Business email compromise: what to do in the first hour
In the first hour of business email compromise, call your bank to try to recall the payment, then lock the intruder out by disabling the account or resetting its password and revoking its sessions, record what the intruder left behind, and only then remove it. Then report it to police and the Canadian Anti-Fraud Centre the same day. The order matters because the payment is the only part that gets harder to fix by the minute.
1. Call the bank
Call your bank before you do anything technical. Ask its fraud department to attempt a recall of the payment and to contact the receiving institution; the earlier the request, the better the odds, and no one can promise the money comes back. Have the amount, date, receiving account details and your own transaction reference in front of you. The Canadian Centre for Cyber Security says that if you suspect money has been transferred, you should contact the financial institution and the corporate email platform immediately (ITSAP.60.002, current as of September 2026).
2. Lock the intruder out
Is changing the password enough? No. A password reset does not necessarily end sessions that are already open, and it does nothing about a forwarding rule or a connected application the intruder left behind. Reset, revoke sessions, and then look for what persists. As of September 2026, Microsoft’s guidance for a compromised Microsoft 365 mailbox starts the same way: disable the affected account during the investigation, or reset its password if you cannot, and then revoke its active sessions. It also warns not to send the new password by email, because the intruder may still be reading it.
3. Record what the intruder left, then remove it
Sign-in and audit logs survive a password reset, but the clean-up deletes rules and app grants, so record them before you remove them:
- Export or pin the sign-in and mailbox audit logs, and extend their retention if your platform allows it.
- Screenshot or export the inbox rules, forwarding settings and connected applications as they are now.
- Keep the fraudulent messages, with full headers. Do not delete them.
- Start a timeline: what was seen, when, by whom, and every action taken.
Then check the places intruders hide, and remove what should not be there:
- Forwarding and inbox rules that copy, redirect or quietly delete mail about payments.
- Connected applications the user granted access to, which can keep reading mail after the password changes.
- New sign-in methods an intruder registered, such as a phone number or authenticator.
- Administrative roles held by the user, which Microsoft’s guidance also says to review.
- Organization-wide mail-flow (transport) rules, which a check of one mailbox will not show.
If one mailbox was compromised, assume others may be and check them. The wider sequence is in the first 24 hours of an incident.
4. Report it
Report it to your local police, who investigate, and to the Canadian Anti-Fraud Centre, which keeps the central record that helps police link cases. Whether anything must also be reported under privacy law is a question for your counsel. Reports go through reportcyberandfraud.canada.ca. What the police relationship looks like in practice is covered in working with police after a cyber incident. Tell the supplier or customer who was impersonated, by phone, so they can warn their own contacts.
What do most organizations get wrong?
The most common error is treating it as a finance problem only. The mailbox is usually still compromised after the payment is found, and the same intruder tries again. The reverse error is common too: a thorough clean-up that deletes rules and grants before anyone records them, or lets log retention lapse, so nothing shows which messages were read. That matters if personal information was in the mailbox, and it is what counsel needs to make a notification decision.
A call-back rule for any new or changed payment details, made to a number you already hold rather than one in the email, stops more of these frauds than any technical control. Domain authentication also makes impersonation harder; see DMARC and email authentication. Where you need investigation, it is part of incident response and forensics, delivered with appropriately licensed partners where the law requires it.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
Investigation and forensic work is delivered with appropriately licensed partners where the law requires it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Who do we call first after a fraudulent payment?
Call your bank before you do anything technical. Ask its fraud department to attempt a recall of the payment and to contact the receiving institution; the earlier the request, the better the odds, and no one can promise the money comes back.
Is changing the password enough?
No. A password reset does not necessarily end sessions that are already open, and it does nothing about a forwarding rule or a connected application the intruder left behind. Reset, revoke sessions, and then look for what persists.
Where do we report business email compromise in Canada?
Report it to your local police, who investigate, and to the Canadian Anti-Fraud Centre, which keeps the central record that helps police link cases. Whether anything must also be reported under privacy law is a question for your counsel.
What stops it happening again?
A call-back rule for any new or changed payment details, made to a number you already hold rather than one in the email, stops more of these frauds than any technical control.
Before it happens
Send us your payment-change procedure and your mail platform settings, and the reply says where an intruder would get through. More of our writing is indexed at writing.