Skip to main content
FIR
All casework

Cyber Incident Investigation

Reconstructing a business email compromise

How mailbox activity, payment communications and access logs can be organized into a defensible incident timeline.

THE CHALLENGE

A payment instruction appeared to come from a known counterparty, but the organization needed to establish whether an account had been compromised and when.

Jurisdiction

United Kingdom / Europe

APPROACH

  • Preserved original emails and headers
  • Reviewed sign-in and mailbox audit activity
  • Examined forwarding rules and message handling
  • Correlated technical activity with the payment timeline

DELIVERABLES

  • Incident chronology
  • Indicators schedule
  • Evidence appendix
  • Containment recommendations

OUTCOME & LIMITATIONS

The organization received a clear separation between confirmed activity, likely intrusion points and remaining evidential gaps.