Digital Forensics Investigation of an Email Fraud Incident
A one-month investigation that established the most likely cause of a misdirected payment, later confirmed by the police.
United States
Background
The company asked us to investigate a security breach that had occurred several months earlier and caused a significant financial loss. Someone altered the payment details in the company’s email correspondence, and a substantial sum went to an account that was not the intended one. Nobody noticed until the payment failed to arrive where it was expected.
The company reported the case to the police and asked us to run a parallel digital forensics investigation.
Two things had to be established, where the attacker obtained the information about the payment, and how the correspondence was altered. Both questions determined what the company had to change to prevent this from happening again.
The weeks between the attack and its discovery reduced what the investigation could recover. Logs have retention limits and employees remember the details of correspondence for a limited period, which is why an investigation that starts weeks after the event recovers less than one that starts immediately.
Challenge
The company had no visibility into how the manipulation had happened. Email correspondence about a payment involves several people on both sides, it passes through mail systems that neither party fully controls, and a change in a bank account number leaves no obvious trace in the message itself. The company found nothing in its environment that identified the entry point.
The investigation had to answer several questions at once:
- how the attacker learned about the payment and its details;
- which user account or device served as the entry point;
- whether the corporate environment had been compromised, and if so, for how long;
- whether the interference came from outside the company, on the side of the correspondence partner;
- what evidence the police would need to continue the case.
Solution overview
We ran a structured digital forensics investigation across the company’s Microsoft 365 and Azure environments, combining log analysis, employee interviews and attack scenario modelling. The work took one month.
The company gave us administrative access to the systems holding the relevant evidence, including Microsoft 365 Admin Center, Microsoft Entra ID, Azure Portal, Microsoft Intune and Microsoft security portals. This access was essential for building findings based on evidence rather than assumptions.
From company-wide screening to the most likely cause
The investigation started with a company-wide review of authentication and access activity. Around fifty employees were screened, which narrowed the scope to four users whose accounts or devices could plausibly have served as entry points.
For those users, we examined corporate devices, reviewed access history and conducted interviews to reconstruct what had happened around the correspondence.
Reconstructing the correspondence and testing scenarios
We analysed the payment-related email flows to determine where the details may have been changed and what messages each party actually received.
Several possible attack scenarios were then tested against the available evidence. Scenarios contradicted by the logs were discarded, while those supported by the evidence were retained. This allowed us to identify the most likely cause while clearly separating confirmed findings from assumptions and scenarios that could not be ruled out.
Preparing the material for the police
The police were investigating the incident in parallel. We therefore organized the relevant logs, timeline, findings and supporting evidence into a structured handover package that could be used directly in their investigation.
Results
We completed the digital forensics investigation in one month and identified the most likely cause of the incident.
The police reached the same conclusion in their own investigation.
The investigation found no evidence of compromise on the corporate devices and no unauthorized applications or malware in the corporate environment. That result narrowed the search considerably, because it showed that the entry point was outside the systems the company manages, among the personal devices and the external side of the correspondence that no internal audit would have covered.
Alongside the conclusion, the company received recommendations on the controls that would prevent a repetition, covering how payment details are confirmed, how corporate email is accessed from outside the managed environment, and what the company monitors in Microsoft 365 to notice this class of attack while it is still developing rather than weeks later.
About IBA Group
IBA Group has been delivering custom projects for more than 30 years and works with clients in over 50 countries. Our security practice covers penetration testing across web, mobile, network, cloud, infrastructure, LLM and IoT environments, as well as source code and architecture reviews, red team and social engineering assessments, phishing simulations, OSINT, and digital forensics and incident investigations.
Want to hear it from the client?
Request a reference and we will send you what the company said about our work.
