Business Email Compromise
Investigation

Someone may be reading your email, or your vendor's, and waiting for the next payment.

We find out how they got in, what they saw and which accounts they control, then close every way back in before money moves.

Home Hero Icon
Microsoft 365 and Entra ID investigation
Home Hero Icon
Evidence preserved for your insurer and counsel
Home Hero Icon
Every way back in found and closed
Home Hero Icon
Independent of your IT provider
Inbox, accounts payableILLUSTRATIVE
FromAccounts Receivable <ar@vendor.example>
SubjectUpdated remittance details

Please send this week's payment to our new bank account. The old account is under review, so do not use it.

What the investigation finds
Sent from the vendor's real mailbox, so it passed every email check
An inbox rule hiding replies from your AP team
An MFA method the user never added
Sign-ins from a country the vendor does not work in
Illustrative example, not client data

What business email compromise is

Business email compromise (BEC) is fraud that uses a trusted email conversation to move money. The attacker either takes over a real mailbox, at your company or at a vendor, or impersonates one closely enough to pass a quick look. Then they wait for a payment that is already expected and change where it goes: a vendor invoice, a closing wire, a payroll deposit.

$3.05B
BEC losses reported to the FBI in 2025, up from $2.77B in 2024
24,768
BEC complaints to the FBI's IC3 in 2025, the second-costliest cyber fraud after investment fraud
~$123K
average reported loss per complaint, and many companies never report

The FBI tracks this crime as BEC and email account compromise (EAC). In BEC, the attacker pretends to be someone you trust. In EAC, the attacker is actually signed in to a real mailbox and sends from it, so the email comes from the real address and passes every authentication check. Phishing is usually the way in; BEC is what the attacker does with the access. The FBI counted $55.5 billion in exposed losses from BEC and EAC worldwide between October 2013 and December 2023.

For background, read What is business email compromise? and our business email compromise analysis.

Why BEC Keeps Working

BEC needs no malware and no hacking skill, just a trusted conversation and a payment that was already expected.

These are the most common patterns, and what we look for in each.

Enterprise Hero Icon
MOST COMMON

Vendor Invoice Fraud

Challenges Highlight  Icon
The payment was already expected.
Enterprise Hero Icon

A supplier "updates" its bank details, or a real invoice arrives with new wire instructions. Accounts payable pays it because nothing looks out of place.

We trace where the change came from: your mailbox, the vendor's, or a lookalike domain.

Enterprise Hero Icon
HARDEST TO SPOT

Vendor Email Compromise

Challenges Highlight  Icon
The email really is from your vendor.
Enterprise Hero Icon

The vendor's own mailbox was taken over, so the message passes SPF, DKIM and DMARC and lands inside a real thread.

We establish whose tenant was compromised, so you know what to fix and what to tell your counterparties.

Enterprise Hero Icon
HIGH PRESSURE

Executive Impersonation:
CEO and CFO Fraud

Challenges Highlight  Icon
Urgent, confidential and badly timed.
Enterprise Hero Icon

A request that appears to come from the CEO or CFO, often sent when they are traveling and cannot be reached.

We check whether the executive's real account was used, or only impersonated.

Enterprise Hero Icon
HIGHEST VALUE

Closing and Capital-Call
Wire Fraud

Challenges Highlight  Icon
Large one-off wires are normal here.
Enterprise Hero Icon

Fake wire instructions arrive during an acquisition, a real estate closing or a capital call, when money moves between parties who barely know each other. We find where the instructions were changed and who else received them.

Enterprise Hero Icon
RECURRING

Payroll Diversion:
The Quiet Redirect

Challenges Highlight  Icon
One changed direct deposit, then the next.
Enterprise Hero Icon

An "employee" asks HR or payroll to change their bank account before the next pay run. Each request is small enough to go unnoticed, and the attacker often has the employee's real mailbox.

Enterprise Hero Icon
OFTEN MISSED

The Reset That Changed Nothing

Challenges Highlight  Icon
A password reset is not the end.
Enterprise Hero Icon

Inbox rules, a registered MFA method, a malicious app consent or a rogue device can all survive a reset. The attacker keeps reading, and waits for the next invoice.

