
Case Study · Business Services
Business Email Compromise Fraud at a Services Firm
- 1 mailboxCompromised and used for the fraud
- ~4 weeksInvestigation and controls remediation
- 2 controlsOut-of-band verification made mandatory
The challenge
A services firm paid what looked like a routine invoice from a regular supplier, to updated bank details. The details were fraudulent: an attacker had access to a mailbox and had watched the exchange for weeks before stepping in.
Management needed to understand how it had happened, whether other payments were at risk and what data had been exposed — without turning the episode into an internal blame exercise.
The integrity of the evidence mattered too: the same logs and messages needed to reconstruct events might later support a recovery action, a regulator notification or a dispute. Handling them rigorously from the outset meant not regretting it afterwards.
My approach
I reconstructed the mailbox access from authentication logs and mail rules, surfaced the hidden rules the attacker used to intercept and divert the relevant messages, and scoped the compromise window precisely.
The investigation exposed the real weak point: changing a supplier’s bank details required no independent verification. I introduced mandatory out-of-band verification and dual approval for master-data changes and above-threshold payments.
On detection, I enabled alerting on anomalous mail rules and improbable sign-ins, and distilled the episode into a management note with the immediate actions towards bank and insurer.
