- Nationwide Digital Forensic & Cyber Investigation Services
Business email compromise remains one of the highest loss cyber crimes reported to the FBI, and almost every case begins with a single set of stolen credentials. This page explains the mechanics of modern phishing, the records that prove what an intruder read, and the questions a defensible investigation has to answer.
Updated August 2026 · Reviewed by Elite Digital Forensics examiners · Nationwide breach response
| Question | One line answer |
|---|---|
| Does multifactor authentication stop BEC? | App and SMS based factors are routinely bypassed by session token theft. Phishing resistant hardware factors are the effective control. |
| Can we prove which emails the intruder read? | Often yes, through mailbox auditing records, but only if the licensing and retention captured them. |
| How fast do attackers act? | Inbox rules and forwarding are commonly created within minutes of the first successful sign in. |
| Is a password reset enough? | No. Stolen session tokens remain valid until sessions are revoked and tokens invalidated. |
| Does BEC trigger notification duties? | Frequently, when the mailbox contained personal, health, or financial information about others. |
| Can stolen funds be recovered? | Sometimes, if the bank and the FBI are engaged within days through the financial fraud kill chain. |
| Term | What it means |
|---|---|
| Business email compromise | Fraud committed through access to, or convincing impersonation of, a legitimate business mailbox. |
| Adversary in the middle | A phishing proxy that relays the victim to the real login page, captures the password, and steals the resulting session cookie. |
| Session token | The credential a browser holds after a successful login. Stealing it allows access without the password or a second factor. |
| Inbox rule | A mailbox rule that moves, deletes, or forwards messages. Attackers use them to hide replies from the legitimate user. |
| Message trace | The provider record of messages entering and leaving the tenant, used to show forwarding and outbound fraud attempts. |
| Thread hijacking | Replying inside a real existing conversation so the fraudulent message inherits the trust of the thread. |
The stereotype of a badly written wire request from an unfamiliar address is long out of date. Contemporary campaigns use functional proxies of the real login page, land inside genuine email threads, and behave carefully enough that the legitimate user notices nothing.
Lure. A link arrives in a shared document notification, an invoice, a voicemail alert, or a reply inside a thread taken from an already compromised partner mailbox.
Credential and token capture. The proxy page shows the authentic provider login, forwards the multifactor prompt to the victim, and captures the resulting session cookie.
Persistence. The attacker registers an additional authentication method, creates inbox rules that hide banking and vendor replies, and may consent an OAuth application for durable access.
Reconnaissance. Searches run against the mailbox for terms like wire, invoice, routing, remittance, and payroll to locate an in progress transaction.
Execution. A payment instruction is altered, an internal request is sent from the trusted account, or the mailbox contents are exported for extortion or resale.
The compromised mailbox itself becomes the next lure. Because messages originate from a genuine authenticated account and continue an existing thread, they pass authentication checks and reader scrutiny alike. Vendors, clients, and internal finance staff are the usual next victims, which is why scoping cannot stop at the first account.
A defensible BEC investigation rests on tenant side records, not on what the user remembers. Each record answers a different question, and together they establish access, duration, and reach.
| Record | What it establishes | Preservation note |
|---|---|---|
| Sign in logs | Successful and failed authentications, source address, device, and whether multifactor was satisfied | Retention is license dependent, commonly 7 to 30 days for interactive sign ins unless exported |
| MailItemsAccessed | Which specific messages were opened or synced by the session | Requires appropriate licensing and mailbox auditing to be enabled beforehand |
| Inbox rule and forwarding events | Attacker created hiding and exfiltration mechanisms with timestamps | Captured in the unified audit log; the rule itself may be deleted by the attacker |
| Message trace | Messages sent from the account and where they were delivered | Detailed trace data ages out quickly and should be exported at once |
| OAuth consent grants | Applications given ongoing access to the mailbox and data | Persists in directory audit records but should be captured with the app identity |
| Authentication method changes | Attacker registered phone numbers, apps, or hardware keys | Strong indicator of intended long term access |
Records are correlated into a single timeline where each attacker session is bounded, each action attributed, and each affected message identified. That timeline is what allows counsel to make a defensible notification decision instead of an assumption, and it is what a carrier expects to see before paying a claim.
Sign in and mailbox audit records age out quickly. We can preserve the tenant evidence today and tell you what the intruder actually reached.
The hardest question after a mailbox compromise is not whether an intruder was present. It is what the intruder saw. Organizations frequently face pressure to notify everyone whose data was in the mailbox, which can mean tens of thousands of people, when the evidence supports a narrower and more accurate conclusion.
Mailbox audit records identify specific messages that were opened or synchronized during attacker sessions.
Messages present in the mailbox during the intrusion window that no record shows as accessed.
Messages received after session revocation, or in mailboxes the intruder never authenticated to.
Structured review of the affected message set to identify what categories of regulated data are actually present.
Precise first and last attacker authentication times so the exposure window is defined by evidence.
Whether the account was used to compromise other internal or partner mailboxes.
Where auditing was not enabled or has already expired, the honest finding is that access cannot be confirmed or excluded for the affected period. That statement, clearly documented, is far more defensible than a confident conclusion the records do not support.
