All Services

Business Email Compromise Response

Your clients are getting emails from your address that you did not send. Invoices with the wrong bank details. Replies inside real conversations. Somebody is in the mailbox, and every hour they stay there costs you a customer relationship.

Emergency response for compromised business email across Dallas, Fort Worth, Arlington and the DFW metroplex. We lock the attacker out, work out exactly what they saw and sent, and help you tell your clients.

What To Do In The First Hour

In this order. The most common mistake is changing the password and assuming it is over — it is not, because the attacker usually keeps access through a mail rule or a connected app that survives a password reset.

  1. Reset the password and revoke active sessions. A reset alone leaves an already-signed-in attacker logged in.
  2. Check for mail forwarding and inbox rules. Look for rules that move or delete messages containing "invoice", "payment", "wire" or "bank" — that is how they hide the replies from you.
  3. Review connected apps and mailbox delegates. An app consent or delegated access grant keeps working after a password change.
  4. Turn on MFA if it is not on, and re-register it if it is. Attackers frequently enrol their own device.
  5. Do not delete the evidence. Keep the rules, the sent items and the sign-in logs — they are what establish scope, and Microsoft 365 audit retention is finite.
  6. Warn anyone who might be paid today. A single phone call to your bookkeeper or biggest client often stops the actual loss.

If money has already moved, contact your bank immediately and ask for a recall — same-day action is what determines whether wire fraud is recoverable. Then call us on 512-518-4408.

What Is Actually Happening

Business email compromise is not a virus and it is not a mass phishing blast. Somebody is reading your mail, learning how your business talks, and then joining a conversation already in progress. That is why it works on people who would never fall for a generic scam.

Thread hijacking

The attacker replies inside a genuine email chain your client already trusts. Same subject line, same history, correct names. Nothing looks unusual because almost nothing is.

Invoice and payment redirection

Your real invoice is intercepted and re-sent with changed bank details, often days later and timed to when payment was already expected.

Hidden inbox rules

Rules quietly file or delete the replies so you never see the confused messages from your client asking about the new account number.

Lookalike domains

Once inside, they register a near-identical domain and move the conversation there, so the fraud continues even after you secure the real mailbox.

MFA that did not stop it

Session-token theft and adversary-in-the-middle phishing bypass multi-factor entirely. Having MFA on does not mean the account was not taken.

The quiet period first

Most attackers read for days or weeks before sending anything. By the time you notice, they already understand your clients, your terms and your signature style.

What We Do

Three things happen in parallel, because the business problem and the technical problem are on different clocks. Your clients need an answer today; the investigation takes longer than that.

  • Lock them out properly. Sessions revoked, tokens invalidated, rogue rules and delegates removed, malicious app consents pulled, MFA re-established on a device you control.
  • Establish what they actually reached. Sign-in history, mailbox audit logs, what was read, what was sent, what was downloaded, and whether they moved from email into file storage or other accounts.
  • Find every message they sent as you. Including the ones deleted from Sent Items, so you know exactly which clients were contacted and what they were told.
  • Check for the lookalike domain. If one was registered, the fraud continues after the mailbox is clean unless it is found and reported.
  • Help you tell your clients. Wording that is accurate and does not overstate, which matters when a customer later asks what you knew and when.
  • Close the entry point. The specific gap, not a generic hardening list.

Our Response Commitments

<15min

To an analyst call with confirmed findings and containment steps — not a ticket acknowledgement.

30–60min

Containment action on a confirmed active compromise, at any hour.

2 hours

Guaranteed response for incident response retainer clients, with a named engineer.

You do not need an existing contract to call. Most BEC engagements start with a business that has never spoken to us before, on the day it happens.

This Is Not The Same As Email Security

Most providers sell email filtering, which is prevention — it tries to stop the phishing message arriving. Useful, and we sell it too. But once someone is already inside the mailbox, filtering has nothing left to do. The attacker is now sending mail from your account, so it never passes through an inbound filter at all, and it authenticates perfectly because it genuinely is you.

Before — prevention

Filtering, impersonation protection, SPF/DKIM/DMARC, staff training, MFA hardening.

Email security →

After — response

Eviction, scope determination, sent-message reconstruction, client notification, root cause. This page.

You are here

If the compromise reached beyond email — file storage, the finance system, other accounts — that becomes a broader digital forensics engagement, and if systems need isolating it escalates to incident response.

