A changed invoice or urgent wire request may be the visible end of a longer sequence. The route can include a stolen browser session, captured credentials, unauthorized application consent, mailbox delegation, a hidden rule, a look-alike domain, or access through a supplier. For a New York business, law firm, nonprofit, healthcare organization, or financial team, the first day should answer three practical questions: Is money still at risk? Does an unauthorized party retain access? Which records will explain the event after routine cloud retention and response activity alter the environment?
Open a financial track and a technical track
The finance lead should verify pending instructions outside the questioned email thread. Use a previously known telephone number or another independently established channel to reach the bank, intended recipient, vendor, and internal approver. Suspend unreleased payments where authorized. If funds moved, contact the financial institution's fraud team promptly and preserve the case or recall reference it provides. A request through the FBI Internet Crime Complaint Center may also be appropriate. No response step guarantees recovery.
At the same time, assign a technical lead and a written action log. Record who approved each containment step, the time performed, the account or system affected, and the observed result. Do not use the suspect mailbox to coordinate the response or validate new banking details. Counsel, insurers, law enforcement, and contractual partners may need notice, but the organization and its counsel control those decisions. GDF supplies technical analysis and does not provide legal advice.
- Confirm whether any payment remains pending or can be recalled
- Move response communications to a trusted channel
- Preserve known fraudulent instructions, bank details, and approval records
- Name one owner for financial actions and one for technical actions
Take a tenant snapshot before cleanup
A password reset is not an evidence collection. Before or alongside containment, capture the account's current security state and the records most likely to expire. For Microsoft 365, that may include Entra sign-ins, unified audit events, message trace, mailbox audit activity, authentication-method changes, registered devices, inbox rules, forwarding settings, delegates, transport configuration, OAuth grants, application activity, alerts, and administrative changes. Google Workspace has different logs, controls, export methods, and retention conditions.
Document the tenant, account identifiers, administrator, collection time, time zone, license, available date range, query or export settings, and errors. Retain native output where the platform permits it. A screenshot can preserve what an administrator saw, but it usually omits event fields, identifiers, pagination, and surrounding records needed for repeatable analysis. Provider availability changes by product, subscription, configuration, and event age, so the source matrix should state what was requested, obtained, or unavailable.
Remove access without erasing the sequence
Containment should address more than the password. An unauthorized party may retain a refresh token, browser session, registered authentication method, delegated permission, application grant, forwarding rule, or access through another account. The approved sequence may include restricting sign-in, revoking sessions and tokens, resetting credentials, reviewing multifactor authentication methods, removing unauthorized applications and delegates, correcting rules, and securing recovery channels.
Coordinate those actions with collection because the changes create new audit events and can destroy useful context. Record the before state, exact action, actor, time, and after state. Review privileged identities, shared mailboxes, service accounts, and administrators that could reach the affected mailbox. Recovery includes confirming expected forwarding, delegation, transport, application consent, and authentication settings after access is restored.
Reconstruct the communication from independent records
Preserve the entire business conversation, not only the message that contains payment instructions. Obtain native messages with headers, attachments, earlier thread versions, replies from external parties, accounting entries, approval records, telephone notes, and bank correspondence. Mailbox copies alone may not show whether a message was delivered, altered in a reply, created from a look-alike domain, or sent through another tenant. Transport and provider records can supply separate timing and routing evidence.
Build the sequence across systems: the legitimate commercial exchange, first suspicious access, rule or permission changes, reconnaissance of prior messages, altered payment request, internal approval, transaction, discovery, and response. Normalize time zones while preserving source timestamps. Distinguish a fact recorded by a system from a statement supplied by a person. Where records conflict, retain both and identify what additional evidence could resolve the difference.
Expand scope through evidence, not assumption
Start with the known account and then test connected exposure. Search for common infrastructure, related sign-ins, repeated application identifiers, similar rules, shared delegates, suspicious domains, messages sent to other payment participants, and access to cloud files or collaboration services. Check whether the event touched shared mailboxes, executives, finance personnel, suppliers, customers, or administrators. Each expansion should have a recorded reason and result.
An IP address does not identify a person. A successful sign-in does not by itself prove that a particular message or file was viewed. The absence of an audit event may reflect logging configuration, retention, product limitations, or an action the platform does not record. The chronology should label confirmed activity, supported inference, information reported by others, competing explanations, and unresolved gaps. This separation makes later legal, insurance, accounting, and management decisions more reliable.
Use a first-day operating rhythm
The schedule is driven by active risk and evidence life, not an arbitrary checklist. During the opening hours, protect payment channels, move communications, identify authority, record the known timeline, and preserve volatile identity and mail data. The next cycle should close persistence, collect related sources, test whether other accounts are involved, and give leadership a factual status report. Before the first day ends, reconcile completed actions, unresolved exposure, missing records, and the owners of the next decisions.
- Opening hours: protect money movement and preserve short-lived records
- First work cycle: remove persistence and collect independent message evidence
- Scope cycle: test related accounts, applications, mailboxes, files, and counterparties
- Handoff: state confirmed facts, open risks, unavailable evidence, and assigned actions
Prepare a record New York decision makers can use
A useful first-day package includes the action log, source inventory, custody record, normalized chronology, affected identities and systems, payment facts, persistence findings, known data-access evidence, collection gaps, and immediate control recommendations. Preserve original exports and note any transformations used for review. A concise executive update should identify what is known, what remains exposed, which statements are provisional, and when the next technical decision is due.
New York notification, privacy, employment, contractual, and law-enforcement questions belong with counsel and accountable organizational leaders. Technical responders should preserve the facts those professionals need without turning a preliminary alert into a legal conclusion. If expert analysis later becomes necessary, the acquisition record, native cloud data, tested alternatives, and documented limits provide a stronger foundation than a narrative reconstructed from memory.