← All posts

Do I Have To Report a Business Email Compromise?

September 16, 2026

Often yes — and the answer depends on the data in the mailbox, your sector, your contracts, and your insurance policy, not on whether money was lost.

This is the question we get on day two of almost every email compromise, and the honest answer is that it depends on what was in the mailbox — not on whether money moved.

This is general information, not legal advice. Your counsel makes the call.

Five separate duties to check

1. State breach notification law. Every US state requires notice when personal information is accessed without authorization. Definitions, timelines, and thresholds vary, and the rule that applies is generally the one where the affected individual lives — not where you are.

2. Sector regulation. HIPAA for protected health information, with its 60-day individual notice and HHS reporting. Financial services rules including GLBA safeguards and increasingly short incident-reporting windows. DFARS and CMMC obligations, with 72-hour reporting to DoD for covered defense information. SEC materiality disclosure for public companies.

3. Contracts. Customer agreements, DPAs, and vendor contracts frequently impose notification within 24, 48, or 72 hours — often tighter than any statute. This is the duty companies most often miss.

4. Insurance. Nearly every cyber policy requires prompt notice and many require carrier-approved vendors. Late notice or an unapproved forensics firm can reduce or void recovery. See cyber insurance requirements after an email breach.

5. Law enforcement. An IC3 filing is strongly advisable whenever funds moved, and is sometimes required by contract or policy.

Why forensics decides the outcome

Notification usually turns on whether personal information was accessed. Without mailbox audit logging, you often cannot show that it was not — and counsel then has to advise notification on the conservative assumption. Good logging and rapid preservation frequently narrow a company-wide notification down to a handful of individuals, or to none.

That is the single strongest financial argument for turning on mailbox auditing before anything happens, and for calling incident responders before your team starts cleaning up. Start at our BEC response page.


Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.

breach notificationcomplianceBECHIPAA

24 / 7 Recovery

When the worst day hits, every minute matters.

Our breach team is standing by — call, email, or submit a request and we respond within minutes.