Business Email Compromise
Investigation
Someone may be reading your email, or your vendor's, and waiting for the next payment.
We find out how they got in, what they saw and which accounts they control, then close every way back in before money moves.
Please send this week's payment to our new bank account. The old account is under review, so do not use it.
$2.2M in wire fraud prevented since May 1, 2026.
None of it flagged first by the client's IT, MSP, bank or security tools. Active compromises were stopped and remediated before a payment left.
What business email compromise is
Business email compromise (BEC) is fraud that uses a trusted email conversation to move money. The attacker either takes over a real mailbox, at your company or at a vendor, or impersonates one closely enough to pass a quick look. Then they wait for a payment that is already expected and change where it goes: a vendor invoice, a closing wire, a payroll deposit.
The FBI tracks this crime as BEC and email account compromise (EAC). In BEC, the attacker pretends to be someone you trust. In EAC, the attacker is actually signed in to a real mailbox and sends from it, so the email comes from the real address and passes every authentication check. Phishing is usually the way in; BEC is what the attacker does with the access. The FBI counted $55.5 billion in exposed losses from BEC and EAC worldwide between October 2013 and December 2023.
For background, read What is business email compromise? and our business email compromise analysis.
Why BEC Keeps Working
BEC needs no malware and no hacking skill, just a trusted conversation and a payment that was already expected.
These are the most common patterns, and what we look for in each.
How a BEC attack unfolds
Most BEC today starts with a fake sign-in page that defeats standard MFA, then runs quietly for weeks. Every step leaves a record in Microsoft 365, if someone knows where to look.
Why your email security, MSP and bank miss it
There is usually no malware and no malicious link in the email that moves the money. It comes from a real account or a convincing lookalike, it passes SPF, DKIM and DMARC checks, and it reads like the dozen invoices before it. Email gateways look for bad attachments and known phishing sites. Banks see an authorized user sending an authorized transfer. Your MSP sees a mailbox working normally. The evidence sits in sign-in records, mailbox rules and audit logs that nobody reviews until someone asks.
How a BEC Investigation Works
We work from the Microsoft 365 and Entra ID records, not from guesses.
Every step preserves evidence first, so what we find holds up with your insurer, your counsel and your bank.
Why an Independent Investigator
The team that runs your Microsoft 365 tenant should not be the one grading how it was compromised. We have no stake in the answer.
Independent of Your IT Provider
We report what happened, including what your provider's settings allowed. We work alongside your IT team or MSP, not in place of them.
Evidence Your Insurer Accepts
Evidence is preserved before anything is changed, following forensic chain-of-custody practices, and reports are written so counsel and carriers can rely on them.
Every Way Back In, Closed
A password reset is not remediation. We find the rules, MFA methods, app consents and devices an attacker leaves behind, and remove them.
Microsoft 365 Depth
The same tenant expertise behind our Microsoft 365 and Azure security assessments: Exchange Online, Entra ID, conditional access and audit logs.
Signs You May Already
Be Compromised
BEC is built to stay quiet.
The first signs usually show up outside IT: in accounts payable, with a vendor, or at the bank.
If any of these sound familiar, treat it as an active incident until the records say otherwise.
When to Call Us
Do not wait for the next payment cycle.
Contact Cloudskope as soon as you see any of these signs.
A Vendor Says It Was Never Paid
Or a customer says they paid an invoice you never sent. The money went somewhere, and the trail starts in someone's mailbox.
Bank Details Nobody Changed
Someone received a "new bank details" email from your domain that nobody at your company wrote.
Rules Nobody Created
A mailbox has an inbox rule or forwarding address nobody remembers setting up, or emails from a vendor or bank stop arriving.
An MFA Method Nobody Added
A new phone number or authenticator app on an account is a classic sign an attacker plans to come back.
Sign-Ins From Unexpected Places
Sign-ins from countries, internet providers or devices your company does not use.
Replies arriving to messages that are not in anyone's Sent Items point the same way.
The Reset That Did Not Stop It
Your IT team reset a password, and the suspicious activity continued.
That usually means the attacker left another way in.
