The short answer: A business email compromise is reconstructed from message headers, mailbox audit logs and sign-in records, not from malware. The forensic examiner rebuilds the timeline of access, mailbox rule abuse and the redirected wire, then preserves it under chain of custody for recovery and litigation.
Business email compromise is the quiet, high-value cousin of ransomware. There is no locked screen and no ransom note. An attacker gets into a mailbox or convincingly impersonates one and uses the trust that email carries to redirect a payment. The FBI Internet Crime Complaint Center reports business email compromise among the highest-dollar-loss categories of cyber crime it tracks, year after year and the mid-market is squarely in the target set because approvals are often informal and a single redirected wire can be very large.
This breakdown describes how a forensic examiner reconstructs a BEC after the money has moved: the anatomy of the attack, the artifacts that survive, how the timeline is rebuilt and how Sherlock Forensics email tooling parses the evidence for a wire-fraud claim.
The Anatomy of a BEC
A typical business email compromise runs in four stages. First, initial access: the attacker obtains a credential through a phishing page or reuses a password exposed in an unrelated breach or steals a live session token so they never need the password at all. Second, quiet residence: the attacker signs in and does nothing disruptive. They read mail, learn who approves payments and study the language of the finance team. Third, concealment: the attacker creates mailbox rules that auto-delete or auto-file the messages that would expose them, so the real account owner never sees the replies. Fourth, the intervention: when a genuine invoice or wire request appears, the attacker inserts themselves, changes the banking details and the payment goes to an account they control.
The absence of malware is the point. Because the attacker is using legitimate credentials through the normal mail interface, endpoint antivirus sees nothing. The evidence lives in the mail system and the identity logs, not on the workstation.
The Forensic Artifacts That Survive
Three categories of evidence carry a BEC investigation. The first is message headers. Every email carries a Received chain that records the servers it passed through and the results of SPF, DKIM and DMARC authentication. A spoofed sender and a genuinely compromised mailbox leave different header signatures and the examiner reads that difference to establish whether the fraud came from inside the account or from an impersonator outside it.
The second is mailbox audit and configuration data: the audit log of which items were read, moved or deleted and the mailbox rules and forwarding settings the attacker created to hide. The third is cloud sign-in logs, which show the source addresses, the client applications and the session tokens used to access the account. Retention policy decides how much of this survives, which is why preservation on day one is the single highest-value action after a BEC is suspected.
Mailbox Rule Abuse and Token Theft
Two techniques recur in nearly every serious BEC. Mailbox rule abuse is the concealment layer: the attacker sets a rule that moves any reply containing words like invoice, payment or wire into an obscure folder or straight to deleted items, so the legitimate user never notices the conversation happening in their name. Recovering and dating those rules shows intent and marks the moment the attacker took operational control of the mailbox.
Token theft is the access layer that defeats simple defenses. When an attacker steals a live session token, they inherit an already-authenticated session and bypass the password entirely and in many configurations they slip past multi-factor prompts because the session is already trusted. The forensic signature is a sign-in from an anomalous address reusing a session that multi-factor never re-challenged. Identifying token theft matters because it changes the remediation: resetting the password alone does not end the attacker access until the active sessions are revoked.
How Sherlock Forensics Email Tooling Parses the Evidence
Once the mail evidence is preserved, it has to be read in a form that stands up to scrutiny. The Sherlock Forensics PST Viewer opens exported mailbox data (PST, OST, MSG and EML) without Outlook and surfaces the forensic detail a review needs: the full Received chain, the SPF, DKIM and DMARC results, the transport path and per-message hashing for integrity. That single license covers the PST, OST, MSG and EML formats, which matters because BEC evidence arrives in whatever format the mail platform exports.
The examiner uses the tooling to isolate the fraudulent thread, compare its headers against known-good mail from the same correspondent and document the exact point where the banking details changed. Because every message carries a SHA-256 hash and the export preserves the original metadata, the reconstructed thread is defensible rather than a screenshot that opposing counsel can question.
Building the Wire-Fraud Timeline
The deliverable that matters to a victim organization and its bank is a timeline. The examiner correlates the three evidence sources into a single sequence: sign-in logs establish when the attacker first accessed the account and from where, mailbox audit logs and recovered rules establish when concealment began and what the attacker read and the message headers establish when the payment thread was intercepted and how the wire instructions were altered. The result is a defensible narrative from first access to final transfer.
That timeline drives the practical response. A tight, well-dated sequence delivered quickly to the receiving bank materially improves the odds of a recall or freeze on the fraudulent transfer and it is the backbone of any insurance claim or civil action that follows.
Chain of Custody for Wire-Fraud Litigation
A BEC investigation frequently ends in a dispute over money, which means the evidence has to survive legal challenge. Every artifact the examiner collects is preserved under a documented chain of custody: hashed at acquisition, stored with access controls and logged from collection through analysis to reporting. The report states its own scope and method so the examiner can testify precisely to what was and was not examined.
For a mid-market company, the combination of a fast timeline and a defensible evidence record is what turns a wire-fraud loss from a total write-off into a recoverable event. Sherlock Forensics runs these investigations end to end, from preservation through the courtroom and builds the email tooling the analysis depends on.
What the Investigation Teaches You to Harden
A BEC investigation is also a hardening roadmap, because the forensic findings point straight at the controls that failed. If the root cause was a stolen session token that bypassed multi-factor, the fix is conditional access policies and shorter session lifetimes, not merely a password reset. If the attacker survived on auto-deleting mailbox rules, the fix is alerting on rule creation and forwarding changes. If the intrusion started with a phished credential, the fix is phishing-resistant authentication for the finance and executive accounts that handle money.
The examiner report should name these controls specifically, so the response does more than restore the status quo that allowed the compromise. A company that treats each BEC as a lesson closes the exact gaps that let it happen, rather than waiting to be hit through the same door twice.
Coordinating With the Bank and Law Enforcement
Speed is decisive after the wire has moved. The receiving bank can sometimes freeze or recall a fraudulent transfer, but only within a short window and only when presented with a clear, dated account of the fraud. A forensic timeline delivered quickly gives the bank what it needs to act. In the United States the FBI Internet Crime Complaint Center operates a recovery process for qualifying wire fraud and Canadian victims work through their financial institution and local law enforcement on a similar clock. In every case the organized evidence the examiner produces is what makes the report actionable rather than a vague complaint.
Sherlock Forensics structures the BEC deliverable for exactly this handoff: a defensible timeline, the preserved artifacts and a report that a bank fraud desk, an insurer or a court can rely on. The investigation and the recovery effort run in parallel, because every hour counts once the money is in motion.
Why BEC Evidence Expires and What to Preserve First
The hardest constraint in a business email compromise investigation is time, because the evidence is perishable. Cloud mail platforms retain sign-in logs, mailbox audit records and message-trace data for a limited window by default and once that window passes the record of the initial access and the attacker activity is simply gone. An organization that waits weeks to investigate a suspected BEC often finds that the logs proving how and when the attacker got in have already rolled off.
The first preservation actions therefore matter more than any later analysis. On suspicion of a BEC, immediately export and preserve the mailbox contents, capture the sign-in and audit logs before they expire, snapshot the current mailbox rules and forwarding configuration and revoke active sessions to end the attacker access. Preserve first and analyze second, because analysis can happen any time but the evidence cannot be recovered once retention purges it. Sherlock Forensics guides clients through that preservation checklist at first contact, so the material the investigation depends on is captured before the clock runs out and then reconstructs the full timeline from the preserved artifacts.