Business email compromise often succeeds because a single altered invoice or payment instruction looks routine. The legal file starts with proving what the legitimate instruction was, what changed, and which mailbox or domain carried the fraudulent request.
Preserve the full email thread with headers, not just the body text. Save prior authentic invoices, vendor master-file entries, call logs confirming any “urgent” change, and the wire confirmation showing the diverted beneficiary account.
Notify the sending bank promptly and ask whether a recall or fraud flag can still reach intermediary or beneficiary banks. Parallel notice to the receiving bank—when identifiable—may matter if funds have not fully cleared.
Internal IT should image or export relevant mailboxes before auto-deletion or remediation overwrites logs. A clean technical trail supports both institutional notices and any later civil disclosure applications.
Disclaimer: This article provides general information only. It is not legal advice and does not guarantee recovery in any matter.