CONTACT US

Business email compromise case study

[Oct 06, 2026]

•

Rexxfield

•

•

A person holds a smartphone displaying an incoming call from an unknown caller, with green and red buttons to accept or decline the call, in a dimly lit setting.

Business email compromise case study: a bank flagged a fraudulent payment at a construction and property services company, and the company brought in Rexxfield to investigate. Business email compromise is costly and common. The FBI’s IC3 received reports of more than $3 billion in BEC losses in 2025, most of it moved by wire or ACH transfer. Here, weeks of unauthorized email access sat behind two fraud campaigns that were more connected than they first appeared.

The attacker had access to the controller’s mailbox. Genuine contacts were being blocked, impersonators were still getting through, and a few suspicious addresses were quietly receiving emails without sending any.

Our work went on to include forensic analysis, identification of two additional accounts and a password and session reset across the company. Follow-up monitoring and verification detected no further compromises. Here’s how the investigation in this business email compromise case study unfolded.

This case has been anonymized. Names, domains, banks, account numbers and financial figures have been fictionalized or rounded. The sequence of events and investigative findings reflect the real case.

The payment was only the beginning

By the time we examined the evidence, the attacker had maintained access to the controller’s email account for several weeks. Two impersonation campaigns were running alongside each other:

  • A dividend distribution scheme, using a lookalike domain to imitate a genuine business conversation.
  • An invoice fraud scheme, impersonating the company’s materials vendor and introducing fraudulent bank details.

At first, neither the company nor our investigators knew the campaigns were linked. We needed to establish when the compromise began, what had happened inside the account and which payment conversations were affected.

Plenty of records, but no ready-made explanation

We had Google Workspace security logs, a full mailbox export and message logs covering five domains. The records did not arrive labelled with what had happened.

Our team mapped the sign-ins, email threads, genuine contacts, lookalike domains and bank accounts against a shared timeline. That let us follow a suspicious payment request back through the conversation and compare it with activity inside the mailbox. It also helped us spot connections that were easy to miss when each email thread was read on its own.

How the two campaigns unfolded

We used the first confirmed unauthorized access as day zero. From there, the sequence became much clearer:

  • Day 0, first unauthorized access: A sign-in from a previously unseen network triggered an alert, yet passed the account’s two-factor approval prompt. How that approval was obtained is not known.
  • Day 30, another suspicious sign-in: A second sign-in followed the same pattern.
  • Day 37, the dividend thread was hijacked: Within three hours of a genuine dividend distribution email, a lookalike domain using visually similar characters appeared in a parallel fraudulent conversation.
  • Day 44, the invoice thread followed: The morning after a genuine vendor estimate arrived, a domain differing by one letter from the real vendor’s domain hijacked the invoice thread. It introduced the first of three fraudulent bank account instructions.
Timeline of the business email compromise case study, from the first unauthorized sign-in to the hijacked invoice thread
Key events in the compromise, counted from the first confirmed unauthorized access.

Both campaigns led back to the same compromised controller mailbox. What had looked like separate impersonation attempts was part of a wider email compromise. This kind of email thread hijacking is easy to miss because the fraudulent messages arrive inside a conversation the victim already trusts.

The clue hiding in the blocked sender list

One of the strongest clues was tucked away in an account setting most people have little reason to inspect. In the days after the first impersonation domains appeared, someone with access to the mailbox blocked four genuine contacts: the advisor, the executive coach, a professional contact and the materials vendor.

Two details stood out:

  • Every blocking action came from the same previously unrecognized network.
  • The lookalike domains impersonating those contacts stayed unblocked and continued reaching the controller for several weeks.

Viewed individually, these blocks looked like scattered log entries spread across about two weeks. Mapped together, they showed a pattern: someone was deliberately controlling who could get through. The genuine contacts were being shut out while their impersonators still had a route into the inbox. It helped explain how the fraud could keep going while messages from the real people were being blocked.

