Skip to content
Financial Fraud

Business email compromise: the first 24 hours after wire fraud

A payment went to a criminal account after an email that looked exactly right. Funds can sometimes be frozen — but the window is measured in hours, not days.

Business email compromise: the first 24 hours after wire fraud — Response Red advisory illustration

The essentials

  • Call your bank's fraud line immediately and request a recall; ask them to alert the receiving bank. Every hour matters.
  • Report to law enforcement the same day — rapid-response programs (such as IC3's Recovery Asset Team in the US) can freeze funds, with the best odds inside 24–72 hours.
  • Do not delete the fraudulent emails. Their full headers prove how the fraud was routed.
  • Assume the mailbox is still compromised: check rules, forwarding, and connected apps before trusting it again.
  • Verify any "corrected" bank details by phone, using a number you already had on file — never one from the email.

Business email compromise does not look like hacking. It looks like a normal invoice, a familiar signature, and one quietly changed bank account number. By the time someone notices, the money has moved — and the attacker is often still reading the mailbox, watching how you react.

Your first 24 hours are a race on two tracks at once: freezing the money, and locking the attacker out without destroying the evidence of what they did.

Do this now

  1. Call the bank — now, by phone. Contact your bank's fraud department, request a recall of the transfer, and ask them to notify the receiving bank. Get case numbers and the exact times of each call.
  2. File with law enforcement the same day. In the US, file at ic3.gov; in the UK, Action Fraud; elsewhere, your national cybercrime unit. Speed matters more than completeness — you can supplement the report later.
  3. Lock the compromised mailbox. From a clean device: reset the password, revoke active sessions and app passwords, and review inbox rules, forwarding addresses, and third-party app access. Screenshot anything suspicious before you disable it.
  4. Warn your counterparties. The attacker may be emailing your customers and suppliers from your own threads. A short, factual heads-up by phone protects them and your relationships.
  5. Freeze the payment pipeline. Pause pending transfers and re-verify any vendor bank details changed in recent weeks — by phone, on known numbers.
  6. Engage responders to scope it. A takeover that sent one fraudulent invoice usually read hundreds of emails. Professionals establish what was accessed, what was sent, and whether other mailboxes are affected.

What not to do

  • Do not delete the fraudulent emails, rules, or forwarding entries — disable and preserve them.
  • Do not reply to the attacker or let them know they have been discovered.
  • Do not assume only one mailbox is affected; attackers pivot to colleagues and executives.
  • Do not coordinate the response from the compromised account.
  • Do not quietly "fix it and move on" — insurance, regulators, and counterparties may all have a stake in what happened.

Preserve the evidence

Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:

  • The fraudulent emails exported with full headers (saved as files, not forwarded).
  • Mailbox audit logs and sign-in history, exported before they age out.
  • The fraudulent invoice or bank-detail change request.
  • Screenshots of malicious inbox rules, forwarding, and app grants before removal.
  • Bank case numbers, wire references, and a timeline of every call made.

Keep a clear head

Someone on your team approved that payment in good faith, and they are probably reliving it hourly. Say the quiet part out loud: nobody is being punished today for reporting facts. Shame is the attacker's best friend — it hides details your bank and your responders need in the first hours.

Treat the day as a bank-and-evidence race, not a blame exercise. The organizations that recover money are the ones that move fast and speak plainly.

Questions victims ask

Can the money actually be recovered?

Sometimes, and speed is the biggest factor. Recalls and freezes initiated within the first 24–72 hours have meaningfully better odds, and partial recovery is common when banks and law enforcement are engaged quickly. After the funds are layered through mule accounts, odds drop sharply.

Was our email hacked, or theirs?

It matters, and forensics can tell. A lookalike domain means your systems may be clean; a genuine mailbox takeover means everything that mailbox could read is potentially exposed — two very different obligations.

Do we have to notify anyone?

Possibly. If the attacker had access to personal data in the mailbox, notification duties may apply depending on jurisdiction. Establish what was accessed first — that is scoping work — and involve counsel early.

When the first hour is over, we take it from there.

Scoping, containment, forensics, and recovery — expert-led and evidence-safe, with AI removing the waiting. Engage a responder or talk to us about readiness.