Business Email Compromise (BEC) Response
Business Email Compromise (BEC) incident response; according to FBI IC3, $2.9 billion in losses in 2023. Covers account takeover, wire fraud, and OAuth abuse scenarios.
Preparation
1 steps- Establish BEC prevention/detection baseline
DMARC/DKIM/SPF (p=reject), impersonation detection, lookalike domain blocking, alert when a forwarding rule to an external address is created, finance/HR/executive training.
Identification
1 steps- Detect and classify the BEC incident
Unexpected forwarding/inbox rules, login from new geography/device, large wire request via email, CEO/CFO impersonation.
Containment
2 steps- Isolate the compromised email account
Revoke all active sessions/tokens, reset password, remove malicious forwarding rules and OAuth permissions, enable MFA.
- Stop the fraudulent wire transfer
If a wire has been initiated, call the sending bank IMMEDIATELY (24–48 hour critical window). Report to FBI IC3 Financial Fraud Kill Chain.