Mailbox, domain and payment chronology

Business Email Compromise and Payment Fraud Investigation

Independent forensic review of suspected mailbox compromise, spoofing, lookalike domains, fraudulent payment instructions and the records needed to explain the sequence.

Direct access to Alistair Ewing · Free initial consultation · Written estimate before work

Was the mailbox compromised, the sender spoofed or the conversation imitated?

Business email compromise can describe several different events. A criminal may gain access to a real mailbox, create a forwarding or inbox rule, register a lookalike domain, spoof a visible sender address, imitate an existing thread or combine several methods. The technical questions and evidence differ, so the review should not begin with a fixed assumption that the email account itself was hacked.

The examination brings together native messages and headers, message-trace data, tenant audit logs, sign-in records, mailbox rules and forwarding, app permissions, authentication changes and, where relevant, endpoint evidence. Those records are aligned with the commercial chronology: who requested a change, how it was checked, when payment was authorised, when the discrepancy was noticed and what containment followed.

The result may support a finding about the source account, domain, observed access, rule creation or communication sequence. It may also show that retention, licensing, prior remediation or missing recipient-side evidence prevents a complete answer. Fund recovery, attribution and criminal investigation remain separate matters.

Questions a BEC review may address

  • Whether a suspect message was sent through a legitimate mailbox, a spoofed address, a forwarding service or a lookalike domain.
  • Whether audit records show unusual sign-ins, unusual session activity, authentication changes, mailbox access, new applications or administrator activity.
  • Whether mailbox rules, including hidden, forwarding or deletion rules, changed how messages were received, copied, moved or concealed.
  • How the fraudulent instruction entered an existing conversation and whether either party’s mailbox records show missing or additional messages.
  • When payment details changed, who received the change, what independent verification occurred and how the technical events align with the payment timeline.
  • Whether the available evidence identifies affected accounts, messages, attachments, contacts or data accessed during the relevant period.
  • Which conclusions remain qualified because logs expired, licensing limited the available audit trail, an account was remediated or the other party’s evidence is unavailable.

Evidence worth preserving early

  • Native EML or MSG messages with complete headers, attachments and surrounding conversation.
  • Message trace, mail-flow and gateway records from the relevant retention period.
  • Microsoft 365, Google Workspace or other available tenant audit logs and sign-in records.
  • Mailbox rules, forwarding settings, delegates, records of application permissions and consent, multi-factor authentication (MFA) methods and account-change history.
  • Recipient-side and sender-side mailbox copies where lawful access can be arranged.
  • Endpoint, browser, credential-store or security telemetry where the device route is in issue and separately authorised.
  • Invoices, payment-change messages and internal approval records in their original digital formats.
  • A dated chronology of calls, bank contact, IT action, password resets, session revocation and other containment.

Three evidence strands

The email, the account and the payment each need their own chronology

Message provenance

Headers, routing, authentication results, message identifiers, MIME structure, attachments and copies held by each party can help test how a message travelled. A visible From address alone does not establish its origin.

Account activity

Sign-ins, sessions, mailbox audit, rules, forwarding, delegates, application permissions and consent records, and security changes may show relevant activity. An unfamiliar location or IP address is an indicator, not proof of who used the account.

Commercial sequence

The request, invoice, approval, independent verification, bank transfer, discovery and response actions are aligned with the technical records. That can identify opportunities and gaps without assigning legal blame.

First preservation decisions

Retain the records before routine remediation removes them

  • Export the suspect messages in native form, not only as screenshots or forwarded copies.
  • Record the exact time the fraud or suspected compromise was recognised.
  • Preserve available audit and message-trace data before its retention window expires.
  • Document password resets, MFA changes, rule deletion, session revocation and device work.
  • Ask the other communication party to preserve its corresponding messages and records through the appropriate legal or commercial route.

Possible outputs

What the review can deliver

  • A consolidated event chronology with source references, the time zone used and any clock differences.
  • An account, mailbox, domain and message evidence matrix.
  • A focused technical findings report for lawyers, insurers, directors or internal investigators.
  • A schedule of preserved indicators and unresolved evidence requests.
  • An expert report where the questions, material, procedure and instruction justify one.

Important limits of mailbox evidence

  • Email authentication can pass when a legitimate account or authorised sending service is misused.
  • Some header fields are supplied by a sender and cannot be treated as independently verified.
  • An unusual sign-in, device, location or IP address does not identify the person using the account.
  • Cloud audit coverage depends on provider, licence, settings, retention and the time at which data was preserved.
  • Password resets, rule removal, session revocation and device remediation may change or remove relevant context.
  • Technical findings do not decide negligence, contractual responsibility, reimbursement or criminal liability.
  • No investigation can promise identification of the offender or recovery of transferred funds.

Information needed to scope the review

  • Organisation, counterparty, insurer, bank, legal adviser and relevant individual names for a conflict check.
  • Whether money moved, whether access may remain active and who is directing the live response.
  • The email and cloud platform, affected domains and number of potentially relevant mailboxes.
  • The approximate incident window, payment chronology and date the issue was discovered.
  • What native messages, audit, trace, sign-in, endpoint and transaction records have been preserved.
  • The questions, intended recipient, deadline and required form of report.

Please do not attach evidence, passwords or confidential case papers to the public enquiry. A secure route is agreed only after the conflict check.

How conflict checks, quotations and evidence transfer work

Independent response references

Official guidance for immediate action and preservation

The NCSC business payment fraud guidance explains the immediate bank and IT response. UK cyber incidents can also be reported through the NCSC incident reporting service.

Victims in England, Wales and Northern Ireland can use the current Report Fraud service. In Scotland, see Police Scotland’s cybercrime reporting guidance. Reporting to the police, Report Fraud or NCSC does not replace any separate contractual, legal, regulatory or insurer notification.

Frequently asked questions

What should we do first if a payment has just been sent?

Contact the bank immediately through a trusted channel and activate the organisation’s security or incident-response route. Preserve the messages and timing, but urgent financial and containment action should not wait for a forensic quotation.

Can you tell whether the email account was actually hacked?

Sometimes audit, session, rule and mailbox records support that conclusion. In other cases the evidence is more consistent with spoofing, a lookalike domain or compromise elsewhere in the correspondence chain. The review tests these alternatives rather than assuming one.

Do email-authentication results prove that the sender was genuine?

No. Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC) can help assess authorised domain use and message handling. A valid result can still accompany misuse of a legitimate account or service. Human authorship and authority require wider evidence.

Are screenshots of the fraudulent emails enough?

They are useful for understanding what was displayed, but native messages and provider records usually contain much more provenance. Keep the screenshots, and preserve EML or MSG files, headers and mailbox data where possible.

Can deleted inbox rules or messages be recovered?

Provider audit, retention, deleted-item stores, message trace, endpoints or another party’s mailbox may retain evidence. Recovery depends on platform, settings, timing and prior action, so it cannot be promised.

Can the report identify who committed the fraud?

Technical evidence may link activity to accounts, infrastructure, sessions or devices. That does not automatically identify the human operator, and lawful attribution may require providers, banks or law enforcement.

Is this the same as an email-authenticity expert instruction?

No. BEC work reconstructs a compromise and payment event across mailbox, cloud and business records. The separate email-authenticity service is designed for a disputed message or provenance proposition in legal evidence. A matter can require both.

Read all questions about fees, timing, evidence and instructing Alistair

Initial enquiry

Need an independent BEC chronology?

Send party and organisation names, the approximate event window, whether payment occurred, the platforms involved and the questions the review must answer. Do not attach messages, bank records or credentials through the public form.

Scope a BEC investigation