24 / 7 Business Email Compromise Response

Your business email is compromised. We can be on a call in minutes.

Hijacked mailboxes, fraudulent wire instructions, hidden forwarding rules, Microsoft 365 and Google Workspace account takeover. Send us the details and an incident commander responds fast, day or night — containment starts right away.

Request Help

Send us the details.

We respond fast — 24/7/365.

First Hour

What to do if your business email is hacked.

Work these in order. If you only have time for one thing, send us the details — we will run them with you while your team keeps the business moving.

  1. 1

    Reset the password and kill every session

    A password reset alone does not evict an attacker holding a valid session token or app password. Revoke sessions and refresh tokens, and reset any app passwords tied to the mailbox.

  2. 2

    Hunt hidden forwarding and inbox rules

    Almost every BEC includes a rule that silently forwards, moves, or deletes messages so you never see the fraudulent thread. Check mailbox rules, forwarding settings, and any connected third-party apps.

  3. 3

    Call your bank before you call anyone else about money

    If an invoice, wire, or payroll change was discussed in that mailbox, treat funds as at risk right now. Fast recall requests and a Financial Fraud Kill Chain filing are time-sensitive — hours matter.

  4. 4

    Preserve the evidence — do not clean up first

    Sign-in logs, audit logs, and message trace data age out. Export and preserve them before remediation, or you lose the ability to prove what was and was not accessed.

  5. 5

    Enforce MFA and close the front door

    Legacy authentication, unmanaged devices, and MFA gaps are how the attacker got in. Containment is not finished until that entry path is closed tenant-wide, not just on one account.

  6. 6

    Scope it properly, then decide on notification

    Which mailboxes were reached, what data sat inside them, and which regulators, customers, and insurers need to hear about it. This is where BEC becomes a legal question, not just an IT one.

Am I Compromised?

Signs your business email has been taken over.

Any one of these is enough to pick up the phone. Attackers usually sit quietly in a mailbox for weeks, reading threads and waiting for an invoice worth stealing.

  • Contacts report replies you never sent, or messages from a lookalike domain
  • Sent items or deleted items contain mail you do not recognize
  • An inbox rule, forward, or filter you did not create
  • Sign-ins from unfamiliar countries, IPs, or unmanaged devices
  • A vendor or customer says your banking details changed
  • MFA prompts arriving when nobody is signing in

What We Do

BEC, EAC, and vendor email compromise — handled end to end.

Questions We Get Mid-Incident

Who do I call when my email is compromised?

Call incident responders who can act inside your Microsoft 365 or Google Workspace tenant immediately, then your bank if any payment was in play, then your cyber insurance carrier or broker. We work alongside carriers, brokers, and breach counsel every week and can join the same call.

How long does it take to recover from BEC?

Containing one mailbox is usually hours. Forensic scoping, cleanup, and notification decisions generally run a few days to two weeks, depending on how many accounts were touched and whether money moved.

Can a hacked email lead to a data breach?

Yes — a mailbox is a filing cabinet. Personal, health, and financial data sits in messages and attachments, and mailbox access alone can trigger notification duties in many jurisdictions.

Do I have to report a business email compromise?

Often, yes. It depends on the data in the mailbox, your state and sector regulations, your contracts, and your insurance policy conditions. We document what was accessed so counsel can make that call on facts rather than guesses.

What is the difference between BEC, EAC, and VEC?

Business email compromise is the broad fraud category. Email account compromise means an attacker is actually inside a mailbox. Vendor email compromise means the compromised mailbox belongs to your supplier, and the fraudulent invoice arrives from a real, trusted address.

More depth in our incident response writing, or see the full recovery intake if an engagement is already underway.

Tell us what's happening. We'll take it from there.

Submit the form and our team is notified immediately — we follow up fast, day or night. Prefer to talk it through? Call 1-844-LYRA-REC.

Or email help@lyrarecovery.com directly.

24 / 7 Recovery

When the worst day hits, every minute matters.

Our breach team is standing by — call, email, or submit a request and we respond within minutes.