Business email compromise

Business email compromise is a mailbox timeline problem.

Payment fraud, vendor impersonation, and suspicious email activity require a review of account events, message movement, mailbox settings, and the sequence that led to the disputed communication.

First distinction

Spoofing is not the same as mailbox access.

Many email fraud events look similar at first glance. The forensic question is whether the message was merely forged, whether an internal mailbox was accessed, whether a vendor account was compromised, whether a fraudulent domain was used, or whether a real payment thread was altered.

01

Spoofed sender

The visible sender may be forged without access to the real mailbox.

02

Compromised mailbox

Sign in records, mailbox rules, deleted messages, and sent items may show account activity.

03

Compromised vendor

The fraud may originate outside the victim business but still affect a real transaction.

04

Payment thread change

Instructions may be inserted into an existing conversation to appear routine.

05

Fraudulent domain

A lookalike domain can imitate a party without touching the real account.

Mailbox sequence

The important record is often spread across several systems.

Email compromise review often involves cloud audit logs, mailbox rules, message trace records, headers, authentication events, security alerts, connected applications, recovery changes, and communications around the payment or disclosure event.

  1. Sign in

    Review account access, geography, device information, application type, MFA prompts, and unusual authentication events.

  2. Mailbox changes

    Look for forwarding, inbox rules, deleted messages, hidden folders, retention changes, and message movement.

  3. Message path

    Compare headers, message trace, replies, sent items, and vendor communications.

  4. Persistence

    Check OAuth grants, connected apps, recovery settings, inbox rules, and other ways access may continue.

  5. After event

    Document containment actions, password changes, account recovery, and preserved logs.

Records with limits

Cloud evidence has retention and logging boundaries.

Some mailbox records are only available for a limited period or depend on the account license, platform settings, logging configuration, and administrative permissions. Audit logs, message trace records, security alerts, sign in details, and deleted mailbox content may not all be available by the time the event is reviewed.

That does not end the analysis. It means conclusions need to be grounded in the records that remain and in the limits of what the provider retained.

BEC consultation

Need to understand what happened inside an email account?

Rune Forensics can review mailbox activity, audit records, message headers, forwarding settings, suspicious logins, connected applications, and payment instruction events.

Request consultation