Business Email Compromise: Stop Invoice Fraud & CEO Fraud

Detect compromised email accounts, stop the fraud, and recover funds.

Compromised email account? We stop the fraud right away.

Acting fast prevents further wire transfers and data loss. We help you lock out the attacker and secure the evidence right away.

To help you as quickly as possible, please have the following information ready:

  • Affected mailboxes and users
  • Time of discovery
  • Wire transfers already initiated
  • Suspicious rules or logins
Get help now

Payment diversion or CEO fraud? How to act right now

A so-called Business Email Compromise attack often goes unnoticed until a fake invoice has been paid or a suspicious email appears in the inbox. At that moment, it matters what you do next and what you deliberately avoid doing, so that the evidence stays intact. Changed mailbox rules, sent emails, or unusual logins are clear signs that your account has been taken over.

aramido handles the forensic analysis of compromised email mailboxes for M365 and other providers. We reconstruct who logged in when, which rules the attacker created, and which data was accessed. These facts form the basis for filing a report with the police, the bank, and the insurer, and for recovering payments that have already been made.

A stopwatch as a metaphor for immediate intervention

Immediate Intervention

You reach us with no waiting. The sooner we end sessions and block access, the smaller the damage caused by fraudulent payments.

A padlock as a metaphor for discretion

Discreet Crisis Support

We work in the background, document the chain of custody without gaps, and prepare the cooperation with the bank, the ZAC, and, if needed, the insurer.

A microscope as a metaphor for forensic excellence

Forensic Excellence

We examine the MFA configuration, mail flow rules, and audit logs to precisely reconstruct the scope and path of the fraud.

Understand business email compromise and contain it

What is a business email compromise?

Business Email Compromise (BEC) is a type of fraud in which attackers take over a business email account or imitate its sender to trick employees into making wire transfers or handing over data. The best-known forms are the CEO fraud scheme, manipulated invoices, and falsified account details. According to one analysis, up to 81 % of cyber incidents in mid-sized companies are attributed to BEC; in 2025 alone, BEC caused damage of more than 200 million euros in Germany. aramido secures the traces of this fraud forensically and provides the reliable basis for recovering funds and protecting against repeat incidents.

  • 1
    We clarify which mailboxes are affected, when the access began, and whether payments have already been triggered.
  • 2
    Active sessions are ended, compromised accounts are blocked, and passwords are rotated to stop the fraud.
  • 3
    The analysis of audit logs and mail flow rules reveals the entry path and the actions taken by the attacker.
  • 4
    We remove planted rules and backdoors and close the security gap through which the access was gained.
  • 5
    Mailboxes and processes are safely restored, with verified MFA and strict access policies.
  • 6
    The incident is documented and measures are derived to prevent and stop future BEC attacks early.

Email fraud? Request help now

Briefly describe what happened. Tell us which mailboxes are affected, the time of the incident, and whether payments have already been triggered. We stop the fraud, secure the traces, and prepare the communication with the bank and the authorities. In urgent cases, reach us directly via our emergency hotline: +49 721 451 99 112.

Status

Please enable JavaScript to use the form.

Expose BEC tactics, regain digital sovereignty

BEC attacks use a wide range of psychological strategies to remain undetected. We analyze these patterns to systematically uncover the deception.

Typical BEC attack patterns

Fake Invoices

Fake Invoices

Fake supplier invoices with manipulated bank details divert payments to accounts controlled by the attackers.

CEO Fraud

CEO Fraud

Fraudsters impersonate the management to force urgent wire transfers.

Account Compromise

Account Compromise

By gaining access to real mailboxes, internal processes are observed and payments are manipulated directly.

Attorney Impersonation

Attorney Impersonation

The identity of a legal representative is used to pressure employees and steal data.

Data Theft

Data Theft

Attackers gain access to sensitive employee or customer data for later fraud attempts.

Payroll Diversion

Payroll Diversion

Manipulations in the payroll administration cause salary payments to flow into foreign accounts.

Our forensic clarification

BEC attacks are designed to remain invisible. Because they do not use classic malware files but rely on psychological manipulation and identity deception, standard security tools often fall short. We therefore do not look at individual emails in isolation, but analyze the entire communication chain and the underlying infrastructure to systematically uncover the deception.

We combine the analysis of technical protocols with a detailed reconstruction of the attack paths. We not only identify the point of entry, but also trace every interaction of the attacker within your systems. This holistic approach ensures that we detect even subtle manipulations that would have remained hidden in a spot check.

Our goal is the complete restoration of your digital security. We make sure that no manipulated artifacts remain in your mailboxes or files and that all backdoors are closed. Through the complete clarification, you understand exactly how the attack succeeded.

Together we use these findings to harden your processes and sustainably protect your company against future attempts at deception.

Frequently asked questions about business email compromise

Our aramido Response Team (aRT) is available 365 days a year during core hours (8 AM to 6 PM) via hotline and email. Customers with a framework agreement receive an initial response within 4 hours during core hours. Containment typically takes one to three days; the final report is usually delivered one to two weeks after the incident.
It is important not to lock the account or delete emails, so that the evidence stays intact. Instead, you should end active sessions, rotate the password, and check the MFA registration. Afterwards, the logs allow us to reconstruct what the attacker did. aramido takes over this forensic evaluation and coordinates the communication with the bank and the authorities.
A fast reaction increases the chance of a chargeback. We document the fraud path, secure the evidence, and prepare the communication with your bank and the ZAC. Whether and how quickly the bank returns a payment depends on the individual case and the deadlines.
Watch out for a slightly changed sender address, a swapped bank account, and unusual urgency. Always verify payment changes through a known contact path that is stored separately, not through the details in the email. Our factsheet with the seven golden rules against social engineering explains further warning signs.
Yes. We collect the data according to recognized industry standards such as ISO/IEC 27037 and maintain an unbroken chain of custody. Our reports are forensically sound and withstand review by lawyers, regulators, or insurers.
In the eradication phase, we remove manipulated rules and backdoors and permanently close the security gap. At the same time, we harden the access with MFA and access policies and set up monitoring that informs us of renewed access attempts.
If personal data is affected, GDPR requires you to report the incident within 72 hours. Affected NIS-2 entities report significant security incidents to the BSI. aramido provides the technical facts that your legal department needs for a correct and timely report.

Process incidents forensically, prevent future attacks

Digital forensics that hold up in court

The forensic analysis of a BEC incident clarifies how the access was gained, which rules were created, and which data was viewed. We secure these traces according to ISO/IEC 27037 and maintain an unbroken chain of custody. Our reports provide a basis for prosecution, insurers, and the recovery of funds.

Incident Response Readiness

How well prepared is your company for a BEC attack? Readiness means building processes and response capabilities before an attack demands them. This includes a secure payment approval process, a verified MFA standard, and clear decision paths. aramido analyzes your workflows, identifies gaps, and makes your team capable of acting before an incident occurs.