce the breach from the compromised account. You'd be notifying the attacker that they've been discovered, and they may still control other mailboxes.

4. Verify the blast radius, by phone

  • Call (don't email) any client who has received fraudulent communication asking for sensitive information or payment method updates.
  • Contact your bank and ask whether they've received unusual requests recently. Let them know the situation and to monitor your account for unusual activity.

5. Make the calls

  • Your incident responder — someone who can retrieve and interpret Google Workspace and Microsoft 365 sign-in logs, audit records, and OAuth grants. The logs that matter most have retention limits, and every day of delay is evidence lost.
  • Your cyber insurer — most policies require prompt notice, and some require using their approved vendors. Late notice can void coverage.
  • Breach counsel — if client data may have been exposed, notification obligations may start running from discovery.

What not to do: the mistakes we see in real cases

  • Don't wipe the laptop. It feels decisive, but destroys evidence and rarely removes the actual access, which typically lives in the cloud account.
  • Don't just change the password and move on. Without revoking sessions, checking rules, and reviewing OAuth grants, the attacker often keeps access, and now knows you're looking.
  • Don't investigate from inside the compromised account. Use an unaffected admin account, or wait for someone who can.
  • Don't assume it's over because the fraudulent email stopped. Attackers routinely maintain quiet access to multiple accounts and return weeks later.

After the first hour

Containment buys you time, but it doesn't answer the questions that matter: how the attacker got in, how long they were there, what they read, and whether client data was exposed. That takes a forensic timeline built from sign-in logs, audit records, message traces, and OAuth grants, documented to the standard your insurer and counsel will require. That's the work of the days that follow, and it's what our incident response engagement covers, from investigation through the hardening that keeps it from happening again.

Are you dealing with BEC right now? Call the Panthryx incident line: +1 480-999-0030. We'll walk you through the first steps at no charge: what to disconnect, what to preserve, and what not to touch.

Before the next one

The firms that handle this well rehearsed it first.

Most BEC losses are preventable with hardened identity controls and people who recognize the patterns of attackers. That's what our managed security and readiness services are here for.