Skip to content
L&M Cybersecurity

Incident Response

Inside a 72-hour response: anatomy of a business email compromise

A finance team paid a supplier invoice that was not from the supplier. What followed is a useful map of how these intrusions actually run.

L&M Incident Response 10 min read

The following is a composite of several engagements, with identifying details removed. The pattern is consistent enough that specifics are unnecessary.

Hour 0: the call

A mid-sized firm notices that a supplier has chased an invoice already marked paid. The payment went to different bank details, supplied in an email thread that looked entirely legitimate — because it was legitimate, until it was not.

Hours 1–8: containment

We revoke all active sessions for the affected mailbox, force credential rotation, and pull the audit logs before anything ages out. Two findings emerge immediately: a mailbox rule silently moving supplier correspondence to an obscure folder, and a registered authenticator device nobody recognises.

Hours 8–36: scope

Sign-in logs show access from a residential proxy service beginning eleven days earlier, following a credential-harvesting page that relayed the MFA prompt in real time. The attacker read, waited, and learned the invoicing cadence before intervening. Two further mailboxes show the same access pattern.

Hours 36–72: recovery and notification

Rules removed, devices revoked, conditional access tightened to block legacy authentication and unmanaged devices. The bank is engaged within the recall window and recovers part of the transfer. Regulatory assessment concludes personal data in the mailboxes was accessed, triggering notification.

What would have stopped it

Phishing-resistant authentication would have defeated the relay outright. Alerting on new mailbox forwarding rules would have caught it on day one. And a payment process requiring out-of-band verification of any bank detail change — a phone call to a known number — would have stopped the loss even with the mailbox fully compromised.

Two of those three are configuration changes. One is a process change. None require a new product.

Seeing something similar in your environment?

Talk to our team

Next step

Find out what an attacker sees before they show you.

Book a scoping call with a senior consultant. No sales engineer, no slide deck — a technical conversation about your actual exposure.