Seven Things to Do in the First 24 Hours After You Suspect Your Business Email Has Been Compromised

Business email compromise generated more than $2.9 billion in reported losses in the United States alone in 2025 according to the FBI’s Internet Crime Complaint Center. The actual figure is estimated to be several times higher because most incidents go unreported. What makes BEC particularly destructive is not the sophistication of the attack. It is the speed at which money moves and the narrowness of the window in which it can be recovered.

When an employee suspects their email account has been accessed by someone else or when a fraudulent payment instruction is discovered, the decisions made in the first 24 hours determine whether the money is recoverable and whether the breach is contained or expands into a broader network compromise. Most organisations get this wrong.

The 24-Hour Response: What to Do and When

HourActionWho ActsWhy It Cannot Wait
0 to 1Isolate the compromised account without deleting anythingIT or security teamDeleting evidence violates forensic integrity and may breach legal hold obligations
0 to 1Contact your bank’s fraud line to attempt a wire recallFinance director or CFOWire recall success rate drops from 40% to under 8% after 4 hours
1 to 2Preserve all email headers and message content via exportIT or security teamEmail logs are typically overwritten after 30 to 90 days
1 to 3Identify all emails sent from the compromised account in the past 30 daysIT or security teamAttackers often use the account to send phishing emails to your contacts
2 to 4Notify your cyber insurance providerRisk manager or legalMost policies require notification within a defined window or coverage is reduced
2 to 6File a complaint with the FBI IC3 portal and local law enforcementLegal or complianceCreates official record needed for insurance claims and wire recall assistance
4 to 12Audit all email forwarding rules and connected third party applicationsIT or security teamAttackers frequently set forwarding rules to maintain access after password reset
12 to 24Notify vendors and clients who may have received fraudulent instructionsSenior leadershipThird party liability can exceed the direct loss if recipients acted on fraudulent emails

Table 1: Correct 24-hour BEC incident response sequence with responsible parties and timing rationale

The Step Most Organisations Skip

The most commonly missed step is the audit of email forwarding rules at hours four to twelve. When an attacker accesses a business email account their first action is usually not to send a fraudulent invoice. It is to set a silent forwarding rule that copies all incoming mail to an external address. This means that resetting the password does not end the attacker’s access. They continue receiving forwarded email for weeks or months after the apparent remediation.

In a significant percentage of investigated BEC cases the attacker had been reading incoming mail for an average of 62 days before sending the fraudulent payment instruction. They used that period to understand the organisation’s financial processes, the names of key decision makers and the language patterns used in legitimate payment requests.

How Attackers Get In: The Three Most Common Entry Points

The most common entry point in 2025 was credential stuffing using passwords exposed in unrelated data breaches. Most people reuse passwords across personal and business accounts. When a personal account is breached in an unrelated incident the password is tested against corporate email systems automatically within hours by credential stuffing tools.

The second most common entry point was phishing: specifically highly targeted spear-phishing emails that impersonated IT departments requesting password reconfirmation. These emails have become increasingly difficult to distinguish from legitimate IT communications because attackers use the organisation’s own branding, real employee names in the sender field and correct internal terminology.

The third entry point, growing in frequency, is OAuth application abuse. An employee is tricked into granting a malicious third-party application access to their email account via a legitimate-looking OAuth permission request. The application receives a persistent access token that survives password resets and MFA changes because it operates at the application layer rather than the authentication layer.

After the First 24 Hours

Once the immediate response steps are complete the focus shifts to scope determination. How many accounts were accessed? Were any other accounts compromised through phishing emails sent from the initial compromised account? Were any file shares, cloud storage systems or financial platforms accessed using the compromised credentials? The answers to these questions determine whether you are dealing with a contained single-account incident or the early stage of a broader network intrusion. In approximately 30% of investigated BEC cases what appeared to be a single account compromise turned out to be the visible portion of a more extensive access event that had been in progress for months.

Leave a Reply

Your email address will not be published.