Business Email Compromise Investigation and Recovery
Business Email Compromise Investigation and Recovery is an emergency engagement for organizations whose Microsoft 365 account — or several — has been taken over. IT Partner contains the attacker first (revoking sessions and tokens, resetting credentials in the right order, removing malicious inbox rules, forwarding, and rogue OAuth grants), then builds a timeline of attacker activity from Microsoft Entra sign-in logs and the Microsoft Purview unified audit log, hunts down every persistence mechanism, summarizes what was accessed or sent, and hands you a prioritized hardening plan. We prepare the evidence your bank, cyber-insurance carrier, and law enforcement will ask for — your counsel and carrier lead those tracks; we support them.
What this engagement is
A business email compromise rarely announces itself. It surfaces as a customer asking about changed bank details on an invoice, a vendor confirming a payment you never requested, inbox rules nobody created, or a wave of phishing sent from your own domain. By that point the attacker has usually been reading mail for days or weeks — and every hour of improvised cleanup can destroy the evidence that shows what they actually did. This engagement does the work in the right order. Containment first: revoke active sessions and refresh tokens, reset credentials for the accounts in scope, verify and clean up registered MFA methods, remove malicious inbox rules and mailbox or transport forwarding, and revoke attacker-consented OAuth applications. Investigation second: a timeline of attacker sign-ins and actions reconstructed from Microsoft Entra sign-in logs and the Microsoft Purview unified audit log, a systematic hunt for persistence — rules, delegations, added MFA methods, app registrations, new accounts, role changes — and an exposure review of what was read, searched, or sent, to the extent your licensing and retention captured it. Hardening third: a prioritized, owner-assigned list of the changes that would have prevented or shortened the incident, so the same door is not left open twice. Who this is for: organizations on Microsoft 365 that are mid-incident or have just closed one — including cases where fraudulent payment instructions already went out. Who it is not for: ransomware and endpoint malware response, on-premises server forensics, or litigation-driven forensic work — those need a different engagement, and we say so during intake rather than after. The engagement is scoped per incident, from $4,950, with the quote confirmed in writing before work begins. The defined investigation scope typically completes within five business days; containment actions start on day one.
Success criteria
What you receive
How the work unfolds
Confirm scope, access, and the containment order with your decision-maker, then execute it: revoke sessions and tokens, reset credentials, clean up MFA methods, remove malicious rules and forwarding, and revoke rogue OAuth grants. Preserve rule definitions, messages, and audit evidence before removing anything.
Sweep the tenant for everything an attacker leaves behind: inbox rules and transport rules, delegations and mailbox permissions, OAuth grants and app registrations, added MFA and recovery methods, new accounts, and admin-role changes. Revert what is malicious; record what is ambiguous for your review.
Reconstruct attacker activity from Entra sign-in logs and the unified audit log: initial access, sessions, mail access and searches, sent messages, and data touched. Identify affected third parties — customers or vendors who received fraudulent mail — so you can decide on notifications.
Assemble the evidence package for bank, carrier, and law enforcement, and draft the prioritized hardening plan with owners. Apply any quick mitigations you approve during the engagement.
Deliver the incident report, walk your administrators through the timeline and the tenant changes, review re-compromise indicators, and agree the follow-on hardening or monitoring work if you want it.
Prerequisites
Who does what
IT Partner
- Lead intake, scoping, and the approved containment sequence, starting with first response within one business hour of your request.
- Execute containment: session and token revocation, coordinated credential resets, MFA method cleanup, malicious rule and forwarding removal, and OAuth grant revocation.
- Preserve rule definitions, messages, and audit evidence before removal, and document every containment action with timestamps.
- Hunt and revert persistence mechanisms across the in-scope tenant surfaces, recording ambiguous findings for your review.
- Reconstruct the attacker-activity timeline and exposure review from Entra sign-in logs and the unified audit log, within your licensing and retention limits.
- Prepare the evidence package and executive summary for your bank, carrier, counsel, and law-enforcement filings.
- Deliver the prioritized hardening plan and apply approved quick mitigations during the engagement.
- Conduct the administrator handoff and identify re-compromise indicators to watch.
Your team
- Provide emergency administrative access and a decision-maker who can approve containment actions promptly.
- Disclose everything known about the incident, including any cleanup already performed and any prior compromises.
- Decide and execute notifications: customers and vendors who received fraudulent mail, your bank, your cyber-insurance carrier, counsel, and law enforcement.
- Own all payment-recovery actions with your bank and law enforcement, using the evidence we prepare.
- Communicate with affected employees, and handle HR or disciplinary matters if an insider is involved.
- Approve the hardening plan priorities and own their implementation unless separately contracted.
- Make legal determinations — including breach-notification obligations — with your counsel; we provide the factual record.
- Review and approve the final report and deliverables against the published success criteria.
What's not included
Limitations & technical notes
Frequently asked questions
We think our Microsoft 365 account is compromised — what should we do right now?