The domains that said nothing

Two other lookalike domains had never sent the controller a single message. They were simply copied into fraudulent threads. Being included as recipients allowed those addresses to receive outgoing communications without joining the conversation. The evidence suggested they were being used to monitor exchanges, although it did not establish who was reading them.

Checking who was receiving information, as well as who was sending it, revealed another part of the fraud infrastructure. The evidence linked both campaigns to one mailbox. It did not prove that a single individual operated every domain.

Anonymized investigation graph linking the compromised mailbox, impersonation domains and fraudulent bank accounts
Relationships found between the compromised mailbox, lookalike domains and payment destinations.

What happened to the money

The two payment outcomes were different:

  • Funds transferred: A six-figure payment reached one of the fraudulent accounts. At the time of the original case report, investigators were still working with the client and its bank to trace and recover the funds. Early indications suggested that recovery could be successful, although banking timelines and recovery processes can be unpredictable.
  • Payment stopped: The bank spotted a separate attempt to redirect a smaller invoice payment before it was completed, preventing a loss on that transaction.

Our investigation connected the fraudulent payment instructions and destination accounts to the email activity behind them, providing context for the ongoing work with the client and bank.

Speed matters here: the sooner a bank and the FBI’s IC3 are involved, the better the chance of a recall. Our BEC wire transfer fraud recovery guide explains the first 72 hours in detail.

Closing off access across the company

Once we had a clearer picture of the email compromise, the next job was helping the company regain control of its accounts. The scope extended beyond the controller’s inbox.

  • Forensic work: We helped examine the compromise and identified two additional accounts.
  • Passwords and sessions: We carried out a company-wide password reset and reset all sessions.
  • Follow-up checks: We monitored and verified the environment after the resets. No further compromises were detected during that monitoring.

Beyond two-factor authentication

Both suspicious sign-ins cleared the account’s two-factor authentication prompt. Two-factor authentication remains an important safeguard, but push-based and SMS methods can still be targeted through phishing and social engineering.

Hardware security keys and passkeys offer stronger protection because authentication is tied to the legitimate domain, rather than relying on a user approving a request or entering a code. For finance teams and accounts-payable mailboxes in particular, stronger authentication is a worthwhile extra layer of protection.

What Rexxfield brought to this business email compromise case study

In this business email compromise case study, the revealing details were spread across email conversations, security logs and account settings. Our job was to work out how they fitted together. That is the core of our business email compromise investigations: preserving email trails, reviewing mailbox permissions, forwarding and blocking settings, tracing domains and sign-in activity, and preparing findings that can support the bank, law enforcement or legal action.

In this business email compromise case study, the result for the company was a clearer account of the fraud, two additional accounts identified, passwords and sessions reset across the organization, and no further compromises detected during follow-up monitoring.

Paid an invoice with fraudulent bank details

If this sounds familiar, start with your bank. A full investigation can follow, but the transfer needs attention straight away. For a step-by-step plan, see our 72-hour BEC response guide.

  • Report the payment: Call your bank using its official number. Ask the fraud team to contact the receiving institution and assess whether the payment can be stopped or recalled.
  • Verify the request: Contact the real supplier through a number you already know or have independently checked. Avoid relying on contact details in the suspicious email.
  • Keep the evidence and secure the account: Keep the original emails, attachments and payment records. Have your IT team secure affected accounts promptly and retain available logs alongside that work.

If you recognize this pattern in your own business, treat it as a business email compromise case of your own and act quickly. Report the incident through the appropriate channel too: IC3 in the United States or ReportCyber in Australia. Both the FBI and the Australian Cyber Security Centre advise contacting your bank immediately.

If this business email compromise case study sounds like your situation and you need help working out what happened, contact Rexxfield. We can assess the evidence, investigate the email compromise and discuss options for supporting recovery efforts. Recovery depends on the circumstances and cannot be guaranteed.

Book a free consultation