Recover from an attack

Business email compromise (BEC) response

A supplier's bank details have suddenly changed, a customer has paid an invoice you never sent, or your mailbox is sending messages you didn't write. Lock the attacker out and find out how far it went.

If it's happening now
  1. If money has been sent, call your bank now. The sooner they know, the better the chance of stopping the payment. Then report it to Report Fraud on 0300 123 2040 or at reportfraud.police.uk (in Scotland, Police Scotland on 101).
  2. Change the password and sign the account out everywhere. Check that multi-factor authentication is on and that no sign-in methods you don't recognise have been added.
  3. Look for mailbox rules and forwarding. Attackers often add rules that forward or hide messages so they can carry on unseen.
  4. Warn the people who may have been targeted by phone rather than email, so nobody acts on a fake request.
  5. Get help before deleting anything. Sign-in and mailbox logs show what the attacker did, and they're only kept for a limited time.
The risk

Business email compromise doesn't need malware. With one password, often taken by a fake sign-in page, an attacker can read a mailbox quietly, learn who pays whom, and send a convincing request to change bank details at just the right moment.

Changing the password isn't always enough. Attackers often leave forwarding rules, connected apps or extra sign-in methods behind so they can get back in.

What it does
  • Removes the attacker's access, including forwarding rules, connected apps and sign-in methods they added
  • Investigates sign-in and mailbox logs to show what was read, sent and changed
  • Checks whether other accounts have been taken over too
  • Works out how the account was compromised, so that way in can be closed
  • Evidence and a report for your bank, your insurer and the police

Most email compromise starts with a phishing message. Email security catches more of them before they arrive, and phishing simulation and training helps staff spot the ones that get through.

Who it's for

Any business whose email has been taken over, or that has paid a fake invoice or sent money to a changed bank account, whether or not you're already a customer.

How we supply it

Email compromise investigations are carried out by Sophos's incident response team and arranged through us. Contact us and we'll get it started. If money has gone, call your bank first.

What's under the hood

Sophos Incident Response Services — Sophos's digital forensics and incident response team, which gained NCSC-assured Cyber Incident Response (Level 2) status in 2024.

Questions
An attack in which criminals take over, or convincingly imitate, a business email account to trick someone into sending money or information. A common form is invoice fraud, where a real supplier appears to ask for payment to a new bank account.
Sometimes, if the bank is told quickly enough to freeze it, which is why calling the bank comes first. The UK's reimbursement rules for this kind of fraud cover individuals, micro-enterprises and small charities, but not larger businesses.
Possibly. A mailbox usually holds personal data, so a compromise can be a reportable breach: UK GDPR requires reporting to the ICO within 72 hours of finding out, unless it's unlikely to put anyone at risk. The investigation shows what was accessed, which helps you decide.
Some phishing kits capture the signed-in session as well as the password, which gets past text-message and app codes. Phishing-resistant sign-in, such as passkeys, closes that gap.
It depends on the size of the incident, and the cost is agreed with you before work starts.

Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

Talk to us → or see every security area →