Credential Phishing and Wire Fraud

Phishing Scams and Business Email CompromiseHow the Fraud Works, and How Examiners Prove What Was Accessed

Business email compromise remains one of the highest loss cyber crimes reported to the FBI, and almost every case begins with a single set of stolen credentials. This page explains the mechanics of modern phishing, the records that prove what an intruder read, and the questions a defensible investigation has to answer.

Updated August 2026 · Reviewed by Elite Digital Forensics examiners · Nationwide breach response

Billions in lossesBusiness email compromise consistently ranks among the costliest crime categories reported to the FBI Internet Crime Complaint Center.
Minutes to hoursTypical interval between credential theft and the first attacker mailbox rule in an adversary in the middle campaign.
Session theftModern phishing kits steal the authenticated session token, which defeats app based multifactor authentication.

Quick answer

Business email compromise is a fraud scheme in which an attacker gains access to a legitimate corporate mailbox, usually through credential phishing or session token theft, then uses that trusted mailbox to redirect payments, harvest data, or reach further into the organization. Forensically it is proven with cloud audit records: sign in logs, mailbox audit entries such as MailItemsAccessed, inbox rule creation, and message trace data. Those records have license dependent retention windows, so preservation should happen immediately.

Common questions, answered in one line

QuestionOne line answer
Does multifactor authentication stop BEC?App and SMS based factors are routinely bypassed by session token theft. Phishing resistant hardware factors are the effective control.
Can we prove which emails the intruder read?Often yes, through mailbox auditing records, but only if the licensing and retention captured them.
How fast do attackers act?Inbox rules and forwarding are commonly created within minutes of the first successful sign in.
Is a password reset enough?No. Stolen session tokens remain valid until sessions are revoked and tokens invalidated.
Does BEC trigger notification duties?Frequently, when the mailbox contained personal, health, or financial information about others.
Can stolen funds be recovered?Sometimes, if the bank and the FBI are engaged within days through the financial fraud kill chain.

Key terms defined

TermWhat it means
Business email compromiseFraud committed through access to, or convincing impersonation of, a legitimate business mailbox.
Adversary in the middleA phishing proxy that relays the victim to the real login page, captures the password, and steals the resulting session cookie.
Session tokenThe credential a browser holds after a successful login. Stealing it allows access without the password or a second factor.
Inbox ruleA mailbox rule that moves, deletes, or forwards messages. Attackers use them to hide replies from the legitimate user.
Message traceThe provider record of messages entering and leaving the tenant, used to show forwarding and outbound fraud attempts.
Thread hijackingReplying inside a real existing conversation so the fraudulent message inherits the trust of the thread.

How a modern business email compromise unfolds

The stereotype of a badly written wire request from an unfamiliar address is long out of date. Contemporary campaigns use functional proxies of the real login page, land inside genuine email threads, and behave carefully enough that the legitimate user notices nothing.

Stage 1

Lure. A link arrives in a shared document notification, an invoice, a voicemail alert, or a reply inside a thread taken from an already compromised partner mailbox.

Stage 2

Credential and token capture. The proxy page shows the authentic provider login, forwards the multifactor prompt to the victim, and captures the resulting session cookie.

Stage 3

Persistence. The attacker registers an additional authentication method, creates inbox rules that hide banking and vendor replies, and may consent an OAuth application for durable access.

Stage 4

Reconnaissance. Searches run against the mailbox for terms like wire, invoice, routing, remittance, and payroll to locate an in progress transaction.

Stage 5

Execution. A payment instruction is altered, an internal request is sent from the trusted account, or the mailbox contents are exported for extortion or resale.

Why the compromise usually spreads

The compromised mailbox itself becomes the next lure. Because messages originate from a genuine authenticated account and continue an existing thread, they pass authentication checks and reader scrutiny alike. Vendors, clients, and internal finance staff are the usual next victims, which is why scoping cannot stop at the first account.

The records that prove what an intruder actually did

A defensible BEC investigation rests on tenant side records, not on what the user remembers. Each record answers a different question, and together they establish access, duration, and reach.

RecordWhat it establishesPreservation note
Sign in logsSuccessful and failed authentications, source address, device, and whether multifactor was satisfiedRetention is license dependent, commonly 7 to 30 days for interactive sign ins unless exported
MailItemsAccessedWhich specific messages were opened or synced by the sessionRequires appropriate licensing and mailbox auditing to be enabled beforehand
Inbox rule and forwarding eventsAttacker created hiding and exfiltration mechanisms with timestampsCaptured in the unified audit log; the rule itself may be deleted by the attacker
Message traceMessages sent from the account and where they were deliveredDetailed trace data ages out quickly and should be exported at once
OAuth consent grantsApplications given ongoing access to the mailbox and dataPersists in directory audit records but should be captured with the app identity
Authentication method changesAttacker registered phone numbers, apps, or hardware keysStrong indicator of intended long term access

What an examiner does with them

Records are correlated into a single timeline where each attacker session is bounded, each action attributed, and each affected message identified. That timeline is what allows counsel to make a defensible notification decision instead of an assumption, and it is what a carrier expects to see before paying a claim.

