Skip to content
ScamVictimLawyer

What to save after a BEC attack

A fake supplier email got paid, and now your business needs a clear record.

Updated 2026-09-29 · Independent resource. Legal review pending.

Why BEC evidence needs a business-wide view

A business email compromise (BEC) attack rarely involves just one email. It usually touches an inbox, an approval chain, a supplier record, and a payment system, so the evidence sits across several systems rather than one folder.

Treat this as gathering a full account, not just forwarding the suspicious email to your bank. Missing one piece, such as who approved the payment, can slow down a bank dispute or a later claim.

Preserve the email exactly as it arrived

Save the fraudulent email in its original format, not a screenshot, so the full technical headers are kept intact. Read how to keep email headers for a BEC case if your email system makes this hard to find.

Keep the genuine email thread it copied or replaced, if one exists, alongside the fake version. Comparing the two often shows exactly where the scam entered, such as a slightly altered sender domain.

Record the internal approval trail

List who received the request, who approved the payment, and what checks were or were not done at each step. A short written note from each person involved, while memory is still fresh, is often as valuable as the email itself.

Save the invoice, the payment instruction, and the transfer confirmation together, with the date and time of each. This builds a clear internal timeline that a bank, the police, or a lawyer can follow.

Keep the bank and payment records

Save the transfer confirmation, the receiving account number, and any correspondence with your bank about a recall attempt. Read how a bank recall works so you understand what your bank can and cannot do once funds have moved.

Do not close or archive the payment record in your accounting system while the case is open, even if it needs to be reversed for your books later.

What to do next

Once the internal record is together, report through your bank’s recall process and make a police report so the Commercial Crime Investigation Department can open a case. A civil claim may be worth exploring for larger amounts if the receiving account can be identified.

A clear, complete file makes it far easier for anyone helping your business to assess the case quickly. You do not need every document perfect before you start that conversation.

If your business is still gathering what happened, tell us the timeline and what you have saved so far, and we can help you see the realistic next step.

Common questions

Do we need IT to help preserve the email evidence?

It helps, since IT can export the full email with its technical headers rather than a screenshot alone. If IT support is not available quickly, save the email in its original format first and involve them once the immediate reporting is done.

Should we keep the fraudulent invoice even though it was fake?

Yes. The fake invoice, along with the genuine one it copied or replaced, shows exactly how the request was disguised. Keep both versions together with the dates each one was received.

What if several staff members were involved in approving the payment?

Get a short written account from each person involved while the details are still fresh, including who received the request and who approved it. This internal timeline is often as useful as the email itself.

If your business is still gathering what happened, tell us the timeline and what you have saved so far, and we can help you see the realistic next step.