How a BEC attack unfolds

Most BEC today starts with a fake sign-in page that defeats standard MFA, then runs quietly for weeks. Every step leaves a record in Microsoft 365, if someone knows where to look.

Step one: the session is stolen, MFA and all
→
Attacker
Relay in the middle
Passes your password and MFA approval to the real sign-in, and keeps the session token it gets back
→
Your tenant
Microsoft 365
Sees a valid sign-in that passed MFA, from the user
1The user enters a password and approves the MFA prompt on the fake page.
2The relay forwards both to the real Microsoft sign-in, which issues a session token.
3The attacker replays the stolen token and is signed in as the user, with no password and no MFA prompt.
Illustration. Phishing-resistant MFA, such as passkeys and security keys, is built to stop this.
Then: from first click to the wire
Day 0
Phish and session theft
A "shared document" link leads to the fake sign-in page. The attacker is in within minutes.
Day 1
Persistence
They register their own MFA method, grant a malicious app access to the mailbox or join a rogue device, so a password reset will not lock them out.
Weeks 1 to 3
Quiet reconnaissance
They read: who approves payments, which vendors are paid when, how invoices are worded. Our dark web scan shows whether your logins are already circulating.
Week 3
Concealment
An inbox rule moves or deletes replies from the vendor, the bank or the finance team, so the real user never sees the warning signs.
Week 4
The ask
An "updated bank details" email lands on a payment that was already going to be made. The wire goes out.
Illustrative timeline. Timing varies by case.

Why your email security, MSP and bank miss it

There is usually no malware and no malicious link in the email that moves the money. It comes from a real account or a convincing lookalike, it passes SPF, DKIM and DMARC checks, and it reads like the dozen invoices before it. Email gateways look for bad attachments and known phishing sites. Banks see an authorized user sending an authorized transfer. Your MSP sees a mailbox working normally. The evidence sits in sign-in records, mailbox rules and audit logs that nobody reviews until someone asks.

How a BEC Investigation Works

We work from the Microsoft 365 and Entra ID records, not from guesses.
Every step preserves evidence first, so what we find holds up with your insurer, your counsel and your bank.

Services Icon

Containment

Stop the next payment first.

What we do

We revoke stolen sessions, lock down compromised accounts, and remove malicious rules, forwarding and rogue devices after they are recorded. Legacy sign-in paths that skip MFA are closed.

why it matters

Until the attacker's access is cut, every pending payment is at risk. Containing it without destroying the evidence keeps the investigation and your claim intact.

typical outcomes
Service Feature Icon

Stolen Session Revocation

Service Feature Icon

Compromised Account Lockdown

Service Feature Icon

Rule and Forwarding Removal

Service Feature Icon

Legacy Sign-In Shutdown

Services Icon

Mailbox & Identity Forensics

Reconstruct exactly what happened.

what we do

We analyze sign-in and audit logs, mailbox rules, MFA registrations, app consents and device joins to establish how the attacker got in, when, and from where.

why it matters

"Someone phished the CFO" is not an answer your insurer or counsel can use. The timeline has to come from the records.

typical outcomes
Service Feature Icon

Sign-In and Session Analysis

Service Feature Icon

MFA and App Consent Review

Service Feature Icon

Mailbox Rule Reconstruction

Service Feature Icon

Rogue Device Detection

Services Icon

Payment & Scope Analysis

Find every thread and account touched.

What we do

We identify which invoice, vendor and payroll conversations the attacker could see, where they inserted themselves, and every mailbox and account involved, at your company or a vendor's.

why it matters

One compromised mailbox rarely means one victim. Knowing the full scope tells you which payments to stop and who else to warn.

typical outcomes
Service Feature Icon

Payment Thread Review

Service Feature Icon

Affected Account Scoping

Service Feature Icon

Vendor vs Internal Attribution

Service Feature Icon

Lookalike Domain Discovery

Services Icon

Evidence & Reporting

Facts your counsel and carrier can rely on.