A compromised mailbox is a countdown

Sign in and mailbox audit records age out quickly. We can preserve the tenant evidence today and tell you what the intruder actually reached.

Determining exposure without overstating it

The hardest question after a mailbox compromise is not whether an intruder was present. It is what the intruder saw. Organizations frequently face pressure to notify everyone whose data was in the mailbox, which can mean tens of thousands of people, when the evidence supports a narrower and more accurate conclusion.

Access confirmed

Mailbox audit records identify specific messages that were opened or synchronized during attacker sessions.

Access possible

Messages present in the mailbox during the intrusion window that no record shows as accessed.

Access excluded

Messages received after session revocation, or in mailboxes the intruder never authenticated to.

Content review

Structured review of the affected message set to identify what categories of regulated data are actually present.

Session bounding

Precise first and last attacker authentication times so the exposure window is defined by evidence.

Downstream reach

Whether the account was used to compromise other internal or partner mailboxes.

Where auditing was not enabled or has already expired, the honest finding is that access cannot be confirmed or excluded for the affected period. That statement, clearly documented, is far more defensible than a confident conclusion the records do not support.

The first day response that preserves both evidence and options

Well intentioned cleanup destroys evidence. Deleting attacker rules, resetting mailboxes, and closing the ticket routinely eliminate the exact records needed later by counsel, the carrier, and the regulator.

  1. Revoke sessions and refresh tokens rather than only resetting the password, then remove attacker registered authentication methods.
  2. Export sign in logs, unified audit records, message trace, and mailbox rules before anything is remediated.
  3. Place a litigation hold on affected mailboxes so deletion does not remove message content.
  4. Preserve rather than delete attacker artifacts, capturing rule definitions and consent grants as evidence first.
  5. Notify the bank immediately on any funds transfer, and file with the FBI Internet Crime Complaint Center to support recall efforts.
  6. Engage counsel early so the investigation can be structured appropriately and the notification analysis can begin with real facts.

What matters most

  • Speed of preservation, because sign in and message trace records expire on short provider schedules.
  • Correct scoping, since the first compromised mailbox is rarely the only one.
  • Licensing reality, because mailbox access detail depends on features that had to be enabled before the incident.
  • Restraint in conclusions, distinguishing confirmed access from possible access.
  • Parallel financial action, since fund recall is time limited and independent of the forensic timeline.

Common misconceptions

We have multifactor authentication, so this cannot be BEC

Adversary in the middle kits steal the post authentication session, satisfying multifactor from the provider point of view.

We reset the password, so the intruder is out

Existing session tokens remain valid until explicitly revoked, and attacker registered authentication methods survive a reset.

Only the finance team is targeted

Human resources, legal, and executive assistant mailboxes are prime targets because of the regulated data they hold.

Nothing was sent, so nothing happened

Reading a mailbox full of personal or health information can itself create a notification obligation.

When this applies, and when it does not

This applies when

  • A wire, payroll, or vendor payment was redirected to an account you did not authorize.
  • A mailbox shows unfamiliar sign ins, hidden rules, or forwarding you did not create.
  • Clients or vendors report receiving fraudulent messages from your domain.
  • Counsel or a carrier requires an independent determination of what was accessed.

This does not apply when

  • A phishing email was received and reported but no credential was ever entered and no sign in succeeded.
  • The dispute is purely contractual between two parties with no unauthorized access involved.
  • The affected account is a personal mailbox with no business records, where a different approach applies.
  • Audit logging was never enabled and all retention windows have long since closed, which limits achievable findings.

Phishing variants and what each one leaves behind

VariantObjectivePrimary evidenceTypical tell
Credential phishingHarvest username and passwordSign in logs, proxy domain recordsSign in from an unusual address or device
Adversary in the middleSteal the authenticated sessionSign in logs showing satisfied multifactor from a new locationMultifactor marked satisfied with no user prompt recollection
OAuth consent phishingObtain durable app access to dataDirectory audit consent grant recordsAn unfamiliar application with mailbox permissions
Thread hijackingInsert fraud into a trusted conversationMessage trace and header analysisA reply from a nearly identical lookalike domain
Vendor impersonationRedirect an outbound paymentHeader analysis and vendor tenant recordsNew banking details delivered by email alone

How Elite Digital Forensics helps

Businesses, outside counsel, and cyber insurance carriers retain us to establish what actually happened inside a compromised tenant. We preserve the evidence before it expires, reconstruct each attacker session, and give decision makers a factual basis for the notification and recovery decisions that follow.