If a wire already went out
Speed matters more than anything else here. The FBI's guidance is clear: time is of the essence. Do these in order, today.
How to prevent business email compromise
Verify the change, not the message
Any new or changed bank details, and any unusual payment request, is confirmed by phone to a number you already had on file, never one supplied in the email. Large transfers need a second approver who was not on the call.
Phishing-resistant MFA such as passkeys or security keys for finance, executives and administrators, so a stolen session or a relayed MFA prompt is not enough.
Conditional access that blocks sign-ins from unmanaged devices and unexpected locations, and turns off legacy sign-in methods that skip MFA.
Controls on app consent, so users cannot grant a third-party app access to their mailbox without approval.
External forwarding off by default, with alerts on new inbox rules and forwarding addresses.
DMARC at enforcement plus monitoring for lookalike domains registered against you and your key vendors. Our email security check shows where you stand.
Audit logging on and kept long enough to investigate. Many tenants keep sign-in records for only 7 to 30 days.
AI has made impersonation better. In 2024, an employee at the engineering firm Arup sent about $25 million after a video call in which the CFO and colleagues were deepfakes. A voice or a face on a call is no longer proof. To find out whether these controls are actually on in your tenant, a Microsoft 365 and Azure security assessment checks each one and fixes what is missing.
Frequently Asked Questions
Straight answers on passwords, MFA, recovery, reporting and insurance.
1Our IT team already reset the password. Are we done?
Probably not. A password reset does not remove an inbox rule, a forwarding address, an authenticator app the attacker registered, a malicious app consent or a rogue device registration. It may not end a stolen session either. Each of those is a way back in. An investigation finds and removes all of them, and confirms whether other accounts were involved.
2We have MFA. How did this happen?
Adversary-in-the-middle phishing defeats standard MFA. The user signs in through a fake page that relays everything to the real Microsoft login, so the user completes the MFA prompt and the attacker keeps the session. Phishing-resistant methods, such as passkeys and security keys, are built to stop this. Learn more about adversary-in-the-middle attacks and session token theft.
3Can we get the money back?
Sometimes, and the odds are best when you act fast. Call your bank to request a recall and file at ic3.gov right away. Recovery depends on how quickly the receiving bank can freeze the funds and how far they have moved. No investigator can promise recovery. What we can do is make sure the attacker cannot redirect the next payment.
4Was it our mailbox or our vendor's?
It can be either, or both. When the fraudulent email comes from a vendor's real address, the compromise may sit in their tenant, not yours. When it comes from a lookalike domain, nobody's mailbox may be compromised at all, but someone has studied your payment process. The investigation establishes which, so you know whose environment needs fixing and what to tell your counterparties.
5What is the difference between BEC and phishing?
Phishing is a method: a message designed to get someone to click, sign in or open something. BEC is a fraud: using a trusted email conversation to redirect money or data. Phishing is often how the attacker gets into the mailbox. The BEC email itself usually contains no link or attachment at all, which is why filters built to catch phishing let it through.
6Is a BEC incident a data breach we have to report?
It can be. If the compromised mailbox held personal information such as Social Security numbers, account numbers or health details, state breach notification laws may apply, and SEC-registered advisers have customer notice duties under Regulation S-P. Whether notice is required depends on what the attacker could access, which is exactly what the investigation establishes. Your counsel makes the call; we give them the facts.
7Does cyber insurance cover BEC losses?
Often in part. Many policies cover social engineering or funds transfer fraud, frequently with a lower sublimit than the rest of the policy and conditions such as call-back verification. Some exclude it. Read the policy, notify the carrier early, and check whether it requires you to use an approved responder before you engage anyone.
8Will you work with our insurer, lawyer and MSP?
Yes. We frequently partner with breach coaches, outside legal counsel and cyber insurance carriers, and we work alongside internal IT teams and MSPs. Our reports are written so counsel and your carrier can rely on them.
Do Not Wait for the Next Payment
If a mailbox, a vendor thread or a payment looks wrong, the attacker may still be inside.
Request incident support or call +1 (214) 617-2080.
.png)