Serving Central Coast, Newcastle & the Hunter Region, NSW

Contact us today 1300 270 412
Simple IT

23 September 2026

Business Email Compromise Recovery Example Explained

Business Email Compromise Recovery Example Explained

A supplier invoice arrives in the same email thread your accounts team has used for months. The bank details look plausible, the wording matches previous messages and payment is due that afternoon. That is how many incidents begin. This business email compromise recovery example shows what a well-managed response can look like when an employee’s Microsoft 365 account is taken over and a fraudulent payment is requested.

The names and figures below are illustrative, but the sequence is typical of cases affecting small and medium-sized businesses across the Central Coast, Newcastle and the Hunter. The key point is not that every incident looks identical. It is that the first few hours have a major bearing on whether money, data and trust can be protected.

A business email compromise recovery example

A 24-person construction business received an email from a regular materials supplier advising that its bank account details had changed. The email arrived from the supplier’s genuine address and continued an existing conversation about a legitimate project.

The accounts officer noticed one small difference: the supplier normally phoned through banking changes, but the email asked for the update to be made immediately. Before the team could confirm it, the business owner received a second message from the supplier. This time, it was sent from a different address and asked why an overdue invoice had not been paid.

The first email was fraudulent. The supplier’s Microsoft 365 account had been compromised, allowing an attacker to read messages and send replies from the genuine mailbox. They had waited until they found a real invoice discussion, then substituted their own bank details.

Fortunately, the payment had not yet been processed. In other cases, the discovery happens after funds have left the account. The recovery process is still similar, but the business must act even faster.

The first hour: contain the problem

The supplier’s IT provider was contacted immediately. They reset the affected user’s password, signed the user out of all active sessions and revoked any remembered access on devices and applications. Multifactor authentication was checked and re-enrolled, because an attacker who has stolen a session token may not be stopped simply by changing a password.

They also reviewed mailbox rules. Criminals commonly create hidden rules that forward messages outside the business, move replies into deleted items or mark messages as read. Those rules let the attacker continue monitoring conversations or prevent the real user from seeing warning signs.

At the construction business, the accounts officer was told not to delete the suspicious emails. Instead, the messages were preserved with their headers and the supplier was contacted by phone using a known number, not one supplied in the email. This confirmed the fraud and gave both businesses evidence for their investigations.

If a payment has been made, call the bank’s fraud team immediately. Ask for an urgent payment recall or trace, and provide the transaction details, amount, time and receiving account information. A recall is not guaranteed, particularly if the funds have already been moved, but delay reduces the chance of recovery.

What a proper recovery involves

Business email compromise is more than a password-reset problem. The attacker may have read emails, copied documents, impersonated staff or changed details in other systems. Recovery needs to address the account, the financial exposure and the people who may have been misled.

Secure the affected account and connected systems

The immediate work is to establish how the account was accessed. It may have been through a convincing phishing page, a reused password exposed in another breach, an unauthorised third-party application or a device with malware. Microsoft 365 sign-in logs can help identify unusual locations, unfamiliar devices, repeated failed sign-ins and suspicious application consent.

The business should reset passwords for affected accounts, remove unknown devices and applications, check multifactor authentication methods and review other accounts that used the same password. Shared mailboxes, finance accounts and senior staff deserve particular attention because they are common targets.

It is also sensible to review whether the attacker accessed SharePoint, OneDrive or Teams files. A compromised mailbox can be the starting point for broader access, especially where permissions are overly generous.

Notify the people who need to know

In this example, the supplier notified customers who had recently received emails from the compromised account. The construction business contacted its internal team, explained the fraudulent bank-detail request and reminded everyone that payment changes must be confirmed by phone.

The right external notifications depend on what was exposed and the nature of the business. A medical practice, legal firm or financial services business may have additional privacy, contractual or regulatory obligations. If personal information may have been accessed, obtain appropriate legal and privacy advice promptly. Do not make assumptions about what the attacker did or did not see.

Communication should be factual and calm. Tell affected people what happened, what they should watch for and how to verify future communications. Avoid sending a vague warning that creates confusion without giving staff or customers a safe way to respond.

Check the financial and operational damage

The business in this scenario reviewed recent invoices, supplier bank-detail changes and payment approvals. It also checked whether other clients had received requests from the compromised supplier mailbox. This was not just an IT task. Finance and operations staff knew which transactions were unusual and which relationships were at risk.

A good review considers practical questions: Were any payments redirected? Did someone change payroll details? Were quotations or contracts viewed? Has the attacker emailed customers, staff or suppliers from the account? Is there evidence that other mailboxes were accessed?

The answers shape the response. A single intercepted invoice may be contained quickly. Access to an executive mailbox with years of commercial correspondence may require a wider review and more careful communication.

Why business email compromise can be hard to spot

These attacks work because they exploit normal business behaviour. People are busy, invoices need approval and suppliers sometimes change banks. The email may contain no obvious spelling mistakes, and it may arrive from a trusted address after an attacker has gained access to that account.

That is why staff training matters, but training alone is not enough. A capable employee can still be caught out by a well-timed request in a genuine email chain. Businesses need processes that make it difficult for one convincing email to trigger a financial loss.

For payment changes, a simple control is independent verification. Confirm new banking details using a known phone number from your records or the supplier’s established contact details. Do not reply to the email requesting the change, and do not use the phone number included in that email.

Reducing the chance of a repeat incident

After containment, the construction business introduced stronger controls without making daily work unnecessarily difficult. Multifactor authentication was required for all Microsoft 365 users, particularly remote staff and finance personnel. Conditional access settings were reviewed to restrict risky sign-ins, and mailbox forwarding outside the organisation was limited.

The company also created a clear payment-change procedure. Any change to supplier or employee bank details required phone verification and a second person’s approval before the next payment run. This adds a little time, but it is proportionate for transactions that can involve thousands of dollars.

Regular review is equally useful. Someone should periodically check for unfamiliar mailbox rules, newly approved apps, unusual sign-in activity and changes to financial records. Managed IT support can make this routine rather than leaving it until a problem occurs.

Backups remain worthwhile, although they are not the main answer to business email compromise. They can help restore emails and files if an attacker deletes or alters information. They cannot reverse a fraudulent bank transfer or remove data an attacker has already read. Prevention, detection and a rehearsed response plan all have a role.

A practical response plan for business owners

You do not need a lengthy cyber manual before you can improve your position. Start by documenting who staff should call if they suspect fraud: your bank, your IT provider, the affected supplier or customer, and the person authorised to pause payments. Make sure those numbers are stored somewhere other than email.

Then test the process. Ask your accounts team what they would do if a supplier requested new bank details at 3 pm on a Friday. If the answer relies on a single person being available or a process no one can find, refine it.

Simple IT helps local businesses put these safeguards around Microsoft 365, email, identity and day-to-day financial workflows. The goal is practical: reduce the opportunity for an attacker, spot suspicious activity sooner and ensure staff know exactly what to do when something does not look right.

A fraudulent email does not need to become a business crisis. Confirm unusual payment requests independently, act quickly when an account may be compromised and treat every incident as a chance to strengthen the process for next time.

Book a free IT review with your local team

Talk to a local Central Coast IT team — no jargon, no obligation.