Containing a business email compromise in Microsoft 365
A representative engagement — details are generalised and anonymised across the kind of business-email-compromise work I'm called into. It describes my approach and the standard response, not a specific named client.
Business email compromise is the incident I get called about most. Someone clicks a convincing login page, an attacker gets into a Microsoft 365 mailbox, and by the time anyone notices there's a fake invoice in flight and a mailbox rule quietly deleting the replies. The difference between a scare and a loss is almost always speed.
The pattern
The calls follow a familiar shape: a finance user's account is behaving oddly, or a supplier flags an invoice with changed bank details. Under the hood it's usually the same story — credentials phished, MFA either absent or fatigued past, and inbox rules set up to hide the attacker's tracks.
Containment first
Before investigating anything, the priority is to get the intruder out and keep them out:
- Revoke active sessions and reset credentials for the affected account, so a stolen token stops working immediately.
- Enforce MFA re-registration — attackers often add their own authenticator; that has to go.
- Hunt for malicious inbox rules — auto-forwarding and "move to RSS/delete" rules are the classic tell, and they're how the fraud stays hidden.
- Block the sign-in via Conditional Access while the investigation runs.
Then the investigation
With the bleeding stopped, the unified audit log tells the story: where the sign-ins came from, what was accessed, whether other mailboxes were touched, and critically — whether any payment or data actually left. That scope determines who needs to be told, including any regulatory or insurer notification.
Closing the door
Containment isn't the finish line. The same gap that let them in is still open, so recovery always ends with hardening: phishing-resistant MFA, Conditional Access that blocks legacy authentication, and — because finance is the target — a hard out-of-band rule for verifying any change to payment details.
The uncomfortable truth about BEC is that the technical fix is the easy part. The lasting fix is a process: no bank-detail change is ever actioned on the strength of an email alone.
If you think an account has been compromised, the first hour matters most. Revoke access first, investigate second.
Have a similar challenge?
I help businesses secure and run their IT. Let's talk.
Start a conversation →