SVC-IR · Incident response & BEC forensics
Business email compromise is the most expensive attack most firms will ever face, and the first hours decide the outcome. Panthryx handles BEC, ransomware, DDoS, and account-takeover incidents end to end: containment first, evidence always, and a clear account of what happened.
How an engagement runs
The compromised account is locked down (password reset, sessions revoked, forwarding rules and delegate access removed) before the attacker can pivot to other mailboxes or intercept another payment conversation.
We reconstruct what happened from the logs the attacker left behind: sign-in records, mailbox rules, OAuth application grants, message traces, and audit events. The result is a timeline covering first access, what was read, what was taken, and what was sent.
Everything is collected and documented to the standard breach counsel and cyber insurers require. If the matter turns into litigation, a claim, or a regulatory notification decision, the evidence holds up.
You get a clear, plain-language account of how the intrusion happened, what was exposed, and what it means, written so someone who wasn't in the room can follow.
The engagement ends with the environment hardened against the vector that was used, and the ones we found open along the way. Many incident clients continue with managed security for active protection against the next attempt.
The same discipline applies when the incident isn't an inbox. We contain and investigate ransomware events and coordinate recovery against your backups and continuity plans. For public-facing platforms, especially SaaS, we provide DDoS guidance: selecting and configuring the right mitigation for your stack and architecting systems designed to weather an attack.
Common questions
Call before you change anything: +1 480-999-0030. Do not wipe the machine, do not delete suspicious emails, and do not announce the breach from the affected account. Reset the account's password and revoke its active sessions if you can do so immediately, then preserve everything else exactly as it is. Our first-hour guide walks through it step by step.
Sometimes, if you move quickly. Contact your bank immediately and request a recall, then file with IC3, the FBI's Internet Crime Complaint Center, whose Recovery Asset Team can freeze funds domestically when notified early. The first 24 to 72 hours decide most outcomes. We help coordinate this alongside the technical investigation.
Yes. That is the standard we write to. Evidence is preserved and documented so someone who was not in the room can follow the reasoning: what happened, when, through which account, and what data was exposed. Cyber insurers and breach counsel routinely require this documentation.
BEC rarely involves malware. The attacker signs in with stolen credentials, reads the mailbox quietly (sometimes for weeks), sets up forwarding rules, and waits for a payment conversation to impersonate. That's why BEC investigation is forensic work on sign-in logs, mailbox rules, and OAuth grants rather than antivirus scans, and why the fix is identity hardening, not software cleanup.
Yes, as advisory work. Panthryx doesn't sell DDoS mitigation. We help you select and configure the right solution for your stack, such as Cloudflare or Akamai, and for SaaS platforms in particular, we help position your systems so an attack degrades service gracefully instead of taking you offline.
Active incident
A compromised account may mean a compromised inbox. Call the incident line and we'll walk you through the first steps: what to disconnect, what to preserve, and what not to touch.