What we do

We preserve the evidence under forensic chain-of-custody practices and deliver a root cause analysis and an executive report written for leadership, counsel and your insurer.

why it matters

Breach notice decisions, insurance claims and bank recall requests all depend on what the attacker could access. Our report gives counsel the facts to decide.

typical outcomes
Service Feature Icon

Chain-of-Custody Evidence

Service Feature Icon

Root Cause Analysis

Service Feature Icon

Executive Report

Service Feature Icon

Counsel and Carrier Support

Services Icon

Hardening

Close every way back in.

What we do

We put phishing-resistant MFA on compromised and high-risk users, tighten conditional access, restrict app consents, turn off external forwarding and move email authentication toward enforcement.

why it matters

Attackers who get paid once come back. Closing the gaps that let them in is what stops the next attempt.

typical outcomes
Service Feature Icon

Phishing-Resistant MFA

Service Feature Icon

Conditional Access Policies

Service Feature Icon

App Consent Controls

Service Feature Icon

DMARC Enforcement

Services Icon

Payment Controls

Verify the change, not the message.

What we do

We help finance put the controls in writing: a call-back to a number already on file for any new bank details, two-person approval above a set amount, and a vendor master file only a few people can change.

why it matters

Most BEC losses come down to one approval made on the strength of an email. A written process removes that single point of failure.

typical outcomes
Service Feature Icon

Call-Back Verification

Service Feature Icon

Dual Approval Thresholds

Service Feature Icon

Vendor Master File Controls

Service Feature Icon

Finance Team Briefing

Service Feature Icon

Deepfake-Resistant Approvals

Why an Independent Investigator

The team that runs your Microsoft 365 tenant should not be the one grading how it was compromised. We have no stake in the answer.

Enterprise Hero Icon

Independent of Your IT Provider

We report what happened, including what your provider's settings allowed. We work alongside your IT team or MSP, not in place of them.

No Conflict

Of Interest
Enterprise Hero Icon

Evidence Your Insurer Accepts

Evidence is preserved before anything is changed, following forensic chain-of-custody practices, and reports are written so counsel and carriers can rely on them.

Protect Your Claim

From Denials
Enterprise Hero Icon

Every Way Back In, Closed

A password reset is not remediation. We find the rules, MFA methods, app consents and devices an attacker leaves behind, and remove them.

Full Eradication

Not Just a Reset
Enterprise Hero Icon

Microsoft 365 Depth

The same tenant expertise behind our Microsoft 365 and Azure security assessments: Exchange Online, Entra ID, conditional access and audit logs.

Tenant Forensics

Built on Logs
Warning Signs

Signs You May Already
Be Compromised

BEC is built to stay quiet.
The first signs usually show up outside IT: in accounts payable, with a vendor, or at the bank.

If any of these sound familiar, treat it as an active incident until the records say otherwise.

When to Call Us

Do not wait for the next payment cycle.

Contact Cloudskope as soon as you see any of these signs.

01

A Vendor Says It Was Never Paid

Or a customer says they paid an invoice you never sent. The money went somewhere, and the trail starts in someone's mailbox.

02

Bank Details Nobody Changed

Someone received a "new bank details" email from your domain that nobody at your company wrote.

03

Rules Nobody Created

A mailbox has an inbox rule or forwarding address nobody remembers setting up, or emails from a vendor or bank stop arriving.

04

An MFA Method Nobody Added

A new phone number or authenticator app on an account is a classic sign an attacker plans to come back.

05

Sign-Ins From Unexpected Places

Sign-ins from countries, internet providers or devices your company does not use.

Replies arriving to messages that are not in anyone's Sent Items point the same way.

06

The Reset That Did Not Stop It

Your IT team reset a password, and the suspicious activity continued.

That usually means the attacker left another way in.

If a wire already went out

Speed matters more than anything else here. The FBI's guidance is clear: time is of the essence. Do these in order, today.

1Call your bank now. Ask for a recall of the funds and ask them to contact the bank that received the transfer.
2File a complaint at ic3.gov. Report regardless of the amount, with full transaction details. In 2025 the IC3 Recovery Asset Team worked 3,900 incidents and helped freeze about $679 million.
3Verify by phone, not email. Call the real vendor on a number you already have. The attacker may still be reading the thread.
4Preserve the evidence. Do not delete the mailbox, the account, suspicious rules or the emails. Entra ID keeps sign-in and audit logs for only 7 days on free plans and 30 days on P1 or P2.
5Tell your insurer and counsel. Many policies have notice requirements and approved responders. Check before you sign with anyone.
6Get the attacker out. Until every foothold is found, the next payment is at risk too. Request incident support.

