1. Prerequisites
- Confirmed or suspected BEC incident
- Access to affected communications
- Access to Finance stakeholders
- Access to vendor management records
- Investigation timeline established
2. Step-by-Step Instructions
-
Identify Fraud Scenario
- Determine:
- Payment fraud
- Payroll fraud
- Vendor fraud
- Invoice fraud
- Determine:
-
Identify Affected Parties
- Identify:
- Employees
- Vendors
- Customers
- Partners
- Identify:
-
Review Fraudulent Communications
- Analyse:
- Emails
- Attachments
- Payment instructions
- Analyse:
-
Determine Financial Exposure
- Identify:
- Requested transfers
- Completed transfers
- Pending transactions
- Identify:
-
Review Banking Information
- Identify:
- Fraudulent account changes
- Vendor banking modifications
- Payroll modifications
- Identify:
-
Coordinate with Finance
- Confirm:
- Transactions completed
- Transactions blocked
- Recovery opportunities
- Confirm:
-
Assess Business Impact
- Determine:
- Financial loss
- Operational impact
- Regulatory implications
- Determine:
-
Assess Recovery Opportunities
- Determine:
- Recall opportunities
- Bank notifications
- Fraud investigations
- Determine:
-
Document Findings
- Prepare impact summary.
-
Escalate and Hand Off
- Provide findings to leadership and recovery teams.
- Update the incident record.
3. Post-Action
- Preserve supporting evidence.
- Document financial impact.
- Track recovery actions and outcomes.
Contributor
Vishal Thakur
GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
