A supplier's bank details have suddenly changed, a customer has paid an invoice you never sent, or your mailbox is sending messages you didn't write. Lock the attacker out and find out how far it went.
Business email compromise doesn't need malware. With one password, often taken by a fake sign-in page, an attacker can read a mailbox quietly, learn who pays whom, and send a convincing request to change bank details at just the right moment.
Changing the password isn't always enough. Attackers often leave forwarding rules, connected apps or extra sign-in methods behind so they can get back in.
Most email compromise starts with a phishing message. Email security catches more of them before they arrive, and phishing simulation and training helps staff spot the ones that get through.
Any business whose email has been taken over, or that has paid a fake invoice or sent money to a changed bank account, whether or not you're already a customer.
Email compromise investigations are carried out by Sophos's incident response team and arranged through us. Contact us and we'll get it started. If money has gone, call your bank first.
Sophos Incident Response Services — Sophos's digital forensics and incident response team, which gained NCSC-assured Cyber Incident Response (Level 2) status in 2024.
Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.