OPERATIONAL PLAYBOOK · IR-02

Business email compromise

Stop fraudulent access and payment risk, preserve mailbox evidence, and find every persistence and delegated-access path.

SEVERITY / CRITICALFIRST ACTION / SECURE THE AFFECTED IDENTITYFORMAT / PRINT-READY

Recognize and declare

Treat these signals as an incident when they cross an authorization, confidentiality, integrity, availability, or safety boundary.

  • Unexpected payment, payroll, banking, or supplier-detail change
  • Suspicious inbox rules, forwarding, OAuth grants, or sent messages
  • Impossible travel, adversary-in-the-middle session use, or MFA changes

Preserve the evidence

Collect authoritative records before destructive cleanup whenever operationally safe. Record source, collector, UTC time, integrity hash, access, and retention decision.

  • Sign-in, token, MFA, device, and conditional-access logs
  • Mailbox audit, message trace, inbox rules, delegates, forwarding, and sent/deleted items
  • OAuth applications, consent grants, transport rules, connectors, and administrative changes
  • Payment instructions, headers, attachments, domains, conversation IDs, and UTC timeline

IR-02 · FIRST 15 MINUTES

Reduce immediate uncertainty

  1. Contact finance through a trusted channel to stop or recall affected payments.
  2. Revoke sessions and tokens, reset authentication, and secure MFA from a known-clean device.
  3. Preserve mailbox, identity, message-trace, and payment evidence before deleting rules or messages.
  4. Disable malicious forwarding, rules, delegates, applications, and transport changes.
  5. Identify every recipient, transaction, supplier, and internal identity touched.

Contain → eradicate → recover

PHASE / 01

Contain

  • Block malicious domains, senders, URLs, sessions, and applications.
  • Protect high-risk finance workflows with out-of-band verification and dual approval.
  • Hunt related accounts, shared mailboxes, delegates, and similar rule names or destinations.
PHASE / 02

Eradicate

  • Remove persistence and rotate exposed identity, application, and third-party credentials.
  • Correct supplier or payroll records changed through the compromised workflow.
  • Review endpoint and browser state when token theft or adversary-in-the-middle access is suspected.
PHASE / 03

Recover

  • Restore access with phishing-resistant authentication and least privilege.
  • Notify affected parties using verified contact data and monitor follow-on fraud.
  • Validate mailbox configuration, application consent, finance controls, and detection coverage.

Decision gates

Record the owner, evidence, uncertainty, operational impact, and rollback condition at every transition.

Containment gate

Fraudulent sessions, forwarding, payment paths, and persistence are disabled.

Investigation gate

Message, identity, application, recipient, and financial scope is documented.

Recovery gate

Finance and identity owners validate records, controls, notifications, and monitoring.

Rollback safeguard: define the last known-good state, measurable failure signals, accountable decision owner, and fastest safe return path before restoring service.

AUTHORSHIP & REVIEW

How to trust and adapt this guide

Author & accountable editor
Leandro Rocha
Version
1.0
Published / reviewed
18 August 2026
Review status
Maintainer-reviewed; independent peer review is not claimed.

Reference basis

  • NIST SP 800-61 Rev. 3
  • CISA guidance for phishing and business email compromise
  • MITRE ATT&CK identity and email techniques

Assumptions

  • The organization has authorized incident leadership, protected communications, and access to relevant telemetry.
  • Actions are adapted to business impact, legal obligations, architecture, and available evidence before execution.

Limitations

  • This field guide is not a substitute for organization-specific legal, privacy, safety, regulatory, or business-continuity advice.
  • Vendor interfaces and log availability vary by product, plan, region, configuration, and retention period.