Three things before anything else. First, if fraudulent payment instructions went out, call your bank now and ask for a recall — hours matter more than anything an investigator does later. Second, stop the improvised cleanup: do not delete inbox rules, purge messages, or wipe the account, because that destroys the record of what the attacker did. Third, contact us with what you know — which accounts, since when, what tipped you off. Containment (revoking sessions, resetting credentials, removing rules and rogue app grants) starts on day one, in an order that preserves evidence.
How fast do you respond?
Our published support SLA is first response within one business hour — and we publish our monthly support statistics for every month since December 2023, including the months we missed, so you can check the record rather than take the claim on faith. We do not advertise a guaranteed 24/7 emergency dispatch, because we would rather publish a number we can prove.
Can you tell us exactly which emails the attacker read?
Often yes, sometimes partially. Microsoft 365 records mailbox activity in the unified audit log, and item-level access events (MailItemsAccessed) — once reserved for premium licensing — have been extended by Microsoft to standard tiers, though coverage depends on your license and configuration history. Where item-level events exist, we can list what was accessed and searched; where they do not, we reconstruct exposure conservatively from sign-ins, sync activity, and sent items, and the report states the confidence level explicitly.
Money was wired to the attacker. Can you get it back?
We will not promise that, and you should be suspicious of anyone who does. Recalls are decided between your bank, the receiving bank, and law enforcement, and success drops sharply with every passing hour. What we do: help you move immediately — bank recall request, evidence for an IC3 (FBI Internet Crime Complaint Center) filing, message traces and timeline extracts your bank and investigators will ask for — prepared fast and documented properly. Recovery actions themselves belong to your bank and law enforcement.
Will you work with our cyber-insurance carrier and our lawyer?
Yes — in a support role. Your carrier and counsel lead the claim and the legal determinations, including whether the incident triggers breach-notification obligations. We produce what they need: the factual timeline, containment log, exposure summary, and evidence package, with the collection method documented. If your policy requires using a carrier-approved response panel, engage the carrier first and we will coordinate with whoever they appoint.
Is this a certified forensic investigation we could use in court?
No, and we say that plainly. This is an operational investigation and recovery engagement: its job is to evict the attacker, establish what happened, and harden the tenant. We document our methods and preserve evidence carefully, and our output can be handed to a forensics firm — but bit-for-bit imaging, formal chain of custody, and expert-witness work are a different discipline that should be engaged through your counsel if litigation is anticipated.
The attacker emailed our customers with fake invoices. What do we do about that?
The investigation identifies which external parties received attacker mail — recipients, messages, and send times — so the notification decision is made on facts rather than guesswork. We help you pull the affected-recipient list and draft the technical explanation of what happened; deciding whom to notify, and sending those communications, stays with you and your counsel, because notification carries legal and commercial judgment we should not make for you.
Will containment lock our whole company out of email?
No. Containment is targeted at the accounts in scope: their sessions are revoked, their credentials reset, their attacker-registered MFA methods removed. Those users re-authenticate and keep working; the rest of the organization is not touched unless the investigation shows the compromise is wider. Every disruptive action is approved by your decision-maker before it runs.
We already reset the password. Are we safe now?
Usually not, and this is the most common mistake we see. A password reset alone does not revoke existing sessions and refresh tokens, does not remove an authenticator app the attacker registered, and does not touch inbox rules, mailbox forwarding, delegate permissions, or OAuth applications the attacker consented to — any one of which keeps them reading your mail after the reset. The persistence hunt exists precisely because attackers assume you will change the password and stop there.
What if we only have basic Microsoft 365 licensing — is an investigation still possible?
Yes. Microsoft Purview Audit (Standard), included with business and enterprise plans, retains 180 days of activity for events generated since October 2023, and Microsoft has extended previously premium item-level events to standard tiers. Sign-in log depth depends on your Entra ID license. The practical effect of lighter licensing is coarser detail in places, not an impossible investigation — and the report will distinguish what the logs prove from what they merely suggest.
What does "from $4,950" actually cover?
The base engagement covers a defined per-incident scope — confirmed in your written quote before work begins — including containment, the persistence hunt, the audit-log timeline and exposure review, the evidence package, the hardening plan, and the handoff, typically within five business days. What moves the price up: more compromised accounts, longer attacker dwell time to reconstruct, or extension beyond Microsoft 365 into endpoints and other systems. Any change is a written, approved re-quote, and you pay after you approve delivery.
How do we keep this from happening again?
The engagement ends with a prioritized hardening plan — typically MFA coverage gaps, Conditional Access, legacy authentication, mail-authentication records, and alerting — with owners and order. Implementation is available as follow-on work: Microsoft 365 Security Baseline and Secure Score Remediation for tenant-wide hardening, Enable MFA for All Users and Conditional Access Policy Implementation for identity, Microsoft Defender for Office 365 Implementation for mail-borne threats, and Managed Detection and Response for continuous monitoring.