How to prevent business email compromise

Verify the change, not the message

Any new or changed bank details, and any unusual payment request, is confirmed by phone to a number you already had on file, never one supplied in the email. Large transfers need a second approver who was not on the call.

Phishing-resistant MFA such as passkeys or security keys for finance, executives and administrators, so a stolen session or a relayed MFA prompt is not enough.

Conditional access that blocks sign-ins from unmanaged devices and unexpected locations, and turns off legacy sign-in methods that skip MFA.

Controls on app consent, so users cannot grant a third-party app access to their mailbox without approval.

External forwarding off by default, with alerts on new inbox rules and forwarding addresses.

DMARC at enforcement plus monitoring for lookalike domains registered against you and your key vendors. Our email security check shows where you stand.

Audit logging on and kept long enough to investigate. Many tenants keep sign-in records for only 7 to 30 days.

AI has made impersonation better. In 2024, an employee at the engineering firm Arup sent about $25 million after a video call in which the CFO and colleagues were deepfakes. A voice or a face on a call is no longer proof. To find out whether these controls are actually on in your tenant, a Microsoft 365 and Azure security assessment checks each one and fixes what is missing.

FAQ

Frequently Asked Questions

Straight answers on passwords, MFA, recovery, reporting and insurance.

1Our IT team already reset the password. Are we done?+

Probably not. A password reset does not remove an inbox rule, a forwarding address, an authenticator app the attacker registered, a malicious app consent or a rogue device registration. It may not end a stolen session either. Each of those is a way back in. An investigation finds and removes all of them, and confirms whether other accounts were involved.

2We have MFA. How did this happen?+

Adversary-in-the-middle phishing defeats standard MFA. The user signs in through a fake page that relays everything to the real Microsoft login, so the user completes the MFA prompt and the attacker keeps the session. Phishing-resistant methods, such as passkeys and security keys, are built to stop this. Learn more about adversary-in-the-middle attacks and session token theft.

3Can we get the money back?+

Sometimes, and the odds are best when you act fast. Call your bank to request a recall and file at ic3.gov right away. Recovery depends on how quickly the receiving bank can freeze the funds and how far they have moved. No investigator can promise recovery. What we can do is make sure the attacker cannot redirect the next payment.

4Was it our mailbox or our vendor's?+

It can be either, or both. When the fraudulent email comes from a vendor's real address, the compromise may sit in their tenant, not yours. When it comes from a lookalike domain, nobody's mailbox may be compromised at all, but someone has studied your payment process. The investigation establishes which, so you know whose environment needs fixing and what to tell your counterparties.

5What is the difference between BEC and phishing?+

Phishing is a method: a message designed to get someone to click, sign in or open something. BEC is a fraud: using a trusted email conversation to redirect money or data. Phishing is often how the attacker gets into the mailbox. The BEC email itself usually contains no link or attachment at all, which is why filters built to catch phishing let it through.

6Is a BEC incident a data breach we have to report?+

It can be. If the compromised mailbox held personal information such as Social Security numbers, account numbers or health details, state breach notification laws may apply, and SEC-registered advisers have customer notice duties under Regulation S-P. Whether notice is required depends on what the attacker could access, which is exactly what the investigation establishes. Your counsel makes the call; we give them the facts.

7Does cyber insurance cover BEC losses?+

Often in part. Many policies cover social engineering or funds transfer fraud, frequently with a lower sublimit than the rest of the policy and conditions such as call-back verification. Some exclude it. Read the policy, notify the carrier early, and check whether it requires you to use an approved responder before you engage anyone.

8Will you work with our insurer, lawyer and MSP?+

Yes. We frequently partner with breach coaches, outside legal counsel and cyber insurance carriers, and we work alongside internal IT teams and MSPs. Our reports are written so counsel and your carrier can rely on them.

Do Not Wait for the Next Payment

If a mailbox, a vendor thread or a payment looks wrong, the attacker may still be inside.

Request incident support or call +1 (214) 617-2080.