Well intentioned cleanup destroys evidence. Deleting attacker rules, resetting mailboxes, and closing the ticket routinely eliminate the exact records needed later by counsel, the carrier, and the regulator.
Adversary in the middle kits steal the post authentication session, satisfying multifactor from the provider point of view.
Existing session tokens remain valid until explicitly revoked, and attacker registered authentication methods survive a reset.
Human resources, legal, and executive assistant mailboxes are prime targets because of the regulated data they hold.
Reading a mailbox full of personal or health information can itself create a notification obligation.
| Variant | Objective | Primary evidence | Typical tell |
|---|---|---|---|
| Credential phishing | Harvest username and password | Sign in logs, proxy domain records | Sign in from an unusual address or device |
| Adversary in the middle | Steal the authenticated session | Sign in logs showing satisfied multifactor from a new location | Multifactor marked satisfied with no user prompt recollection |
| OAuth consent phishing | Obtain durable app access to data | Directory audit consent grant records | An unfamiliar application with mailbox permissions |
| Thread hijacking | Insert fraud into a trusted conversation | Message trace and header analysis | A reply from a nearly identical lookalike domain |
| Vendor impersonation | Redirect an outbound payment | Header analysis and vendor tenant records | New banking details delivered by email alone |
Businesses, outside counsel, and cyber insurance carriers retain us to establish what actually happened inside a compromised tenant. We preserve the evidence before it expires, reconstruct each attacker session, and give decision makers a factual basis for the notification and recovery decisions that follow.
Immediate export of sign in logs, unified audit records, mailbox rules, and message trace across every affected account.
A bounded timeline of every unauthorized authentication, action taken, and message accessed.
An evidence based scope of what was accessed, so notification decisions rest on records rather than assumptions.
Header and infrastructure analysis to support bank recall efforts, IC3 filings, and law enforcement referrals.
Determination of whether the compromise originated with a counterparty and how far it propagated.
Court qualified examiners able to explain cloud email evidence and its limits under cross examination.
Consultations are confidential. We work directly with affected businesses, with outside counsel, and with cyber insurance carriers and brokers nationwide.
Elite Digital Forensics is an independent digital forensics firm serving businesses, attorneys, and insurers nationwide. Our examiners include former law enforcement forensic examiners who have testified as court qualified expert witnesses in state and federal proceedings. We do not sell security software and we do not manage client networks, so our findings carry no conflict of interest when the question is whether an environment was adequately secured.
Every engagement follows documented chain of custody, defensible acquisition methods, and reporting written for attorney review, insurer submission, regulator response, or courtroom use. Work performed at the direction of counsel is generally treated as attorney work product prepared in anticipation of litigation. Call (833) 292-3733 or request a confidential consultation.
Adversary in the middle phishing proxies relay the victim to the genuine login page and capture the session cookie that is issued after the multifactor prompt is satisfied. The attacker then replays that cookie, so the provider treats the session as fully authenticated without any further prompt.
Often yes. Mailbox auditing records message level access events that identify the specific items opened or synchronized during a session. This depends on auditing being enabled and appropriately licensed before the incident, and on the records still being within retention when they are exported.
It frequently is, because mailboxes typically contain personal, health, or financial information about other people. The determination is legal rather than technical, but it rests on forensic facts about which accounts were accessed, when, and what those mailboxes contained.
Revoke sessions and tokens, remove attacker registered authentication methods, place affected mailboxes on hold, and export audit and sign in records before remediation. If money moved, contact the bank immediately and file with the FBI Internet Crime Complaint Center.
Detailed message trace data and interactive sign in records commonly age out within days to weeks depending on license tier. Treat preservation as an immediate task rather than a step to schedule after remediation is complete.
Recovery is possible when the receiving institution is notified quickly. The FBI financial fraud kill chain has recovered substantial sums, but success drops sharply after the first days, so banking notification should run in parallel with the forensic work rather than after it.
#DigitalForensics #ComputerForensics #CellPhoneForensics #ExpertWitness #DigitalForensicExperts #EliteDigitalForensics #ForensicInvestigation #DataBreachResponse #DataBreachInvestigation #IncidentResponse #CyberForensics #BEC #Phishing #EmailForensics #WireFraud
This content is for educational and informational purposes only and does not constitute legal advice. Elite Digital Forensics provides independent digital forensic services and expert witness testimony; we do not provide legal representation. Every case is fact specific; outcomes depend on the evidence, jurisdiction, and counsel. Retain qualified legal counsel for advice about your matter.
Elite Digital ForensicsΒ is a Professional Digital Forensics and Cyber Consulting Company that provides services nationwide.Β
Elite Digital Forensics Assistant
By submitting this form, you consent to be contacted by email, text, or phone. Your information is kept secure and confidential. Reply Stop to opt out at anytime.Β
IMPORTANT: Please remember to check your spam or junk folder
We use cookies for site functionality and, only with your permission, analytics and advertising. See our Privacy Policy for details. California residents have the right to Do Not Sell or Share My Personal Information.