
Business Email Compromise Recovery: What Businesses Should Do After an Email Account Is Compromised
October 7, 2026
A business email compromise requires a calm, methodical response. This guide details the complete BEC recovery process for business leaders, from initial detection and containment to financial fraud recovery, investigation, and prevention.
When a business email account is compromised, you must act quickly and methodically to contain the damage, eject the attacker, and recover control. A business email compromise (BEC) is not just an IT problem; it's a business crisis that can lead to significant financial loss, data breaches, and regulatory penalties. The moments after discovering a compromised account are critical.
Your immediate goals are to stop any financial losses, secure the account, and preserve evidence for investigation. Do not panic. Do not delete the user account or mailbox—this destroys crucial evidence. The attacker may have been in your systems for weeks or months, setting up methods to persist even after a password reset. A thorough, structured response is essential.
If you are in the middle of a business email compromise incident, contact our 24/7 response team now at business email compromise.
This guide outlines the complete recovery process for a business email compromise. We will walk through the steps from initial detection to long-term prevention, helping you navigate the crisis and secure your organization.
How Do You Know If a Business Email Account Is Compromised?
Recognizing the signs of a compromise is the first step. While some indicators are obvious, others are subtle. Attackers often try to remain hidden as long as possible while they learn your business operations to launch a convincing financial fraud attack, such as CEO fraud or vendor email compromise.
Common signs include:
- Reports of unusual emails: Your employees, customers, or vendors report receiving strange emails from one of your accounts.
- Unexpected password reset prompts: The legitimate user receives prompts to approve a multi-factor authentication (MFA) push they did not initiate.
- Strange sign-in locations: Reviewing Microsoft 365 or Google Workspace sign-in logs reveals logins from unusual geographic locations or at odd hours.
- New email forwarding rules: The attacker creates inbox rules that forward sensitive emails (like those containing "invoice" or "payment") to an external address. Learn more about how to stop unauthorized email forwarding rules.
- Missing emails: The user notices that important emails have disappeared, often because the attacker has deleted them to hide their tracks.
- Changes to email signatures or settings: An attacker might alter a user's signature to include a different phone number.
For a complete list of indicators, see our guide on the signs your business email has been hacked.
What Are the First Steps to Take After an Email Compromise?
Once you suspect or confirm a compromise, you need to take immediate containment actions. The goal is to lock the attacker out and prevent further damage. These are the absolute first steps you should take.
- Do Not Delete Anything: Deleting accounts or mailboxes destroys evidence needed for a forensic investigation.
- Reset the User's Password: Immediately reset the password for the compromised account.
- Revoke Active Sessions: A password reset alone is not enough. You must forcibly sign the attacker out of all active sessions. In Microsoft 365, this is done via the "Revoke all sessions" option in the user's account settings. In Google Workspace, you can reset the user's sign-in cookies.
- Review and Remove Malicious Inbox Rules: Check for any new or suspicious inbox rules in the user's mailbox and remove them. These are a primary tool attackers use to maintain access and monitor communications.
For a detailed emergency checklist, read our article: My Business Email Was Hacked: What Do I Do First?
How Do You Clean Up a Hacked Microsoft 365 or Google Workspace Account?
After initial containment, a deeper cleanup is required to fully eradicate the attacker from your environment. Attackers often leave behind backdoors to regain access later. Simply resetting a password is not enough.
A thorough cleanup involves a multi-point inspection of the affected account and your tenant-level settings. This is a critical phase where mistakes can allow the attacker to persist.
Key eradication and cleanup steps include:
- Securing the Account: After the initial password reset and session revocation, ensure Multi-Factor Authentication (MFA) is enabled and configured correctly for the user. Review and remove any unfamiliar MFA methods the attacker may have registered.
- Auditing Mailbox Activities: Scour the Unified Audit Log in Microsoft 365 or the Audit Log in Google Workspace for suspicious activities. Look for actions like creating forwarding rules, accessing sensitive files, or sending emails. This helps scope the incident. Our email compromise cleanup checklist provides a detailed workflow.
- Inspecting for Hidden Persistence: Attackers can grant themselves permissions to other mailboxes, create new user accounts, or elevate privileges on applications. A full investigation must check for these less-obvious persistence mechanisms.
- Checking Other Connected Systems: Determine what other applications the compromised account had access to (e.g., SharePoint, Teams, financial portals, HR systems) and check for unauthorized activity there.
For platform-specific guidance, see our articles on Microsoft 365 account takeover recovery and what to do when a Google Workspace account is compromised.
What If We Sent Money to the Attackers?
If the business email compromise resulted in fraudulent financial transfers, time is of the essence. Recovery is not guaranteed, but swift action can increase your chances.
- Contact Your Bank Immediately: Call your financial institution's fraud department. Ask them to initiate a SWIFT recall for wire transfers or an ACH reversal for ACH payments. Provide them with all transaction details.
- Report to the FBI: File a complaint with the FBI's Internet Crime Complaint Center (IC3) at ic3.gov. The FBI’s Recovery Asset Team (RAT) has had success freezing and recovering funds, but only if you report the fraud quickly, typically within 72 hours.
