Business email compromise, often shortened to BEC, is one of the costliest cybercrimes reported to the FBI's Internet Crime Complaint Center. In construction, it frequently shows up as a hijacked mailbox used to redirect payments, request changes to bank details, or study ongoing projects before striking.
The most important point is that a compromised account is usually quiet. The attacker does not want to be noticed, so there is no ransom screen or crashed server. The signs are subtle, and they appear first to ordinary employees. Teaching staff to recognize them shortens the time an attacker has inside your email.
What Attackers Do With a Mailbox
Once inside, an attacker often spends days or weeks reading. They learn who approves payments, which vendors you pay, how invoices look, and how people write to each other. Then they act: sending a convincing request from a trusted account, inserting themselves into a payment thread, or hiding replies so the real owner does not see them.
Signs in the Mailbox Itself
Ask staff to report any of the following immediately:
- Rules they did not create. Attackers often create inbox rules that forward copies elsewhere, move messages to obscure folders, or mark them as read. Check the rules list periodically.
- Missing replies. A colleague says they replied but you never saw it.
- Sent items you do not recognize. Messages in the sent folder or deleted items that you did not write.
- Odd forwarding settings. Automatic forwarding to an outside address.
- Contacts or signature changes. Subtle edits to banking details in a template or a changed phone number in a signature.
Signs in Sign-In Activity
Your Microsoft 365 or other email platform keeps sign-in records. Look for:
- Sign-ins from countries or regions where you have no staff or projects
- Sign-ins at times that do not match the person's habits
- Repeated multifactor prompts the user did not trigger
- Sign-ins from unfamiliar devices or applications
- Password reset or security info changes the user did not request
Users also see signs: unexpected approval prompts on their phone, alerts about new device sign-ins, or being logged out unexpectedly. Treat repeated unexpected prompts as an attack, not a glitch.
Signs in Business Behavior
Sometimes the first indicator is not technical:
- A vendor says they never sent the banking change request you received
- A customer asks why you emailed a different payment address
- A thread about payment suddenly includes a new person or a lookalike domain
- A message pushes unusual urgency or secrecy around a payment
- A senior leader appears to request a favor, such as gift cards or an urgent transfer, in a style that is slightly off
When someone says "I never sent that," believe them and investigate.
What to Do When You Suspect It
Speed matters. A simple response sequence:
- Report to IT or your provider right away, by phone, not by email from the possibly compromised account
- Reset the password and revoke active sessions and tokens
- Verify multifactor methods and remove any the user did not register
- Check and remove suspicious inbox rules and forwarding
- Review sent mail and sign-in logs to understand scope
- Identify any payment or banking changes that may have been affected and pause them
- Notify finance, your bank if needed, and your insurance contact
Preserve logs before cleaning up, since you may need them later.
Reduce the Odds
Technical controls help considerably:
- Require multifactor authentication for every account, preferring phishing-resistant methods where possible
- Disable legacy sign-in methods that bypass multifactor
- Alert on new forwarding rules and unusual sign-ins
- Use conditional access to restrict risky locations and unmanaged devices
- Warn users about lookalike domains
But the best defense remains a team that speaks up. Make it easy and safe to report something odd, even if it turns out to be nothing.
A Quick Habit
Once a quarter, ask everyone with email to check their inbox rules and forwarding settings. It takes five minutes and catches things filters miss.
Ironfield Cyber monitors Microsoft 365 for these signals and helps contractors respond when an account looks compromised. If you want us to review your email protections and alerts, we can start with a short assessment.