Active Incident? 24/7 Response →
Witness

For Small Business

Hit by a BEC Scam? The First 48 Hours for Small Businesses

Wire fraud via fake invoice or vendor switch hits small businesses hardest. The recovery window is days, not weeks. Here is the playbook.

All articles·9 min read·April 21, 2026

If a wire just left, do this in the next hour

Speed is the entire game with business email compromise (BEC). The FBI's Financial Fraud Kill Chain (FFKC) can recover funds, but only when the receiving bank is contacted before the attacker pulls the money out. Recovery odds drop from ~75% in the first 24 hours tosingle digits after 72 hours.

The 60-minute checklist

  1. Call your bank's wire fraud department. Not the branch. Not the customer service line. The fraud or AML team. Tell them you have an unauthorized wire and request a recall under "fraudulent payment order" / Article 4A reasoning.
  2. File at IC3.gov. The FBI's Internet Crime Complaint Center is the federal triage point. Note the exact wire amount, sending and receiving bank, account numbers, and timestamp. IC3 is what triggers the FFKC process.
  3. Email your bank in writing. Within the hour, follow up your phone call with an email so you have a paper trail of when you reported the fraud. Your insurance policy will require this.
  4. Lock down the compromised inbox. Sign out all sessions, rotate the password, audit and delete any forwarding rules or filters, revoke OAuth grants. See our forensic checklist for compromised email.
  5. Tell your insurance broker. Most cyber policies have a 24-72 hour notice requirement. Late notice can void coverage.

Day 1-2: forensic preservation

Before anyone "cleans up" the compromised mailbox, preserve it forensically. The evidence you need:

If your IT vendor has already "fixed it" by deleting suspicious rules and resetting passwords without preserving the artifacts, your insurance claim and any subsequent litigation just got harder. We recover what is recoverable from incident response engagements like this.

How BEC scams actually work — so you can prevent the next one

Three patterns explain ~90% of small-business BEC losses:

The insurance reality

What we do

24/7 incident response for BEC eventsrapid containment, forensic preservation, recovery coordination with your bank and theFBI, and the written report your insurance carrier and counsel will need. Available as aretainer engagement for SMB clients who want a number to call before they need it.


Related services

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded Witness in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

BEC response: frequent questions

Certified Expertise

GIAC · AWS · Splunk · CompTIA

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management