- Notify the Recipient Bank: Your bank should do this, but you or your attorney can also contact the fraud department of the beneficiary bank that received the stolen funds.
This process, often called a "kill chain" for financial fraud, is time-sensitive. For more details, read our guide on responding to wire fraud after an email hack.
When Is Outside Incident Response Help Warranted?
A business email compromise can quickly become too complex for an internal IT team to handle alone. The investigation requires specialized forensic skills, and a mishandled response can lead to greater financial loss, regulatory fines, and legal liability.
Consider engaging an external incident response firm like Lyra Recovery when:
- You have lost money: Financial fraud requires a rapid, experienced response to maximize the chance of recovery.
- You aren't sure how the attacker got in: If the initial point of entry is unclear, the attacker may still have access. Learn more about how business email compromise happens.
- You suspect the attacker is still in your environment: If you see continued suspicious activity after a password reset, you need expert help to hunt down and remove the threat actor.
- You handle sensitive data: If the compromised account had access to PII, PHI, or other regulated data, a forensic investigation is necessary to determine if a data breach occurred. This has significant legal and regulatory implications.
- Your cyber insurance carrier requires it: Most policies require you to engage a pre-approved incident response vendor to manage the investigation and recovery.
- Your team is overwhelmed: Incident response is a full-time job. Your team needs to focus on running the business, not learning forensic investigation on the fly.
An experienced firm provides the technical expertise to conduct a thorough investigation and the strategic guidance to manage the entire crisis, from financial recovery to legal and regulatory compliance. You can see our structured approach in our BEC incident response playbook.
How Do You Investigate a Business Email Compromise?
An investigation seeks to answer key questions: who, what, when, where, and how. It goes beyond cleanup to determine the full scope and impact of the incident. This is essential for preventing re-entry, meeting legal obligations, and satisfying cyber insurance requirements.
An investigation typically involves:
- Evidence Preservation: Securing logs (sign-in, audit, email gateway) and a forensic image of the mailbox before they are overwritten or deleted.
- Log Analysis: A forensic analyst reviews logs from Microsoft 365, Google Workspace, firewalls, and other sources to trace the attacker's activity from initial access to final action.
- Data Exfiltration Analysis: The investigation determines what emails and files the attacker accessed or downloaded. This helps answer the crucial question: can a hacked email lead to a data breach? This analysis often involves using tools like Microsoft Purview eDiscovery to search for indicators of data theft.
- Root Cause Analysis: Identifying the security weakness that allowed the compromise to happen, such as a phishing email or the lack of MFA.
- Reporting: Compiling a detailed report that documents the incident timeline, scope of access, and recommended remediation steps. This report is often required by insurance carriers and regulators.
Do I Have to Report a Business Email Compromise?
Whether you are legally required to report a BEC incident is a complex question. The answer depends on your jurisdiction, industry, the type of data involved, and your contractual obligations.
- Data Breach Notification Laws: If the attacker accessed personally identifiable information (PII) or protected health information (PHI), data breach notification laws in states like California (CCPA/CPRA) or Europe (GDPR) may require you to notify affected individuals and regulatory bodies. Our firm can work with your legal counsel to navigate these email breach notification requirements.
- Cyber Insurance Policies: Most cyber insurance policies have strict reporting requirements. You must notify your carrier within a specific timeframe (often 24-72 hours) to preserve your right to coverage. Review the cyber insurance requirements after an email breach.
- Contractual Obligations: Your contracts with customers or partners may require you to notify them in the event of a security incident.
Always consult with legal counsel to determine your specific obligations. For a general overview, see our guide: Do I have to report a business email compromise?
Frequently Asked Questions
How long does it take to recover from BEC?
Recovery time varies. Initial containment might take a few hours, but a full investigation and remediation can take days or weeks, depending on the incident's complexity. For a deeper look, see our article on how long it takes to recover from BEC.
What's the difference between email spoofing and compromise?
Email spoofing vs. email compromise is a key distinction. Spoofing is when an attacker fakes the "From" address to look like it came from you. Compromise is when they have actually logged into your real mailbox and are sending emails from it. Compromise is far more dangerous.
How can we prevent this from happening again?
The best prevention is layered security. This includes mandatory MFA for email security, robust cybersecurity awareness and phishing training for employees, and technical controls like Conditional Access policies. Implementing a managed detection and response service can also provide 24/7 monitoring.
How do attackers get the password in the first place?
Most often, it's through a phishing email that leads to BEC. An employee receives a convincing email, clicks a link to a fake login page, and enters their credentials. Attackers may also purchase credentials from the dark web, which is why dark web credential monitoring is a valuable proactive service.
Responding to a business email compromise is a high-stakes, complex process. Following a structured plan and engaging expert help when needed is the surest way to minimize the damage and secure your organization for the future. If you are dealing with a BEC incident and need immediate assistance, fill out our recovery intake form to engage our 24/7 response team.