---
title: 'Business email compromise (BEC) response'
url: 'https://triplepoint.org.uk/security/incident-response/business-email-compromise'
markdown: 'https://triplepoint.org.uk/security/incident-response/business-email-compromise.md'
date: '2026-10-08'
description: 'Business email compromise help for UK businesses. Lock attackers out of a hacked mailbox, investigate invoice and payment fraud, and close the way back in.'
---

# Business email compromise (BEC) response

If it's happening now1. **If money has been sent, call your bank now.** The sooner they know, the better the chance of stopping the payment. Then report it to Report Fraud on 0300 123 2040 or at reportfraud.police.uk (in Scotland, Police Scotland on 101).
2. **Change the password and sign the account out everywhere.** Check that multi-factor authentication is on and that no sign-in methods you don't recognise have been added.
3. **Look for mailbox rules and forwarding.** Attackers often add rules that forward or hide messages so they can carry on unseen.
4. **Warn the people who may have been targeted** by phone rather than email, so nobody acts on a fake request.
5. **Get help before deleting anything.** Sign-in and mailbox logs show what the attacker did, and they're only kept for a limited time.

 The riskBusiness email compromise doesn't need malware. With one password, often taken by a fake sign-in page, an attacker can read a mailbox quietly, learn who pays whom, and send a convincing request to change bank details at just the right moment.

Changing the password isn't always enough. Attackers often leave forwarding rules, connected apps or extra sign-in methods behind so they can get back in.

 What it does- Removes the attacker's access, including forwarding rules, connected apps and sign-in methods they added
- Investigates sign-in and mailbox logs to show what was read, sent and changed
- Checks whether other accounts have been taken over too
- Works out how the account was compromised, so that way in can be closed
- Evidence and a report for your bank, your insurer and the police

Most email compromise starts with a phishing message. [Email security](https://triplepoint.org.uk/security/people-and-email/email-security) catches more of them before they arrive, and [phishing simulation and training](https://triplepoint.org.uk/security/people-and-email/phishing-simulation) helps staff spot the ones that get through.

 Who it's forAny business whose email has been taken over, or that has paid a fake invoice or sent money to a changed bank account, whether or not you're already a customer.

 How we supply itEmail compromise investigations are carried out by Sophos's incident response team and arranged through us. Contact us and we'll get it started. If money has gone, call your bank first.

 What's under the hood**Sophos Incident Response Services** — Sophos's digital forensics and incident response team, which gained NCSC-assured Cyber Incident Response (Level 2) status in 2024.

 Questions What is business email compromise?+An attack in which criminals take over, or convincingly imitate, a business email account to trick someone into sending money or information. A common form is invoice fraud, where a real supplier appears to ask for payment to a new bank account.

 Will we get the money back?+Sometimes, if the bank is told quickly enough to freeze it, which is why calling the bank comes first. The UK's reimbursement rules for this kind of fraud cover individuals, micro-enterprises and small charities, but not larger businesses.

 Do we have to report it to the ICO?+Possibly. A mailbox usually holds personal data, so a compromise can be a reportable breach: UK GDPR requires reporting to the ICO within 72 hours of finding out, unless it's unlikely to put anyone at risk. The investigation shows what was accessed, which helps you decide.

 We use multi-factor authentication. How did they get in?+Some phishing kits capture the signed-in session as well as the password, which gets past text-message and app codes. Phishing-resistant sign-in, such as passkeys, closes that gap.

 How much does it cost?+It depends on the size of the incident, and the cost is agreed with you before work starts.

[← Back to Recover from an attack](https://triplepoint.org.uk/security/incident-response)

## Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

[Talk to us →](https://triplepoint.org.uk/contact?about=Business%20email%20compromise) or [see every security area →](https://triplepoint.org.uk/security)

---

## Navigation

- Parent: [Cyber incident response and recovery](https://triplepoint.org.uk/security/incident-response.md)
- Previous: [Ransomware attack recovery](https://triplepoint.org.uk/security/incident-response/ransomware-recovery.md)
- Next: [Network intrusion and breach response](https://triplepoint.org.uk/security/incident-response/network-intrusion.md)
