ArcanaIncident-response documentationBrowse the feedTemplates
Back to feed
Runbook · Analysis
RB-ANALYSIS-038

Financial Fraud Impact Assessment

1. Prerequisites

  • Confirmed or suspected BEC incident
  • Access to affected communications
  • Access to Finance stakeholders
  • Access to vendor management records
  • Investigation timeline established

2. Step-by-Step Instructions

  1. Identify Fraud Scenario

    • Determine:
      • Payment fraud
      • Payroll fraud
      • Vendor fraud
      • Invoice fraud
  2. Identify Affected Parties

    • Identify:
      • Employees
      • Vendors
      • Customers
      • Partners
  3. Review Fraudulent Communications

    • Analyse:
      • Emails
      • Attachments
      • Payment instructions
  4. Determine Financial Exposure

    • Identify:
      • Requested transfers
      • Completed transfers
      • Pending transactions
  5. Review Banking Information

    • Identify:
      • Fraudulent account changes
      • Vendor banking modifications
      • Payroll modifications
  6. Coordinate with Finance

    • Confirm:
      • Transactions completed
      • Transactions blocked
      • Recovery opportunities
  7. Assess Business Impact

    • Determine:
      • Financial loss
      • Operational impact
      • Regulatory implications
  8. Assess Recovery Opportunities

    • Determine:
      • Recall opportunities
      • Bank notifications
      • Fraud investigations
  9. Document Findings

    • Prepare impact summary.
  10. Escalate and Hand Off

    • Provide findings to leadership and recovery teams.
    • Update the incident record.

3. Post-Action

  • Preserve supporting evidence.
  • Document financial impact.
  • Track recovery actions and outcomes.

Contributor

Vishal Thakur
GitHub: https://github.com/malienist

Contributed to the Arcana Incident Response Documentation Framework.