Most business email compromises aren’t discovered by a security tool. They’re discovered by a phone call: a vendor asking where their payment went, a customer forwarding a strange invoice from your domain, or your bank flagging a wire that doesn’t look right.

That call starts a clock. In a BEC incident, the first 24 hours determine two things: whether you get any of the money back, and whether the attacker gets to keep operating inside your email while you scramble. Here’s how to spend those hours well.

Hour zero: call your bank, not your IT provider

If money has moved — a fraudulent wire, a payment sent to a changed bank account — your first call is to your bank’s fraud department. Ask them to attempt a wire recall. This is the single most time-sensitive action in the entire incident. Funds typically sit briefly in the first receiving account before they’re moved through mule accounts or converted to cryptocurrency, and once that happens recovery odds drop toward zero.

Don’t wait until you understand what happened. Don’t wait for a meeting. The forensics can wait hours; the bank call can’t.

If the payment went out from a vendor or customer’s account because they were fooled by an email that appeared to come from you, tell them to make the same call to their bank, now.

Hour one: file with the FBI’s IC3

File a complaint at ic3.gov. This isn’t a formality — the FBI’s Internet Crime Complaint Center runs a Recovery Asset Team that works with financial institutions to freeze fraudulent transfers, and it’s most effective when complaints arrive within the first 24–72 hours. Include the wire details: amounts, dates, account numbers, and the fraudulent emails that set it up.

Filing early also matters later. Your insurance carrier, your bank, and law enforcement will all ask when you reported it.

Hours two through four: preserve everything

The instinct after discovering a compromise is to clean up — delete the phishing email, purge the fraudulent messages, reset everything, move on. Resist it.

The evidence in that mailbox answers the questions that determine your legal and contractual obligations: how the attacker got in, how long they were there, and what they could see. Delete it and you may end up having to assume the worst — and notify as if everything was exposed.

Concretely:

  • Don’t delete emails, including the phishing message and anything the attacker sent.
  • Don’t wipe or rebuild the affected computer or account.
  • Start a timeline document. Who noticed what, when, and what actions were taken. Write times down as you go — memory gets fuzzy fast.
  • Screenshot what you find — suspicious sign-ins, unfamiliar inbox rules — before touching anything.

Hours four through eight: get the attacker out — properly

Here’s the part most organizations get wrong: they reset the password and declare victory.

A password reset alone often doesn’t evict a modern attacker. If they stole a session token — increasingly the norm — they can keep reading email after the reset. If they registered their own MFA method or authorized a malicious OAuth application, they have persistence that survives any password change. Eviction means, in order:

  1. Reset the password on affected accounts.
  2. Revoke all active sessions so stolen tokens stop working.
  3. Review MFA methods and remove any device or number you don’t recognize.
  4. Audit inbox rules and forwarding. Attackers create rules that hide their activity — auto-deleting replies, forwarding finance emails externally. Remove them, but screenshot first.
  5. Review OAuth app grants and revoke anything unfamiliar.

One more thing: stop discussing the incident in the compromised environment. If the attacker is still reading the inbox, they’re reading your response plan too. Coordinate by phone or text until you’ve verified they’re out.

Hours eight through twenty-four: figure out who else is affected

BEC rarely stays contained to one mailbox. From inside your email, attackers send convincing messages to your vendors and customers — often the same banking-change scam that hit you, now wearing your name.

  • Check the sent items and message trace for emails the attacker sent from your domain.
  • Call — don’t email — any vendor or customer who received fraudulent messages, and warn your finance team that follow-on attempts are common.
  • Verify any recent banking-change requests by phone, using a number you already had on file, not one from the email.

What the first 24 hours can’t answer

By the end of day one, you’ve stopped the bleeding. What you don’t yet know is the scope: how the attacker got in, how long they had access, whether they reached other mailboxes or files, and whether what they saw triggers notification obligations to customers, regulators, or your insurance carrier.

That’s the investigation — sign-in logs, mailbox audit logs, OAuth grants, and an activity timeline with real dwell-time estimates. It’s focused work in Microsoft 365 or Google Workspace, not a six-figure enterprise incident response engagement, and it’s exactly what our BEC incident response service covers: how they got in, what they saw, verified eviction, and hardening so it doesn’t happen twice.

If you’re in the middle of this right now, call us at (608) 448-6075 or email with INCIDENT in the subject line. And if you haven’t been hit yet, the checklist above makes a good tabletop exercise — run it with your finance team before you need it for real.