Short answer: often yes. A business email compromise becomes a reportable event the moment personal information in that mailbox was accessible to someone who should not have had it. Not stolen. Accessible. That distinction is where most companies get the analysis wrong.
What actually triggers notification
State breach laws are built around personal information: names paired with Social Security numbers, driver license numbers, financial account numbers, and in most states medical or health insurance information. A single mailbox usually holds all of those somewhere, buried in an HR thread, a benefits enrollment, a signed contract, or a scanned check.
Once an attacker has held the account, the legal question is not what they read. It is what they could have read. Proving a narrower scope requires audit logs, and those logs have retention limits, which is why the first 48 hours matter so much to the reporting decision.
South Carolina, North Carolina, and Georgia
All three states require notice to affected residents when personal information is compromised, and all three expect it without unreasonable delay. South Carolina also requires notice to the Department of Consumer Affairs when the incident affects 1,000 or more residents. North Carolina requires notice to the Attorney General Consumer Protection Division, and the notice itself has content requirements. Georgia follows the same general structure for residents, with consumer reporting agency notice at volume.
Because breach law follows the resident, not your office, one incident can pull in all three states at once plus wherever else your customers live. Scope the mailbox contents before you decide you are exempt.
Regulated industries have shorter clocks
- Healthcare. Under HIPAA, an unauthorized person holding a mailbox with protected health information is presumed to be a breach unless a documented four-factor risk assessment shows low probability of compromise. That assessment has to be written down.
- Defense contractors. If controlled unclassified information sat in the compromised mailbox, federal reporting timelines apply and they are measured in hours, not weeks. CMMC assessment evidence also expects your incident reporting process to exist before you need it. Our CMMC compliance program covers that requirement directly.
- Financial services. GLBA and FTC Safeguards obligations attach to customer financial information, with notification duties on top of state law.
Reporting to law enforcement is separate
Notifying affected individuals is not the same as reporting the crime. If money moved, file with the FBI Internet Crime Complaint Center the same day. The Financial Fraud Kill Chain can still recall a domestic wire in the early window, and that process depends on a filed report.
What to do before you decide
Contain first, decide second. Get the attacker out, preserve the logs, then scope the exposure with evidence in hand. If you are in the middle of one right now, our page on what to do when your business email is compromised lists the first ten minutes, and the line at 864-224-0008 is answered live around the clock.

