Home/Services/Business Email Compromise (BEC) Recovery
security service

Business Email Compromise (BEC) Recovery

BEC email compromise recovery for European firms: lock the attacker out, trace the fraud, close hidden forwarding rules and meet GDPR duties. 24/7.

Manual, expert-ledEvidence-based findingsFree remediation retest

Fast BEC email compromise recovery locks the attacker out of your mailboxes, traces what they saw and sent, and closes the hidden rules they left to keep reading your mail. If a fraudulent invoice just went out under your name or a payment was redirected, our European response team can contain the account, preserve the evidence and help you limit the loss.

Business email compromise is quiet by design. There is no ransom note and nothing looks broken, which is exactly why it works. An attacker sits inside a mailbox, watches how your finance team talks to suppliers, and then slips in at the right moment with a convincing request to change bank details. By the time anyone notices, money has often already moved. Recovery is a race to cut access, understand the exposure and stop the next payment.

What BEC recovery covers

Recovering from an email compromise is part account cleanup, part fraud investigation, and part fast communication with the people the attacker was impersonating. The technical work is to eject the intruder and find every foothold; the business work is to stop payments in flight and warn the counterparties being targeted in your name.

Immediate lockout: forced password reset, revoked sessions and enforced MFA
Hunting and removing malicious inbox rules, forwarding and delegate access
A forensic timeline of what the attacker read, sent and deleted
Tracing fraudulent invoices and redirected-payment attempts
Reviewing OAuth app grants and connected devices the attacker added
GDPR exposure assessment for any personal data in the compromised mailboxes

How business email compromise usually happens

Most cases we handle start with stolen credentials, not clever malware. The attacker gets a working username and password and simply logs in, which is why it slides past defences built to catch viruses. Knowing the entry route tells you both how to close it and how far to look.

Phishing and credential theft

A convincing fake login page harvests the password, often defeating any sense of “we would never fall for that” because the page is a pixel-perfect copy of your real sign-in. Once the attacker has the password, the mailbox is open unless multi-factor authentication stands in the way.

Password reuse and stuffing

A password leaked from an unrelated breach gets tried against your email, and if a staff member reused it, the attacker walks straight in. This is why a single reused password on a personal site can end up costing a company a five-figure invoice fraud.

Getting around weak MFA

Where multi-factor authentication exists but is weak, attackers use real-time phishing kits that relay the code, or wear the victim down with repeated push prompts until they approve one out of fatigue. Part of recovery is closing that gap, not just resetting the password the attacker already used.

Our BEC recovery process, phase by phase

We run every email compromise through the same sequence, because the attacker’s persistence is easy to miss if you only reset the obvious password and move on.

Triage

We confirm the compromise, identify which accounts are affected, and check whether money is currently in motion. If a fraudulent payment is in flight, that becomes the first priority alongside containment, because a bank recall has a short window.

Contain

We force a password reset, revoke every active session and token so the attacker’s logged-in browser dies, and enforce strong multi-factor authentication. Resetting the password alone is not enough, because an existing session or an app token can keep the attacker inside after the password changes.

Eradicate

We hunt for everything the attacker set up to stay in and stay hidden. That means malicious inbox rules that auto-delete or forward mail, secret forwarding addresses, added mailbox delegates, rogue OAuth application grants, and enrolled devices. These are the mechanisms that let an attacker keep reading your mail long after you think you have kicked them out.

The hidden forwarding trick

A common move is a rule that quietly forwards a copy of every incoming message to an outside address, or one that deletes replies containing words like “invoice” or “payment” so the victim never sees the counterparty’s questions. We find and remove these, then check the audit logs to see how long they were running.

Recover

We restore normal, secure access for the legitimate user, verify the mailbox is clean, and work with you on communicating with affected suppliers or customers. Where a fraudulent message went out under your name, a prompt, honest correction to the recipients often prevents a second victim.

Harden

We close the door properly: enforced phishing-resistant MFA, tightened mail-flow rules, blocked legacy authentication protocols that skip MFA, and alerting on suspicious inbox-rule changes. We also review the wider tenant, because an attacker who reached one mailbox often tried the others.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Following the money and the fraud

The mailbox is the crime scene, but the loss usually happens in the payments. A thorough recovery follows both.

Fraudulent invoices and payment redirection

We trace the messages the attacker sent, the invoices they altered or forged, and any request to change supplier bank details. If a payment has already gone out, speed matters, and we help you push your bank for a recall while the funds may still be reachable.

Warning the people impersonated

BEC often uses your mailbox to defraud your customers and suppliers, not you directly. Identifying who the attacker contacted, and warning them quickly, stops your compromise turning into their loss and protects the relationship.

Preserving evidence for the bank and police

We preserve the mailbox audit logs, the malicious rules and the fraudulent messages to a standard that supports a bank dispute, an insurance claim or a police report. Cleaning up carelessly can destroy exactly the evidence you need to recover the money.

Why the first hours decide the outcome

Email compromise rewards speed more than almost any other incident, because two clocks are running at once. One is the attacker still reading your mail and setting up the next fraud. The other is the payment sitting in a bank’s system, recoverable for a short window and gone after it.

