Business Email Compromise Response
An invoice was paid to the wrong account. A mail that looked like the CEO asked finance to move money. Call 088 SECDESK (7323375). We drive the bank recall, preserve evidence, and trace the attacker.
We have run bank-recall coordination and BEC forensics for Dutch manufacturers, logistics operators, and a regional housing corporation.
Invoice paid to a fake account? What to do in the first hour.
- 01
Call your bank and request a recall, then call us
The most time-sensitive action is a recall request to the paying bank, ideally within hours of the transfer. SEPA recalls have a realistic window of roughly 24 to 72 hours before the funds leave the receiving account. For SWIFT wires, the window is shorter and depends on the intermediary banks. While you are on the phone with your bank's fraud team, call us on the other line.
- 02
Preserve every email and attachment. Do not reply, do not forward around
The fraudulent invoice, the request from the fake CEO, the headers, the reply chain, and any calendar invites the attacker sent are evidence. Do not forward them around the company (it pollutes the chain of custody). Keep the originals in the mailbox, and let us export them properly.
- 03
Do not delete anything, and stop payment runs
If you are mid-way through a payment run, pause it. Check whether other invoices from the same supplier or to the same IBAN are queued. Attackers often slip several fakes through in one week. Do not delete the suspicious mail, the forwarding rules, or the sign-in history, we need them.
Wire in flight? Call 088 SECDESK now, every minute counts.
088 SECDESK (7323375)What Business Email Compromise is, and how SecDesk handles a BEC incident
What BEC actually is
Business Email Compromise (BEC) is a fraud pattern where an attacker uses a real or spoofed business email identity to trick finance, HR, or operations into moving money or data. Sometimes the attacker sits inside a genuinely compromised mailbox (the supplier, the client, a colleague). Sometimes they use a lookalike domain, a homoglyph that reads like the real address. The ask is almost always a payment, an IBAN change, or a payroll redirect.
Triage and scope, first 30 minutes
We map the scam. Was the sending mailbox genuinely compromised, or spoofed? Was it your CEO, your supplier, or a customer? Did the attacker insert themselves into an existing thread (a reply-chain attack), or did they start from scratch? We pull sign-in logs, mail headers, and any forwarding rules on both your tenant and, where possible, the counterparty's.
Bank coordination and recall
We help you draft the recall request, provide the evidence the bank's fraud team needs, and follow up through each intermediary if it is a SWIFT wire. We stay in contact while the recall is pending. Recovery is not guaranteed, but speed and documented fraud evidence give you the best shot.
Forensic investigation
We build a forensic timeline: how long the attacker had access, which invoices and IBANs they touched, whether they changed banking details with any supplier, and whether they still have access. We preserve evidence (mailbox exports with full headers, Unified Audit Log extracts, Exchange mailbox audit logs, sign-in log exports, and any screenshots or transaction records) with chain of custody for criminal proceedings and insurance claim.
Remediation, notification, and report
We contain the compromised mailbox (yours or the counterparty's, where we can coordinate), reset credentials with session revocation, remove forwarding rules, and harden conditional access. If personal data was exposed, we support your AVG notification to the Autoriteit Persoonsgegevens. We support aangifte at the politie, and the OM coordinates further where relevant. Your cyber insurer receives a report structured for claim review.
Common BEC patterns we see
CEO fraude
A short, urgent email from what looks like the CEO's address asks finance to make a payment, usually outside normal approval. The sender is either a lookalike domain or a genuinely compromised mailbox. Urgency and secrecy are the tells.
Invoice redirection
An attacker inside a real supplier mailbox emails you a legitimate-looking invoice with new bank details. The logos, formats, and reply chain all look right. You pay. The supplier never sees the money.
Supplier impersonation via lookalike domain
The attacker registers a domain that differs from your supplier's by one character (a homoglyph such as rn instead of m, or a misplaced hyphen). They reply to an existing thread from the spoofed address, quietly insert themselves, and redirect payment.
Can you recover the money?
Sometimes. Recovery depends on how fast the recall reaches the receiving bank, whether the attacker has already drained the account, and whether the receiving bank in a non-EU jurisdiction cooperates. The Fraudehelpdesk collects data that helps broader enforcement even when individual recovery fails.
Frequently asked questions
Can we recover the money already sent?
Sometimes. A recall started within hours has a realistic chance on SEPA transfers; shorter window on SWIFT. After about 72 hours the money is usually routed through money mules and chances drop. File the recall anyway. The documented fraud supports your insurance claim and the criminal case.
Should we tell the counterparty (customer or supplier)?
Yes, as soon as you have stabilised your own side. If the attacker was inside their mailbox, they need to contain on their end, or the fraud spreads. If it was a lookalike, they need to know customers are being impersonated. We can make the call with you if that helps.
Will our bank help?
Yes, banks have fraud teams that process recall requests. They expect clear documented fraud: the original invoice, the fake invoice, proof of IBAN change, and the sign-in or header evidence. A structured fraud report from us speeds their work.
Is this a matter for the police?
Yes, file aangifte at the politie. The OM may pick up the case depending on scale and jurisdiction. Report to the Fraudehelpdesk too. Your cyber insurer will usually require a police file number.
Does our cyber insurance cover this?
Many Dutch cyber policies include social engineering and funds transfer fraud coverage, often with sub-limits lower than the main policy. Call your broker the same day and send them our preliminary findings. Our final report is structured for insurer claim review.
What evidence do we need to preserve?
The original fraudulent email with full headers, the real thread it hijacked (if applicable), the invoice PDF, the payment confirmation, the mailbox rules on the compromised account, sign-in logs covering the attacker's access window, and any voicemails or SMS the attacker used. Keep copies in a secure export, do not rely on the live mailbox alone.
Related reading
Wire in flight? Call 088 SECDESK now
Every minute counts. A senior responder picks up, and we coordinate the bank recall while we contain the compromised mailbox.
- Two-hour SLA
- Dutch senior responders