logo

Observations From Business Email Compromise (BEC) Attacks

ID: 6c82e03e-c5d8-579c-abaf-f925a1af7baf

STIX ID: report--6c82e03e-c5d8-579c-abaf-f925a1af7baf

Feed Name: TrustedSec blog

Threat Score
50/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This article provides investigative guidance for business email compromise (BEC) incidents, stressing the importance of log analysis, message-header and IOC extraction, inspection of mailbox inbox rules (and automated enumeration via PowerShell) to find message redirection/persistent collection, and review of MFA and OAuth registrations to detect bypass or persistence; it aims to help reduce attacker dwell time and improve detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.