Emergency response · 24/7/365

Your business email has been compromised. Call 864-224-0008 now.

A senior responder answers live, day or night. We take first-time callers. Containment starts on the call, before anything is written down.

[ IF MONEY IS MOVING ]
  • 01Call your bank and request a wire recall immediately.
  • 02Call us at 864-224-0008 so containment runs in parallel.
  • 03Report to the FBI IC3 the same day. Recovery odds fall sharply after 72 hours.
[ 01 ]
Live
Answer 24/7/365
[ 02 ]
Minutes
To first containment action
[ 03 ]
Non-clients
Accepted on emergency terms
[ 04 ]
Documented
Clear incident timeline
Right now

Do this in the next 10 minutes

Work down this list while you wait for a responder. Order matters: money first, access second, evidence always.

01

Freeze outbound payments

Tell finance and your bank to hold every wire, ACH change, and vendor banking update until you say otherwise. This is the step that saves money.

02

Reset the password

From a device that is not involved in the incident. Use a new password that has never been used anywhere else.

03

Sign out every session

A password reset alone does not evict an attacker holding a live token. Revoke all sessions and refresh tokens on the account.

04

Check for hidden rules

Look for forwarding rules, inbox rules that move mail to RSS or Archive, and any new mail-connected apps the user did not approve.

05

Warn the people who pay you

Call your customers and vendors. If the attacker already emailed them from the account, a phone call is the only trustworthy channel left.

06

Preserve everything

Do not delete messages, do not wipe the mailbox, do not reimage the laptop. Logs and message copies are needed to reconstruct what happened.

Do not wait for the checklist to be finished before you call.

Call 864-224-0008
On the call

What happens when you reach us

Four stages, starting the moment the phone connects.

01

Triage

A senior responder scopes the incident live: which accounts, what moved, who has been contacted, and whether money is still in flight.

02

Contain

Credentials reset, sessions and tokens revoked, attacker rules and app consents removed, and suspicious sign-in paths blocked.

03

Investigate

Audit and sign-in logs reconstruct what the attacker read, searched, downloaded, and sent, so exposure is scoped on evidence, not guesswork.

04

Harden

Conditional access, phishing-resistant multi-factor, and mail flow controls close the path used, followed by a written incident report and next-step guidance.

Diagnosis

Signs your email account was taken over

Any one of these is enough to treat the account as compromised until proven otherwise.

  • Sign-ins from countries or devices your team never uses
  • Forwarding or inbox rules nobody created
  • Sent messages you cannot account for, or a suspiciously empty Sent folder
  • Invoices or banking changes going out under your name
  • Multi-factor prompts arriving when nobody is logging in
  • Contacts replying to conversations you never started
  • Mail landing in Archive or RSS Feeds instead of the inbox
  • Password reset notices for connected services
Terminology

The terms responders will use

Security teams, auditors, banks, and law enforcement use these terms precisely. So do we.

Business email compromise (BEC)

Fraud that uses business email to redirect money or extract data. The umbrella term banks, law enforcement, and security teams use.

Email account compromise (EAC)

The attacker is genuinely signed in to the mailbox, not spoofing it from outside. Every message they send is authentic.

Vendor email compromise (VEC)

Your supplier's mailbox is the one that was taken over. The fraudulent invoice arrives from their real address, inside a real thread.

CEO fraud

An urgent request that appears to come from an executive, pressuring a finance or HR employee into a payment or data release.

Recovery

Removing an attacker from Microsoft 365 or Google Workspace

A password reset is not eviction. These are the steps that actually end the attacker's access.

Microsoft 365 account takeover recovery

  • Reset credentials and revoke all sessions and refresh tokens
  • Remove attacker-created inbox rules, forwarding, and mailbox delegates
  • Revoke OAuth app consents the attacker granted to keep persistent access
  • Re-register multi-factor authentication and remove attacker-added methods
  • Review audit and sign-in logs for what was read, searched, and downloaded
  • Enable conditional access so the same login path cannot be reused

Google Workspace compromised account recovery

  • Reset the password and sign the account out of all devices
  • Delete forwarding addresses, filters, and delegated access
  • Remove connected third-party apps and revoke app passwords
  • Rebuild two-step verification and clear attacker backup codes
  • Audit login and admin activity logs for the full session history
  • Tighten context-aware access rules before returning the account to service
Coverage

Email compromise response across the Carolinas and Georgia

Remote containment is immediate everywhere we serve. Onsite dispatch is same day in the Upstate and next business day or sooner in Charlotte and Atlanta.

Once the fire is out

How to prevent business email compromise from happening again

Every engagement ends with a hardening roadmap. These are the controls that stop the next attempt at the door.

Zero trust architecture

Verify every sign-in against device, location, and risk instead of trusting a password.

Zero trust approach

Identity and access management

Phishing-resistant multi-factor authentication and conditional access on every mailbox.

Identity and access management

Email security filtering

Catch lookalike domains, impersonation, and credential-harvesting links before delivery.

Email security and spam filtering

Endpoint allowlisting

Default-deny control so credential stealers and remote access tools cannot execute.

Application control

Staff who can spot a lookalike login page stop most of these attacks themselves. See cyber awareness training and, for a wider view of your exposure, the cybersecurity risk scorecard.

Questions

Business email compromise, answered

Not urgent

Think you were targeted but nothing has moved yet?

If there is no active fraud and no attacker in the mailbox right now, send the details and a responder follows up within one business hour.

Active incident, money in flight, or an attacker with live access: do not use this form. Call 864-224-0008.

Already stabilized and want the post-incident work? Start with cyber incident review or incident response planning.

Start here

Send us a message

Pick the path below so we route you to the right team.

Get started

Still reading? Call us instead.

Every minute an attacker holds a mailbox is another invoice they can reroute. A senior responder is on the line in under a minute, 24 hours a day.