Incident responseMove immediately when money or mailbox access may be compromised.
If a fraudulent transfer may have occurred, contact the financial institution immediately and use established fraud-recovery procedures. The FBI directs victims to report BEC through the Internet Crime Complaint Center. Preserve relevant email, headers, authentication logs, payment records, mailbox rules, application grants, and communications while operational response continues.
For suspected mailbox takeover, contain the identity, revoke sessions and tokens, reset or replace authentication factors as appropriate, review privileged roles and recovery settings, remove malicious rules and forwarding, review delegated access and application consent, and investigate the period before detection for additional fraud or data exposure.
Notify affected vendors and internal stakeholders through trusted contact paths when an attacker may have sent fraudulent instructions from a real account. Correcting the technical compromise does not automatically stop downstream fraud that is already in motion.