Email Compromise Response Across Dallas-Fort Worth

We are based in McKinney and handle email compromise cases across Dallas, Fort Worth, Arlington, Plano, Frisco and the surrounding metroplex. Most of this work is done remotely and starts within the hour, because mailbox evidence is in the cloud and waiting for someone to drive out costs you the window that matters.

The businesses this hits hardest in North Texas are the ones that send invoices: construction and trades, professional services, medical billing, wholesale suppliers, title and escrow, and anyone whose clients are used to receiving payment instructions by email. It is rarely a technology failure at heart — it is that your email is how money moves, and somebody worked that out.

Related reading: the first 48 hours of a compromised Microsoft 365 mailbox, how wire fraud actually unfolds, and how attackers get past multi-factor authentication.

Frequently Asked Questions

Emails are going to my clients from my address right now. What do I do first?

Reset the password and revoke all active sessions, not just the password — a reset on its own leaves an attacker who is already signed in exactly where they are. Then check for inbox rules and mail forwarding, because that is how they hide your clients' replies from you, and review connected apps and mailbox delegates, which survive a password change. Warn anyone who might pay an invoice today; one phone call often prevents the actual loss. Keep the rules and sent items rather than deleting them, since that is the evidence that establishes what happened. Then call us on 512-518-4408.

We had MFA turned on. How did this happen?

Multi-factor authentication stops password reuse and simple phishing; it does not stop session-token theft or adversary-in-the-middle attacks, where a convincing sign-in page relays your credentials and your MFA approval to the attacker in real time and hands them a valid session. From that point they are inside without ever needing your password again. Attackers also commonly enrol their own device for MFA once in, which is why re-registering multi-factor on a device you control is part of eviction rather than an optional extra.

Can you tell which of my clients were emailed?

Usually yes, and it is normally the first thing clients want. We reconstruct the sent activity from mailbox audit logs and message traces rather than relying on the Sent Items folder, because attackers routinely delete from Sent to stay hidden — which means the folder understates what went out. That reconstruction gives you a defensible list of who was contacted and what they received, which is what turns a panicked blanket apology into a targeted, credible notification.

A client already paid the fraudulent invoice. Can the money be recovered?

Sometimes, and speed is almost the only variable you control. Contact the bank immediately and ask for a recall or to initiate the fraud process; domestic wires identified within hours are recoverable far more often than ones discovered days later, and the FBI's IC3 operates a Recovery Asset Team for qualifying cases. We are not a law firm and we do not handle the banking claim, but we produce the timeline and evidence your bank, insurer and counsel will each ask for, and we can usually do it the same day.

Do we have to notify anyone legally?

It depends on what was in the mailbox rather than on the fact of the compromise itself. Under Texas breach notification law the trigger is unauthorised acquisition of sensitive personal information, and a mailbox often contains far more of it than owners expect — identity documents, bank details, medical or HR correspondence. If you handle health information, HIPAA obligations may also apply. This is why scope matters more than eviction: a lawyer can only advise properly once someone has established what was actually accessible. We provide that determination; the legal call is your counsel's.

Is this not just what email security is for?

Email security is prevention — it filters what arrives. Once an attacker is in the mailbox they are sending outbound as you, so there is no inbound filter in the path and the mail authenticates correctly because it genuinely originates from your account. Your clients' filters will not stop it either, for the same reason. Prevention and response are different jobs, and at this point you need the second one.

How much does this cost, and do we need a contract first?

No contract is needed to call — most of these engagements begin with a business we have never spoken to, on the day it happens. Cost is scoped by how many mailboxes are involved and how far the investigation needs to go, and we will give you a likely range on the first call before you commit. Many cyber insurance policies cover email compromise response; if you carry one, notify the carrier before engaging anyone, because most policies require it and some restrict who you may use.

How long until this is under control?

Eviction — locking the attacker out properly — is usually done the same day, often within hours of the first call. Establishing what they reached and which clients were emailed typically takes a few days depending on how long they were inside and how much audit history is retained. If the compromise spread beyond email into file storage or other systems, it becomes a broader investigation running one to three weeks. We tell you which of those you are in early, because the answer changes what you should be saying to clients this week.

Every Hour They Stay In Costs You A Client

If mail is going out under your name right now, call. We will tell you on the first call what to do in the next ten minutes, whether or not you hire us.