Recognize and declare
Treat these signals as an incident when they cross an authorization, confidentiality, integrity, availability, or safety boundary.
- Unexpected payment, payroll, banking, or supplier-detail change
- Suspicious inbox rules, forwarding, OAuth grants, or sent messages
- Impossible travel, adversary-in-the-middle session use, or MFA changes
Preserve the evidence
Collect authoritative records before destructive cleanup whenever operationally safe. Record source, collector, UTC time, integrity hash, access, and retention decision.
- Sign-in, token, MFA, device, and conditional-access logs
- Mailbox audit, message trace, inbox rules, delegates, forwarding, and sent/deleted items
- OAuth applications, consent grants, transport rules, connectors, and administrative changes
- Payment instructions, headers, attachments, domains, conversation IDs, and UTC timeline
IR-02 · FIRST 15 MINUTES
Reduce immediate uncertainty
- Contact finance through a trusted channel to stop or recall affected payments.
- Revoke sessions and tokens, reset authentication, and secure MFA from a known-clean device.
- Preserve mailbox, identity, message-trace, and payment evidence before deleting rules or messages.
- Disable malicious forwarding, rules, delegates, applications, and transport changes.
- Identify every recipient, transaction, supplier, and internal identity touched.
Contain → eradicate → recover
PHASE / 01Contain
- Block malicious domains, senders, URLs, sessions, and applications.
- Protect high-risk finance workflows with out-of-band verification and dual approval.
- Hunt related accounts, shared mailboxes, delegates, and similar rule names or destinations.
PHASE / 02Eradicate
- Remove persistence and rotate exposed identity, application, and third-party credentials.
- Correct supplier or payroll records changed through the compromised workflow.
- Review endpoint and browser state when token theft or adversary-in-the-middle access is suspected.
PHASE / 03Recover
- Restore access with phishing-resistant authentication and least privilege.
- Notify affected parties using verified contact data and monitor follow-on fraud.
- Validate mailbox configuration, application consent, finance controls, and detection coverage.
Decision gates
Record the owner, evidence, uncertainty, operational impact, and rollback condition at every transition.
Containment gate
Fraudulent sessions, forwarding, payment paths, and persistence are disabled.
Investigation gate
Message, identity, application, recipient, and financial scope is documented.
Recovery gate
Finance and identity owners validate records, controls, notifications, and monitoring.
Rollback safeguard: define the last known-good state, measurable failure signals, accountable decision owner, and fastest safe return path before restoring service.
AUTHORSHIP & REVIEW
How to trust and adapt this guide
- Author & accountable editor
- Leandro Rocha
- Version
- 1.0
- Published / reviewed
- 18 August 2026
- Review status
- Maintainer-reviewed; independent peer review is not claimed.
Reference basis
- NIST SP 800-61 Rev. 3
- CISA guidance for phishing and business email compromise
- MITRE ATT&CK identity and email techniques
Assumptions
- The organization has authorized incident leadership, protected communications, and access to relevant telemetry.
- Actions are adapted to business impact, legal obligations, architecture, and available evidence before execution.
Limitations
- This field guide is not a substitute for organization-specific legal, privacy, safety, regulatory, or business-continuity advice.
- Vendor interfaces and log availability vary by product, plan, region, configuration, and retention period.