Act quickly but preserve evidence

Contact the relevant bank immediately when funds may have been diverted. At the same time, avoid deleting suspicious emails, resetting affected devices or removing account data before preservation steps are considered.

Secure the account carefully

Change credentials from a known-clean device, revoke active sessions, review forwarding rules and recovery details, and enable multi-factor authentication. Record the actions taken and their times.

Preserve native email evidence

Save suspicious emails in a native format such as MSG or EML where possible. Forwarded copies and screenshots may omit headers and technical routing information needed for analysis.

Identify the affected systems

Determine which mailboxes, computers, phones, cloud services and financial processes were involved. Preserve logs and audit records before retention periods expire.

Examine both technical and procedural causes

Business email compromise may involve stolen credentials, malicious forwarding rules, compromised endpoints, impersonation or manipulation of payment procedures. The investigation should consider both the technical intrusion and the transaction workflow.

Important: This guidance is general. The correct preservation method depends on the device, system, legal authority and circumstances of the matter.