Business Email Compromise: What To Do in the First Hour
September 16, 2026
A hijacked mailbox is an active fraud in progress. Here is the exact order of operations for the first hour, from session revocation to bank recall.
Business email compromise is not a malware problem. There is usually nothing to remove from a laptop, no encrypted file share, and no ransom note. Someone is simply signed in as your employee, reading threads and waiting for an invoice worth stealing. That makes the first hour about identity and money, not antivirus.
1. Revoke sessions, not just the password
A password reset on its own does not evict an attacker who already holds a valid session token, an app password, or an OAuth grant. In Microsoft 365 you reset the credential, revoke sessions and refresh tokens, and clear app passwords. In Google Workspace you sign the user out of all sessions and revoke connected application access. If you skip this, the attacker keeps reading mail through the reset.
2. Find the hidden rules
Nearly every email account compromise includes a rule that hides the attacker's work: forward everything to an external address, move anything containing "invoice" or "wire" to RSS Feeds, or delete replies from a specific vendor. Check mailbox rules, forwarding settings, delegate access, and connected third-party apps. Removing the rule is also evidence — screenshot and export it before you delete it.
3. If money was in play, call the bank now
If that mailbox discussed an invoice, wire, payroll change, or ACH detail, treat funds as at risk this minute. Recall requests and an FBI IC3 Financial Fraud Kill Chain filing are dramatically more effective within 24 to 72 hours. Do not wait for the technical investigation to finish before making the call.
4. Preserve logs before you clean up
Sign-in logs, unified audit logs, and message trace data have retention limits, and remediation overwrites state. Export them first. Without that record you cannot later prove which mailboxes were reached — and that is exactly what counsel, your carrier, and regulators will ask.
5. Close the entry path tenant-wide
The attacker got in through a gap: legacy authentication, an MFA exclusion, a token-stealing phishing page, or a device nobody manages. Containment is not finished when one account is clean. It is finished when the same technique fails across the tenant.
6. Scope, then decide on notification
Which accounts were touched, what data sat inside them, and who has to be told. Mailbox access alone can trigger notification duties, so this becomes a legal question quickly. See reporting obligations after a business email compromise for how that decision usually goes.
If your internal team is doing this for the first time while the phone rings with angry customers, hand it to people who do it weekly. Our managed detection and response team runs this sequence on live tenants every week.
Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.