Emergency tenant preservation

Immediate export of sign in logs, unified audit records, mailbox rules, and message trace across every affected account.

Attacker session reconstruction

A bounded timeline of every unauthorized authentication, action taken, and message accessed.

Exposure determination

An evidence based scope of what was accessed, so notification decisions rest on records rather than assumptions.

Fraud tracing support

Header and infrastructure analysis to support bank recall efforts, IC3 filings, and law enforcement referrals.

Vendor and partner analysis

Determination of whether the compromise originated with a counterparty and how far it propagated.

Expert testimony

Court qualified examiners able to explain cloud email evidence and its limits under cross examination.

Problems we solve

  • A payment went to a fraudulent account and no one can say how the instructions were altered.
  • You must decide whether a mailbox compromise requires notifying thousands of individuals.
  • Your carrier will not advance the claim without an independent forensic determination.
  • Customers are receiving fraudulent invoices that appear to come from your company.
  • You suspect the intrusion started with a vendor rather than inside your own tenant.

Talk with a forensic examiner about your incident

Consultations are confidential. We work directly with affected businesses, with outside counsel, and with cyber insurance carriers and brokers nationwide.

About Elite Digital Forensics

Elite Digital Forensics is an independent digital forensics firm serving businesses, attorneys, and insurers nationwide. Our examiners include former law enforcement forensic examiners who have testified as court qualified expert witnesses in state and federal proceedings. We do not sell security software and we do not manage client networks, so our findings carry no conflict of interest when the question is whether an environment was adequately secured.

Every engagement follows documented chain of custody, defensible acquisition methods, and reporting written for attorney review, insurer submission, regulator response, or courtroom use. Work performed at the direction of counsel is generally treated as attorney work product prepared in anticipation of litigation. Call (833) 292-3733 or request a confidential consultation.

Frequently asked questions

How does business email compromise bypass multifactor authentication?

Adversary in the middle phishing proxies relay the victim to the genuine login page and capture the session cookie that is issued after the multifactor prompt is satisfied. The attacker then replays that cookie, so the provider treats the session as fully authenticated without any further prompt.

Can you tell exactly which emails the attacker read?

Often yes. Mailbox auditing records message level access events that identify the specific items opened or synchronized during a session. This depends on auditing being enabled and appropriately licensed before the incident, and on the records still being within retention when they are exported.

Is a business email compromise a reportable data breach?

It frequently is, because mailboxes typically contain personal, health, or financial information about other people. The determination is legal rather than technical, but it rests on forensic facts about which accounts were accessed, when, and what those mailboxes contained.

What should we do in the first hour after discovering a compromise?

Revoke sessions and tokens, remove attacker registered authentication methods, place affected mailboxes on hold, and export audit and sign in records before remediation. If money moved, contact the bank immediately and file with the FBI Internet Crime Complaint Center.

How long do we have before the evidence disappears?

Detailed message trace data and interactive sign in records commonly age out within days to weeks depending on license tier. Treat preservation as an immediate task rather than a step to schedule after remediation is complete.

Can stolen funds be recovered after a fraudulent wire?

Recovery is possible when the receiving institution is notified quickly. The FBI financial fraud kill chain has recovered substantial sums, but success drops sharply after the first days, so banking notification should run in parallel with the forensic work rather than after it.

References and authoritative sources

  1. FBI Internet Crime Complaint Center (IC3) — https://www.ic3.gov/
  2. CISA, Implementing Phishing Resistant MFA — https://www.cisa.gov/resources-tools/resources/implementing-phishing-resistant-mfa
  3. Microsoft Purview, Manage audit log retention policies — https://learn.microsoft.com/purview/audit-log-retention-policies
  4. Google, Email sender guidelines — https://support.google.com/a/answer/81126
  5. Verizon Data Breach Investigations Report — https://www.verizon.com/business/resources/reports/dbir/
  6. CISA, Report a Cyber Incident — https://www.cisa.gov/report

#DigitalForensics #ComputerForensics #CellPhoneForensics #ExpertWitness #DigitalForensicExperts #EliteDigitalForensics #ForensicInvestigation #DataBreachResponse #DataBreachInvestigation #IncidentResponse #CyberForensics #BEC #Phishing #EmailForensics #WireFraud

This content is for educational and informational purposes only and does not constitute legal advice. Elite Digital Forensics provides independent digital forensic services and expert witness testimony; we do not provide legal representation. Every case is fact specific; outcomes depend on the evidence, jurisdiction, and counsel. Retain qualified legal counsel for advice about your matter.

Assistant Icon Elite Digital Forensics Assistant
πŸ‘‹ Live Chat Now!
Free Virtual Consultation 24/7
Chat Now!

By submitting this form, you consent to be contacted by email, text, or phone. Your information is kept secure and confidential. Reply Stop to opt out at anytime.Β 

IMPORTANT: Please remember to check your spam or junk folder