Skip to content
ScamVictimLawyer

A BEC Incident Response Checklist

Your business just discovered a fraudulent payment and needs a clear response plan.

Updated 2026-09-29 · Independent resource. Legal review pending.

The first hour: stop and verify

The first response is always the same regardless of how the fraud happened. Stop any pending or related payment, and verify what actually occurred before assuming the worst or the best. Do not wait for a full picture before pausing payments connected to the suspicious request.

Call your bank’s fraud line directly, not the general customer service line, and ask about a recall on the specific transfer. Read how to recall a corporate wire transfer for detail on what your bank can realistically do.

The first day: report and preserve

Report to the police and lodge a case with the Commercial Crime Investigation Department. Call the National Scam Response Centre on 997 if the transfer was recent. Preserve the original email with its headers, the invoice or instruction, and every internal approval message.

Do this even while details are still being confirmed internally, since a documented report supports the bank dispute and any later step. What to save after a BEC attack covers this in more detail.

The first week: trace the source and check exposure

Work out how the scam entered: a compromised inbox, a lookalike domain, or a leaked document. This affects both your bank dispute and how you prevent a repeat. If the compromised account may have held customer or employee data, check what a data breach after BEC means for your business.

If the fraud involved a supplier invoice, verify your suppliers again through a separate channel. One compromised inbox can be used to target more than one payment.

Ongoing: tighten controls and check insurance

Once the immediate response is done, tighten your payment controls so the same gap cannot be used again. Dual approval, callback verification, and holds on new supplier accounts are common, low cost changes that make a real difference.

Check whether your business holds a policy that might respond to this loss. Read cyber fraud and business insurance to see what an insurer typically needs to assess a claim.

What to do next

Work through the stages in order rather than trying to do everything at once: stop, report, preserve, trace, then prevent. Each stage supports the next, and skipping ahead can mean losing evidence the earlier stage would have kept.

If the amount is significant, a first legal assessment can help. It can show whether a formal letter of demand or a civil claim against the receiving account is worth pursuing.

If your business is in the middle of a BEC incident right now, tell us what happened and we will help you see the right order of steps.

Common questions

What is the first thing our business should do after discovering BEC?

Stop any pending payment linked to the suspicious instruction immediately, then contact your bank's fraud line using a number you already have on file. Every hour matters in the first day, since a transfer that is still moving can sometimes still be recalled or held.

Who inside the company should be involved in the response?

Finance, IT, and a senior decision maker should be involved from the start, since the response usually needs a payment action, a technical check, and an approval all at once. Bringing in a lawyer early is also worth considering once the amount is significant.

How long does a full BEC response usually take?

The first response happens within hours or days, but tightening controls, working with your bank or insurer, and any legal step can take weeks. Treat it as a set of stages rather than one task to finish quickly.

If your business is in the middle of a BEC incident right now, tell us what happened and we will help you see the right order of steps.