Skip to content
ScamVictimLawyer

Handle a Data Breach After BEC

A compromised inbox may have exposed personal data, and you need to know what comes next.

Updated 2026-09-29 · Independent resource. Legal review pending.

Work out what was actually exposed

Not every business email compromise case involves personal data, but many do, since a compromised inbox often holds contact lists, invoices, and correspondence with customers or employees. Start by asking IT to map exactly what the compromised account could access.

This includes attachments, linked cloud storage, and any auto forwarding rules the attacker may have set up, since these often go unnoticed for longer than the fraudulent email itself.

A password reset and a review of recent login activity should happen alongside this assessment, even before the full picture is clear. Closing off further access matters as much as understanding what was already taken.

Understand the obligations that may apply

Malaysia’s data protection law governs how personal data is handled, and the Department of Personal Data Protection is the relevant authority for compliance questions. Whether a specific notification obligation applies depends on what data was exposed and how, so this is worth checking with a lawyer rather than assuming either way.

Treat this as a separate but related track to your fraud response, since it involves compliance questions on top of the financial loss.

Decide who needs to know

If customers, suppliers, or employees may have received fraudulent messages from the compromised account, telling them directly helps prevent them from being targeted by the same attacker. A short, clear notice explaining what happened is usually enough.

This is a trust and prevention step that stands on its own, separate from any formal notification requirement your lawyer may identify. Send it through a verified channel rather than the compromised one, since replying from an affected account could confuse the message further.

Fold this into your wider response

This assessment runs alongside the rest of your BEC incident response, not instead of it. Reporting the fraud, contacting your bank, and reviewing supplier accounts still need to happen at the same time.

Tightening your internal controls afterward should also cover the email and account security gaps that allowed access in the first place, not just the payment process.

What to do next

Get IT’s assessment of what was accessed in writing, since this becomes important evidence for both your bank dispute and any compliance question. Bring a lawyer in early if the exposure looks significant, so you understand your options before deciding what to communicate.

Acting on this alongside the rest of your response, rather than after it, keeps your business better protected on every front.

Document each step of this assessment as you go, including the date and who was involved. This record supports both your compliance position and any later conversation with a lawyer or an insurer.

If your business is trying to work out whether a BEC incident involved a data exposure, tell us what happened and we will help you think through the next step.

Common questions

How do we know if customer or employee data was exposed in a BEC incident?

Work with IT to review what the compromised inbox or account could access, including attachments, contact lists, and any linked systems, not just the fraudulent email itself. This assessment tells you whether personal data protection questions apply, and it is worth doing even if you are not certain.

Do we have to inform the people whose data may have been exposed?

Malaysia's data protection law places obligations on how personal data is handled, and the Department of Personal Data Protection is the relevant authority. A lawyer can help you work out what your specific situation requires, since this depends on what data was involved and how it was stored.

Should we tell customers about the fraud itself, not just any data exposure?

If customers or suppliers may have received fraudulent emails from a compromised account, telling them directly helps prevent them from being targeted too. This is also a practical trust step, separate from any formal data protection obligation.

If your business is trying to work out whether a BEC incident involved a data exposure, tell us what happened and we will help you think through the next step.