Business Email Compromise (BEC) Recovery
BEC email compromise recovery for European firms: lock the attacker out, trace the fraud, close hidden forwarding rules and meet GDPR duties. 24/7.
Fast BEC email compromise recovery locks the attacker out of your mailboxes, traces what they saw and sent, and closes the hidden rules they left to keep reading your mail. If a fraudulent invoice just went out under your name or a payment was redirected, our European response team can contain the account, preserve the evidence and help you limit the loss.
Business email compromise is quiet by design. There is no ransom note and nothing looks broken, which is exactly why it works. An attacker sits inside a mailbox, watches how your finance team talks to suppliers, and then slips in at the right moment with a convincing request to change bank details. By the time anyone notices, money has often already moved. Recovery is a race to cut access, understand the exposure and stop the next payment.
What BEC recovery covers
Recovering from an email compromise is part account cleanup, part fraud investigation, and part fast communication with the people the attacker was impersonating. The technical work is to eject the intruder and find every foothold; the business work is to stop payments in flight and warn the counterparties being targeted in your name.
How business email compromise usually happens
Most cases we handle start with stolen credentials, not clever malware. The attacker gets a working username and password and simply logs in, which is why it slides past defences built to catch viruses. Knowing the entry route tells you both how to close it and how far to look.
Phishing and credential theft
A convincing fake login page harvests the password, often defeating any sense of “we would never fall for that” because the page is a pixel-perfect copy of your real sign-in. Once the attacker has the password, the mailbox is open unless multi-factor authentication stands in the way.
Password reuse and stuffing
A password leaked from an unrelated breach gets tried against your email, and if a staff member reused it, the attacker walks straight in. This is why a single reused password on a personal site can end up costing a company a five-figure invoice fraud.
Getting around weak MFA
Where multi-factor authentication exists but is weak, attackers use real-time phishing kits that relay the code, or wear the victim down with repeated push prompts until they approve one out of fatigue. Part of recovery is closing that gap, not just resetting the password the attacker already used.
Our BEC recovery process, phase by phase
We run every email compromise through the same sequence, because the attacker’s persistence is easy to miss if you only reset the obvious password and move on.
Triage
We confirm the compromise, identify which accounts are affected, and check whether money is currently in motion. If a fraudulent payment is in flight, that becomes the first priority alongside containment, because a bank recall has a short window.
Contain
We force a password reset, revoke every active session and token so the attacker’s logged-in browser dies, and enforce strong multi-factor authentication. Resetting the password alone is not enough, because an existing session or an app token can keep the attacker inside after the password changes.
Eradicate
We hunt for everything the attacker set up to stay in and stay hidden. That means malicious inbox rules that auto-delete or forward mail, secret forwarding addresses, added mailbox delegates, rogue OAuth application grants, and enrolled devices. These are the mechanisms that let an attacker keep reading your mail long after you think you have kicked them out.
The hidden forwarding trick
A common move is a rule that quietly forwards a copy of every incoming message to an outside address, or one that deletes replies containing words like “invoice” or “payment” so the victim never sees the counterparty’s questions. We find and remove these, then check the audit logs to see how long they were running.
Recover
We restore normal, secure access for the legitimate user, verify the mailbox is clean, and work with you on communicating with affected suppliers or customers. Where a fraudulent message went out under your name, a prompt, honest correction to the recipients often prevents a second victim.
Harden
We close the door properly: enforced phishing-resistant MFA, tightened mail-flow rules, blocked legacy authentication protocols that skip MFA, and alerting on suspicious inbox-rule changes. We also review the wider tenant, because an attacker who reached one mailbox often tried the others.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Following the money and the fraud
The mailbox is the crime scene, but the loss usually happens in the payments. A thorough recovery follows both.
Fraudulent invoices and payment redirection
We trace the messages the attacker sent, the invoices they altered or forged, and any request to change supplier bank details. If a payment has already gone out, speed matters, and we help you push your bank for a recall while the funds may still be reachable.
