Skip to content
Solvex Space
DFIR & ForensicsLogistics / freight forwarding72-hour response, 2-week investigation

Containing a business email compromise before the wire cleared

Privately-held freight forwarder, ~400 staff, Microsoft 365 estate

A freight forwarder's finance team caught a supplier payment that didn't feel right — the account details had changed in a thread that read exactly like their supplier. It was a compromised mailbox with inbox rules hiding the real correspondence. Emergency response locked the estate down the same day, forensics mapped exactly which mailboxes and threads were touched, and the pending transfer was recalled before it cleared.

Representative engagement — the client is confidential, and the figures and the quoted comment illustrate typical outcomes for the work described.

Funds lost
$0
transfer recalled inside the window
Time to estate-wide containment
< 24h
from first call
Attacker dwell time reconstructed
19 days
from mailbox and sign-in telemetry
Mailboxes confirmed touched
3 of 400+
scope narrowed by evidence, not assumption

The challenge

  • An attacker inside a finance mailbox had been silently reading and redirecting supplier payment threads via hidden inbox rules.
  • One six-figure transfer to attacker-controlled details was already initiated and inside the recall window.
  • The firm needed to know precisely which correspondence and data the attacker touched — for its bank, its insurer and its notification decisions.

What we did

  • Took the call the same day: revoked sessions and tokens estate-wide, removed the malicious inbox rules and OAuth grants, and enforced phishing-resistant re-authentication for finance roles.
  • Worked with the bank inside the recall window while containment ran in parallel.
  • Acquired and analysed mailbox audit logs, sign-in telemetry and message traces to reconstruct the attacker's full window of access.
  • Mapped every thread and attachment accessed, giving counsel a defensible factual basis for notification decisions.
  • Left hardening in place — conditional access, finance-flow payment verification procedure, and detection rules for inbox-rule abuse.

The outcome

  • The initiated transfer was recalled before clearing; no funds were lost.
  • The investigation produced a defensible account of exactly what was accessed, narrowing notification obligations to the facts.
  • The same lure was reported and blocked by staff within days of the refreshed finance-team procedure — evidence the process change stuck.
The scariest part wasn't the money — it was not knowing what else they'd read. Getting a precise answer to that question is what let us face our bank, our insurer and our customers with confidence.
CFO, freight forwarding groupIllustrative — composed to show the kind of feedback this work draws, not a quotation from a named client.
Business Email Compromise Response | Case Study — Solvex Space