Business Email Compromise Investigation
Business email compromise investigation in British Columbia.
A payment went to the wrong account, or a mailbox was used to send invoices nobody authorized. We reconstruct what the attacker did inside Microsoft 365 or Google Workspace, how they got in, and what data they touched, in a report written for insurers, counsel, and regulators.

When this service is needed
Typical scenarios where counsel and corporate clients retain us.
- Wire or invoice payment diverted to an attacker's account
- Mailbox takeover with forwarding or inbox rules discovered
- Cyber insurance claim that needs a forensic scope
- Phishing sent from a compromised employee mailbox
- Possible access to client or personal information under PIPEDA or BC PIPA
- Vendor or partner reports fraudulent emails from your domain
How we approach it
A defensible, repeatable process.
Tools we apply
Named, current, and listed in every report.
- Microsoft Purview Audit (Standard and Premium)
- Microsoft Entra ID sign-in and audit logs
- Exchange Online message trace and mailbox audit
- Google Workspace admin audit and Vault
- Magnet AXIOM Cyber for endpoint follow-up
Standards we follow
Aligned to Canadian and international guidance.
- NIST SP 800-61 incident handling
- PIPEDA and BC PIPA breach notification thresholds
- Sedona Canada Principles on ESI preservation
What you receive
Deliverables built for counsel, the regulator, and the court.
Forensic image, examiner report, exhibits and hash logs, and an expert affidavit where the matter requires it.
Common questions
Business Email Compromise Investigation questions from Canadian counsel and corporate clients.
How do you find out how the attacker got into the mailbox?
Answer pending.
Can you tell which emails the attacker actually read or exported?
Answer pending.
Do we need to notify anyone after a business email compromise?
Answer pending.
Will the report work for our cyber insurance claim?
Answer pending.
How fast do we need to start after the fraud is discovered?
Answer pending.
Can the investigation be done remotely?
Answer pending.
Related services
Often retained alongside business email compromise investigation.
Data Breach Investigation
Defensible breach investigation built for PIPEDA, BC PIPA, and OPC or OIPC interface.
Explore serviceMicrosoft 365 Audit Log & Insider Investigation
Reconstruction of user activity across Microsoft 365 from the unified audit log, Entra ID, SharePoint, and Exchange for departing-employee and misconduct matters.
Explore serviceCloud Forensics
Defensible collection and analysis of Microsoft 365, Google Workspace, AWS, Slack, Teams, and Salesforce evidence under legal hold.
Explore serviceNeed business email compromise investigation support on a Canadian matter?
Book a confidential consultation. Our team will reach out as soon as possible.