Warning the people impersonated
BEC often uses your mailbox to defraud your customers and suppliers, not you directly. Identifying who the attacker contacted, and warning them quickly, stops your compromise turning into their loss and protects the relationship.
Preserving evidence for the bank and police
We preserve the mailbox audit logs, the malicious rules and the fraudulent messages to a standard that supports a bank dispute, an insurance claim or a police report. Cleaning up carelessly can destroy exactly the evidence you need to recover the money.
Why the first hours decide the outcome
Email compromise rewards speed more than almost any other incident, because two clocks are running at once. One is the attacker still reading your mail and setting up the next fraud. The other is the payment sitting in a bank’s system, recoverable for a short window and gone after it.
Every hour is another read mailbox
While the attacker retains access they see your replies, learn your processes, and refine the con. Cutting access quickly does not just stop the current fraud, it denies them the intelligence to run a better one next week.
The bank recall window is short
If money has moved to a mule account, the funds are often withdrawn or moved on within hours. A fast, evidenced request to your bank, with the fraudulent messages preserved, gives you the best chance of a recall before the trail goes cold.
What you receive
You come out of the incident with a clean tenant and a record you can act on, not just a reassurance that it is handled.
An incident and exposure report
A written account of how the attacker got in, what they could access, which rules and grants they left behind, and what fraudulent messages went out. It supports your GDPR assessment, your insurance claim and any bank dispute.
A hardening plan and free retest
A prioritised list of the changes that close the gap the attacker used, and a free retest once you have applied them so you can confirm the mailbox and the tenant are genuinely locked down.
GDPR duties after an email compromise
Mailboxes are full of personal data, which means a BEC is often a personal data breach as well as a fraud. If the attacker could read messages containing customer, employee or supplier personal data, you have to assess your notification duties, not just fix the account.
The Article 33 assessment
Under GDPR Article 33, a breach likely to risk people’s rights must be notified to the supervisory authority within 72 hours of you becoming aware of it. A compromised mailbox that held personal correspondence, attachments or contact data will often meet that bar. We establish what the attacker could actually access, and over what period, so your data protection officer can make the call on solid facts.
Telling the affected people
Where the exposure is likely to be high risk to individuals, Article 34 may require you to tell them directly. This matters especially when the mailbox held sensitive data or when the attacker used it to target the very people whose data was inside. We provide the technical scope; your counsel decides the response.
Pricing
Email compromise recovery is priced by how many accounts are involved and how deep the fraud investigation needs to go. Here is the shape of a typical European engagement.
| Package | What’s included | Response time | Price |
|---|---|---|---|
| Single-account recovery | Lockout, session revocation, rule and forwarding cleanup and hardening for one compromised mailbox | Same day | from €450 |
| Rapid BEC response | Multi-account or active-fraud incident: containment, forensic timeline and payment-tracing support | Same day, 24/7 | from €900 |
| Forensic investigation (hourly) | Deep audit-log analysis, tenant-wide review and evidence preservation for disputes or claims | Started within hours | from €180/hr |
| Email security retainer | Priority response under an SLA, plus monitoring and periodic tenant hardening reviews | Guaranteed by SLA | from €800/month |
| Resilience & response planning | MFA rollout, mail-flow hardening and a BEC response runbook, built before an incident | Scheduled | from €1,200 |
| Custom / large tenant | Broad compromises or complex fraud across many accounts, scoped to your situation | On scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a hardening retest included. Start emergency response
FAQ
How did the attacker get into our email?
The password’s been changed, are we safe now?
Can we get the money back if a payment was redirected?
How much does BEC email compromise recovery cost?
Do we have to notify anyone under GDPR?
Should we warn our suppliers and customers?
How do you stop it happening again?
Does this work with Microsoft 365 and Google Workspace?
Related services
European businesses that have spotted a hijacked mailbox, a fraudulent invoice sent in their name, or a redirected payment, and need the attacker locked out, the fraud traced and their GDPR duties assessed before the loss grows.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.