Business email compromise generated more than $2.9 billion in reported losses in the United States alone in 2025 according to the FBI’s Internet Crime Complaint Center. The actual figure is estimated to be several times higher because most incidents go unreported. What makes BEC particularly destructive is not the sophistication of the attack. It is the speed at which money moves and the narrowness of the window in which it can be recovered.
When an employee suspects their email account has been accessed by someone else or when a fraudulent payment instruction is discovered, the decisions made in the first 24 hours determine whether the money is recoverable and whether the breach is contained or expands into a broader network compromise. Most organisations get this wrong.
The 24-Hour Response: What to Do and When
| Hour | Action | Who Acts | Why It Cannot Wait |
| 0 to 1 | Isolate the compromised account without deleting anything | IT or security team | Deleting evidence violates forensic integrity and may breach legal hold obligations |
| 0 to 1 | Contact your bank’s fraud line to attempt a wire recall | Finance director or CFO | Wire recall success rate drops from 40% to under 8% after 4 hours |
| 1 to 2 | Preserve all email headers and message content via export | IT or security team | Email logs are typically overwritten after 30 to 90 days |
| 1 to 3 | Identify all emails sent from the compromised account in the past 30 days | IT or security team | Attackers often use the account to send phishing emails to your contacts |
| 2 to 4 | Notify your cyber insurance provider | Risk manager or legal | Most policies require notification within a defined window or coverage is reduced |
| 2 to 6 | File a complaint with the FBI IC3 portal and local law enforcement | Legal or compliance | Creates official record needed for insurance claims and wire recall assistance |
| 4 to 12 | Audit all email forwarding rules and connected third party applications | IT or security team | Attackers frequently set forwarding rules to maintain access after password reset |
| 12 to 24 | Notify vendors and clients who may have received fraudulent instructions | Senior leadership | Third party liability can exceed the direct loss if recipients acted on fraudulent emails |
Table 1: Correct 24-hour BEC incident response sequence with responsible parties and timing rationale
The Step Most Organisations Skip
The most commonly missed step is the audit of email forwarding rules at hours four to twelve. When an attacker accesses a business email account their first action is usually not to send a fraudulent invoice. It is to set a silent forwarding rule that copies all incoming mail to an external address. This means that resetting the password does not end the attacker’s access. They continue receiving forwarded email for weeks or months after the apparent remediation.
In a significant percentage of investigated BEC cases the attacker had been reading incoming mail for an average of 62 days before sending the fraudulent payment instruction. They used that period to understand the organisation’s financial processes, the names of key decision makers and the language patterns used in legitimate payment requests.
How Attackers Get In: The Three Most Common Entry Points
The most common entry point in 2025 was credential stuffing using passwords exposed in unrelated data breaches. Most people reuse passwords across personal and business accounts. When a personal account is breached in an unrelated incident the password is tested against corporate email systems automatically within hours by credential stuffing tools.
The second most common entry point was phishing: specifically highly targeted spear-phishing emails that impersonated IT departments requesting password reconfirmation. These emails have become increasingly difficult to distinguish from legitimate IT communications because attackers use the organisation’s own branding, real employee names in the sender field and correct internal terminology.
The third entry point, growing in frequency, is OAuth application abuse. An employee is tricked into granting a malicious third-party application access to their email account via a legitimate-looking OAuth permission request. The application receives a persistent access token that survives password resets and MFA changes because it operates at the application layer rather than the authentication layer.
After the First 24 Hours
Once the immediate response steps are complete the focus shifts to scope determination. How many accounts were accessed? Were any other accounts compromised through phishing emails sent from the initial compromised account? Were any file shares, cloud storage systems or financial platforms accessed using the compromised credentials? The answers to these questions determine whether you are dealing with a contained single-account incident or the early stage of a broader network intrusion. In approximately 30% of investigated BEC cases what appeared to be a single account compromise turned out to be the visible portion of a more extensive access event that had been in progress for months.

Leave a Reply