Act quickly but preserve evidence
Contact the relevant bank immediately when funds may have been diverted. At the same time, avoid deleting suspicious emails, resetting affected devices or removing account data before preservation steps are considered.
Secure the account carefully
Change credentials from a known-clean device, revoke active sessions, review forwarding rules and recovery details, and enable multi-factor authentication. Record the actions taken and their times.
Preserve native email evidence
Save suspicious emails in a native format such as MSG or EML where possible. Forwarded copies and screenshots may omit headers and technical routing information needed for analysis.
Identify the affected systems
Determine which mailboxes, computers, phones, cloud services and financial processes were involved. Preserve logs and audit records before retention periods expire.
Examine both technical and procedural causes
Business email compromise may involve stolen credentials, malicious forwarding rules, compromised endpoints, impersonation or manipulation of payment procedures. The investigation should consider both the technical intrusion and the transaction workflow.
