Compromised email account? We stop the fraud right away.
To help you as quickly as possible, please have the following information ready:
- Affected mailboxes and users
- Time of discovery
- Wire transfers already initiated
- Suspicious rules or logins
Payment diversion or CEO fraud? How to act right now
A so-called Business Email Compromise attack often goes unnoticed until a fake invoice has been paid or a suspicious email appears in the inbox. At that moment, it matters what you do next and what you deliberately avoid doing, so that the evidence stays intact. Changed mailbox rules, sent emails, or unusual logins are clear signs that your account has been taken over.
aramido handles the forensic analysis of compromised email mailboxes for M365 and other providers. We reconstruct who logged in when, which rules the attacker created, and which data was accessed. These facts form the basis for filing a report with the police, the bank, and the insurer, and for recovering payments that have already been made.

Immediate Intervention
You reach us with no waiting. The sooner we end sessions and block access, the smaller the damage caused by fraudulent payments.

Discreet Crisis Support
We work in the background, document the chain of custody without gaps, and prepare the cooperation with the bank, the ZAC, and, if needed, the insurer.

Forensic Excellence
We examine the MFA configuration, mail flow rules, and audit logs to precisely reconstruct the scope and path of the fraud.
Understand business email compromise and contain it
What is a business email compromise?
Business Email Compromise (BEC) is a type of fraud in which attackers take over a business email account or imitate its sender to trick employees into making wire transfers or handing over data. The best-known forms are the CEO fraud scheme, manipulated invoices, and falsified account details. According to one analysis, up to 81 % of cyber incidents in mid-sized companies are attributed to BEC; in 2025 alone, BEC caused damage of more than 200 million euros in Germany. aramido secures the traces of this fraud forensically and provides the reliable basis for recovering funds and protecting against repeat incidents.
- 1We clarify which mailboxes are affected, when the access began, and whether payments have already been triggered.
- 2Active sessions are ended, compromised accounts are blocked, and passwords are rotated to stop the fraud.
- 3The analysis of audit logs and mail flow rules reveals the entry path and the actions taken by the attacker.
- 4We remove planted rules and backdoors and close the security gap through which the access was gained.
- 5Mailboxes and processes are safely restored, with verified MFA and strict access policies.
- 6The incident is documented and measures are derived to prevent and stop future BEC attacks early.
Email fraud? Request help now
Briefly describe what happened. Tell us which mailboxes are affected, the time of the incident, and whether payments have already been triggered. We stop the fraud, secure the traces, and prepare the communication with the bank and the authorities. In urgent cases, reach us directly via our emergency hotline: +49 721 451 99 112.
Expose BEC tactics, regain digital sovereignty
BEC attacks use a wide range of psychological strategies to remain undetected. We analyze these patterns to systematically uncover the deception.
Typical BEC attack patterns

Fake Invoices
Fake supplier invoices with manipulated bank details divert payments to accounts controlled by the attackers.

CEO Fraud
Fraudsters impersonate the management to force urgent wire transfers.

Account Compromise
By gaining access to real mailboxes, internal processes are observed and payments are manipulated directly.

Attorney Impersonation
The identity of a legal representative is used to pressure employees and steal data.

Data Theft
Attackers gain access to sensitive employee or customer data for later fraud attempts.

Payroll Diversion
Manipulations in the payroll administration cause salary payments to flow into foreign accounts.
Our forensic clarification
BEC attacks are designed to remain invisible. Because they do not use classic malware files but rely on psychological manipulation and identity deception, standard security tools often fall short. We therefore do not look at individual emails in isolation, but analyze the entire communication chain and the underlying infrastructure to systematically uncover the deception.
We combine the analysis of technical protocols with a detailed reconstruction of the attack paths. We not only identify the point of entry, but also trace every interaction of the attacker within your systems. This holistic approach ensures that we detect even subtle manipulations that would have remained hidden in a spot check.
Our goal is the complete restoration of your digital security. We make sure that no manipulated artifacts remain in your mailboxes or files and that all backdoors are closed. Through the complete clarification, you understand exactly how the attack succeeded.
Together we use these findings to harden your processes and sustainably protect your company against future attempts at deception.
Frequently asked questions about business email compromise
Process incidents forensically, prevent future attacks
Digital forensics that hold up in court
The forensic analysis of a BEC incident clarifies how the access was gained, which rules were created, and which data was viewed. We secure these traces according to ISO/IEC 27037 and maintain an unbroken chain of custody. Our reports provide a basis for prosecution, insurers, and the recovery of funds.
Incident Response Readiness
How well prepared is your company for a BEC attack? Readiness means building processes and response capabilities before an attack demands them. This includes a secure payment approval process, a verified MFA standard, and clear decision paths. aramido analyzes your workflows, identifies gaps, and makes your team capable of acting before an incident occurs.





