WhatsApp
Scenario · Professional services · Incident response forensics · London

Investigating a payment fraud email compromise for a London business

Typical client: A London professional services firm

A composite scenario based on the kind of work we are instructed on. Identifying details are removed and it does not describe a specific client.

How we would help a London firm find out how a fraudster intercepted client payment emails and what data was exposed.

The challenge
A London professional services firm discovers that a client paid a large invoice into a fraudster's bank account after receiving what looked like a genuine email from the firm. Leadership needs to know how the mailbox was accessed, what else was seen, and whether to notify the ICO within 72 hours.
Our approach
We would preserve the Microsoft 365 audit and sign-in logs before they roll over, then examine the affected mailboxes for malicious forwarding rules, suspicious logins and data accessed. We would image the relevant user devices to check for credential theft malware, and set out the attack timeline in plain English for the board, insurers and the police.
The outcome
The firm would have a clear, evidenced account of the compromise to support its insurance claim and any ICO notification decision, plus practical steps to close the gap. Our findings would be prepared to evidential standard in case civil recovery or a criminal complaint follows.