Spoofed sender
The visible sender may be forged without access to the real mailbox.
Business email compromise
Payment fraud, vendor impersonation, and suspicious email activity require a review of account events, message movement, mailbox settings, and the sequence that led to the disputed communication.
First distinction
Many email fraud events look similar at first glance. The forensic question is whether the message was merely forged, whether an internal mailbox was accessed, whether a vendor account was compromised, whether a fraudulent domain was used, or whether a real payment thread was altered.
The visible sender may be forged without access to the real mailbox.
Sign in records, mailbox rules, deleted messages, and sent items may show account activity.
The fraud may originate outside the victim business but still affect a real transaction.
Instructions may be inserted into an existing conversation to appear routine.
A lookalike domain can imitate a party without touching the real account.
Mailbox sequence
Email compromise review often involves cloud audit logs, mailbox rules, message trace records, headers, authentication events, security alerts, connected applications, recovery changes, and communications around the payment or disclosure event.
Review account access, geography, device information, application type, MFA prompts, and unusual authentication events.
Look for forwarding, inbox rules, deleted messages, hidden folders, retention changes, and message movement.
Compare headers, message trace, replies, sent items, and vendor communications.
Check OAuth grants, connected apps, recovery settings, inbox rules, and other ways access may continue.
Document containment actions, password changes, account recovery, and preserved logs.
Records with limits
Some mailbox records are only available for a limited period or depend on the account license, platform settings, logging configuration, and administrative permissions. Audit logs, message trace records, security alerts, sign in details, and deleted mailbox content may not all be available by the time the event is reviewed.
That does not end the analysis. It means conclusions need to be grounded in the records that remain and in the limits of what the provider retained.
BEC consultation
Rune Forensics can review mailbox activity, audit records, message headers, forwarding settings, suspicious logins, connected applications, and payment instruction events.
Request consultation