The negotiation had been going on for weeks, all by email, all normal. Close to closing, the expected message arrives: the bank details for the payment, in the same conversation thread, with the same signature, the same tone. The company pays. Days later, the supplier demands payment: it never received anything. The two reread the exchange and discover, too late, that at some point the conversation changed hands: the account provided was not the supplier's, the sender's domain had one letter swapped, or the message came from the legitimate mailbox, hijacked. This is the scam known as BEC, business email compromise, and it produces a loss and a lawsuit at the same time: both companies are victims, and one of them will be left holding the bill.
The deciding question: where was the criminal?
Legally, the dispute between the two companies revolves around diligence: who left the door open and who failed to check what was reasonable. Technically, that debate only leaves the realm of guesswork with one answer: in which environment was the fraudster operating? If the hijacked mailbox was the supplier's, from which the false instruction departed, the weight tilts one way; if the compromise was on the buyer's side, which received the legitimate message and had the screen switched before its eyes, it tilts the other; if no environment was breached and everything ran through a look-alike domain registered the day before, the analysis turns to who should have noticed. Each scenario leaves distinct traces, and it is the examination that separates them.
The work covers both ends. In the message headers, the real route of each email: relay servers, authentication results (SPF, DKIM, DMARC), discrepancies between the displayed sender and the actual sender. In the mailbox logs, the signs of intrusion: logins from strange locations and devices, and above all the forwarding and hiding rules created by the intruder, the classic trick of silently diverting replies so the victim never notices the parallel conversation. In the payer's environment, the workstation artifacts confirm whether the fraudulent message truly arrived from outside or whether there was an internal compromise.
"In BEC, both companies swear their innocence, and both tell the truth they know. The expert report exists to establish the truth neither of them saw: in which environment the criminal was working."
The first hours are worth the case
Once the diversion is discovered, three clocks run at the same time. The money's: immediate contact with the banks and the filing of the police report increase the chance of freezing the funds before they are scattered. The evidence's: authentication records and provider logs expire, and the mailboxes keep being used, overwriting traces; forensic preservation of the messages, full headers, and access logs must happen before IT's well-intentioned "cleanup". And the contract's clock: cyber insurance policies and notification clauses have their own deadlines, and formal non-compliance costs the coverage. All three races depend on the same initial gesture: treating the episode as an investigation scene, not as an embarrassment to be resolved over the phone.
Worth noting: the examination also protects the party that paid correctly. When the report demonstrates that the instruction came from the hijacked supplier's legitimate mailbox, the paying company ceases to be negligent and becomes the creditor in the debate.
What the expert report establishes
- The anatomy of the fraud: fake domain, hijacked mailbox, or internal diversion, with the traces of each hypothesis tested;
- The complete timeline: from the first unauthorized access to the fraudulent payment instruction;
- The indicators of diligence and failure in each environment: email authentication configured or absent, alerts ignored, double verification practiced or not;
- The technical basis for the liability debate between the companies, for the insurer, and for criminal prosecution.
Variations on the same scam
The diverted supplier payment is the classic form, but the family is large. In the fake executive fraud, the finance department receives the message "from the president" requesting an urgent and confidential transfer, almost always on a Friday afternoon, exploiting hierarchy and haste. In the HR variation, the "employee" asks to change the salary deposit account days before payday. In the fake invoice scheme, the legitimate invoice is intercepted and reissued with a tampered barcode. The common denominator is the same: the scam does not attack the system, it attacks the routine, the repeated gesture of paying what looks right. And the technical signature also repeats: examining the headers, the access logs, and the mailbox rules reveals where the conversation was intercepted and which link trusted when it should have verified. Whoever has mapped one variation recognizes the others; whoever has never examined any pays the next fake invoice.
The prevention that costs a phone call
No technological control replaces the golden rule against BEC: new or changed bank details are confirmed through a second channel, a call to the supplier's already-known number, never to the phone listed in the suspicious email itself. Alongside it, multi-factor authentication on corporate mailboxes, well-configured domain authentication policies, alerts for newly created forwarding rules, and training the finance team to distrust urgency. The scam exploits precisely the trust built over a long conversation; the defense is to institutionalize distrust at the only moment that matters: the eve of the payment.
When prevention fails, the dispute remains, and it will be decided by the quality of the evidence each side preserved. The company that freezes the traces on day one enters the negotiation, the lawsuit, or the insurance claim with demonstrated facts. The one that "fixes" the hijacked mailbox before preserving enters with a story, and stories, against expert reports, tend to lose.
In BEC, the bill always lands on whoever has less evidence. The examination exists so that it will not be you.