Every hour is another read mailbox

While the attacker retains access they see your replies, learn your processes, and refine the con. Cutting access quickly does not just stop the current fraud, it denies them the intelligence to run a better one next week.

The bank recall window is short

If money has moved to a mule account, the funds are often withdrawn or moved on within hours. A fast, evidenced request to your bank, with the fraudulent messages preserved, gives you the best chance of a recall before the trail goes cold.

What you receive

You come out of the incident with a clean tenant and a record you can act on, not just a reassurance that it is handled.

An incident and exposure report

A written account of how the attacker got in, what they could access, which rules and grants they left behind, and what fraudulent messages went out. It supports your GDPR assessment, your insurance claim and any bank dispute.

A hardening plan and free retest

A prioritised list of the changes that close the gap the attacker used, and a free retest once you have applied them so you can confirm the mailbox and the tenant are genuinely locked down.

GDPR duties after an email compromise

Mailboxes are full of personal data, which means a BEC is often a personal data breach as well as a fraud. If the attacker could read messages containing customer, employee or supplier personal data, you have to assess your notification duties, not just fix the account.

The Article 33 assessment

Under GDPR Article 33, a breach likely to risk people’s rights must be notified to the supervisory authority within 72 hours of you becoming aware of it. A compromised mailbox that held personal correspondence, attachments or contact data will often meet that bar. We establish what the attacker could actually access, and over what period, so your data protection officer can make the call on solid facts.

Telling the affected people

Where the exposure is likely to be high risk to individuals, Article 34 may require you to tell them directly. This matters especially when the mailbox held sensitive data or when the attacker used it to target the very people whose data was inside. We provide the technical scope; your counsel decides the response.

24/7
emergency lockout, any hour
100%
hidden rules and grants hunted, not guessed
72h
the GDPR clock we help you meet

Pricing

Email compromise recovery is priced by how many accounts are involved and how deep the fraud investigation needs to go. Here is the shape of a typical European engagement.

Package What’s included Response time Price
Single-account recovery Lockout, session revocation, rule and forwarding cleanup and hardening for one compromised mailbox Same day from €450
Rapid BEC response Multi-account or active-fraud incident: containment, forensic timeline and payment-tracing support Same day, 24/7 from €900
Forensic investigation (hourly) Deep audit-log analysis, tenant-wide review and evidence preservation for disputes or claims Started within hours from €180/hr
Email security retainer Priority response under an SLA, plus monitoring and periodic tenant hardening reviews Guaranteed by SLA from €800/month
Resilience & response planning MFA rollout, mail-flow hardening and a BEC response runbook, built before an incident Scheduled from €1,200
Custom / large tenant Broad compromises or complex fraud across many accounts, scoped to your situation On scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a hardening retest included. Start emergency response

FAQ

How did the attacker get into our email?
Almost always with a working password rather than malware, taken through a phishing page, a reused password from another breach, or by defeating weak multi-factor authentication. We confirm the exact route from the sign-in and audit logs so you close it instead of guessing.
The password’s been changed, are we safe now?
Not necessarily. An attacker can stay in through an active session, an app token, a mailbox delegate or a hidden forwarding rule even after the password changes. Real BEC email compromise recovery means revoking sessions and tokens and hunting down every one of those footholds.
Can we get the money back if a payment was redirected?
Sometimes, if you move fast. We help you preserve the evidence and push your bank for a recall while the funds may still be reachable, and we support your insurance claim and police report. The sooner the fraud is spotted, the better the odds.
How much does BEC email compromise recovery cost?
Recovering a single mailbox starts from €450, and a multi-account incident with active fraud from €900, with deeper forensic work from €180 an hour. You get a fixed quote after a free scoping call.
Do we have to notify anyone under GDPR?
Often, yes. A compromised mailbox usually holds personal data, so if the attacker could read it you may have a reportable breach under Article 33, with its 72-hour deadline. We establish exactly what was accessible so your data protection officer can decide on facts.
Should we warn our suppliers and customers?
Usually yes, and quickly. BEC frequently uses your mailbox to defraud the people you correspond with, so identifying who the attacker contacted and warning them stops your incident becoming their loss and protects the relationship.
How do you stop it happening again?
We enforce phishing-resistant multi-factor authentication, block legacy protocols that bypass MFA, tighten mail-flow rules, and set up alerting on suspicious inbox-rule changes. We also review the rest of the tenant, since an attacker in one mailbox usually tried the others.
Does this work with Microsoft 365 and Google Workspace?
Yes. We recover compromised accounts on both, using their audit and sign-in logs to trace access and their admin controls to lock the attacker out and harden the tenant. The approach is the same even though the buttons differ.

Related services

Who needs this

European businesses that have spotted a hijacked mailbox, a fraudulent invoice sent in their name, or a redirected payment, and need the attacker locked out, the fraud traced and their GDPR duties assessed before the loss grows.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Business Email Compromise (BEC) Recovery"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.