Your business email has been compromised. Call 864-224-0008 now.
A senior responder answers live, day or night. We take first-time callers. Containment starts on the call, before anything is written down.
- 01Call your bank and request a wire recall immediately.
- 02Call us at 864-224-0008 so containment runs in parallel.
- 03Report to the FBI IC3 the same day. Recovery odds fall sharply after 72 hours.
Do this in the next 10 minutes
Work down this list while you wait for a responder. Order matters: money first, access second, evidence always.
Freeze outbound payments
Tell finance and your bank to hold every wire, ACH change, and vendor banking update until you say otherwise. This is the step that saves money.
Reset the password
From a device that is not involved in the incident. Use a new password that has never been used anywhere else.
Sign out every session
A password reset alone does not evict an attacker holding a live token. Revoke all sessions and refresh tokens on the account.
Check for hidden rules
Look for forwarding rules, inbox rules that move mail to RSS or Archive, and any new mail-connected apps the user did not approve.
Warn the people who pay you
Call your customers and vendors. If the attacker already emailed them from the account, a phone call is the only trustworthy channel left.
Preserve everything
Do not delete messages, do not wipe the mailbox, do not reimage the laptop. Logs and message copies are needed to reconstruct what happened.
Do not wait for the checklist to be finished before you call.
Call 864-224-0008What happens when you reach us
Four stages, starting the moment the phone connects.
Triage
A senior responder scopes the incident live: which accounts, what moved, who has been contacted, and whether money is still in flight.
Contain
Credentials reset, sessions and tokens revoked, attacker rules and app consents removed, and suspicious sign-in paths blocked.
Investigate
Audit and sign-in logs reconstruct what the attacker read, searched, downloaded, and sent, so exposure is scoped on evidence, not guesswork.
Harden
Conditional access, phishing-resistant multi-factor, and mail flow controls close the path used, followed by a written incident report and next-step guidance.
Signs your email account was taken over
Any one of these is enough to treat the account as compromised until proven otherwise.
- Sign-ins from countries or devices your team never uses
- Forwarding or inbox rules nobody created
- Sent messages you cannot account for, or a suspiciously empty Sent folder
- Invoices or banking changes going out under your name
- Multi-factor prompts arriving when nobody is logging in
- Contacts replying to conversations you never started
- Mail landing in Archive or RSS Feeds instead of the inbox
- Password reset notices for connected services
The terms responders will use
Security teams, auditors, banks, and law enforcement use these terms precisely. So do we.
Business email compromise (BEC)
Fraud that uses business email to redirect money or extract data. The umbrella term banks, law enforcement, and security teams use.
Email account compromise (EAC)
The attacker is genuinely signed in to the mailbox, not spoofing it from outside. Every message they send is authentic.
Vendor email compromise (VEC)
Your supplier's mailbox is the one that was taken over. The fraudulent invoice arrives from their real address, inside a real thread.
CEO fraud
An urgent request that appears to come from an executive, pressuring a finance or HR employee into a payment or data release.
Removing an attacker from Microsoft 365 or Google Workspace
A password reset is not eviction. These are the steps that actually end the attacker's access.
Microsoft 365 account takeover recovery
- Reset credentials and revoke all sessions and refresh tokens
- Remove attacker-created inbox rules, forwarding, and mailbox delegates
- Revoke OAuth app consents the attacker granted to keep persistent access
- Re-register multi-factor authentication and remove attacker-added methods
- Review audit and sign-in logs for what was read, searched, and downloaded
- Enable conditional access so the same login path cannot be reused
Google Workspace compromised account recovery
- Reset the password and sign the account out of all devices
- Delete forwarding addresses, filters, and delegated access
- Remove connected third-party apps and revoke app passwords
- Rebuild two-step verification and clear attacker backup codes
- Audit login and admin activity logs for the full session history
- Tighten context-aware access rules before returning the account to service
Email compromise response across the Carolinas and Georgia
Remote containment is immediate everywhere we serve. Onsite dispatch is same day in the Upstate and next business day or sooner in Charlotte and Atlanta.
How to prevent business email compromise from happening again
Every engagement ends with a hardening roadmap. These are the controls that stop the next attempt at the door.
Zero trust architecture
Verify every sign-in against device, location, and risk instead of trusting a password.
Zero trust approachIdentity and access management
Phishing-resistant multi-factor authentication and conditional access on every mailbox.
Identity and access managementEmail security filtering
Catch lookalike domains, impersonation, and credential-harvesting links before delivery.
Email security and spam filteringEndpoint allowlisting
Default-deny control so credential stealers and remote access tools cannot execute.
Application controlStaff who can spot a lookalike login page stop most of these attacks themselves. See cyber awareness training and, for a wider view of your exposure, the cybersecurity risk scorecard.
Business email compromise, answered
Think you were targeted but nothing has moved yet?
If there is no active fraud and no attacker in the mailbox right now, send the details and a responder follows up within one business hour.
Active incident, money in flight, or an attacker with live access: do not use this form. Call 864-224-0008.
Already stabilized and want the post-incident work? Start with cyber incident review or incident response planning.
Send us a message
Pick the path below so we route you to the right team.
Reporting, recovery, and prevention
Detailed guides for the decisions that follow a compromised mailbox.
Breach notification duties in South Carolina, North Carolina, and Georgia, plus HIPAA and CMMC clocks.
Revoke sessions, kill forwarding rules, pull OAuth consents, rebuild MFA, and verify with logs.
The identity controls and payment verification rules that actually stop it happening again.
Still reading? Call us instead.
Every minute an attacker holds a mailbox is another invoice they can reroute. A senior responder is on the line in under a minute, 24 hours a day.

