1. Sign in to Microsoft 365 admin center.
2. Open Exchange > Mail flow rules for sarah@acmesupply.com.
3. Delete the rule named "." that moves messages containing 'invoice' to Deleted Items.
4. Reset Sarah's password and revoke active sessions.
5. Enable MFA if not already on.
InboxGuards · wire hold sheet
First 90 minutes
Printed Sep 5, 2026 · 11:47 AM · your organization · keep this with the person who approves payments
The alert that triggered this
[CRIT] Hidden inbox rule created at 2:14 AM to auto-delete invoices (after-hours — severity raised)
detected: 2026-09-05 11:29 (11:29 UTC)
account: sarah@acmesupply.com
source ip: 102.89.34.10
alert id: demo-1
Fill this in before you need it
Bank wire/fraud desk: Account manager: IT / MSP contact: Cyber insurer claims line: Policy number: Who can approve a hold:
Do these in order
1
Call the bank — by phone, not email
Ask for the wire/fraud desk and use the words "business email compromise" and "recall request". Every minute matters: recalls succeed far more often inside the first few hours. Do not send this request by email — the mailbox may still be read by the attacker.
2
Freeze any pending or scheduled payments
Pause outbound wires, ACH batches and scheduled vendor payments until the mailbox is confirmed clean. Verify new or changed bank details only by calling a number you already had on file — never a number from the email thread.
3
Lock the account
Reset the password, revoke all active sessions and refresh tokens, then require MFA. A password reset alone leaves the attacker signed in.
4
Delete the attacker's plumbing
Remove forwarding rules, inbox rules that move mail to hidden folders, added recovery emails/phones, delegated mailbox access, and any app password or connected app you don't recognize.
5
Screenshot before you clean up
Insurers and law enforcement will ask for evidence. Capture it now — cleanup destroys it.
6
Report it
File at ic3.gov (FBI IC3) and notify your cyber insurer. Many policies require notice within a short window, and a late notice can reduce or void a claim.
What to say when the bank picks up
“My name is at ____________. I need the wire fraud desk. We have a confirmed business email compromise. A wire sent on for went to an account we now believe is fraudulent. I am requesting a wire recall and a hold on any further outbound transfers on our accounts until I call back and confirm. Please give me a case or reference number before we hang up.”
Screenshot / save this evidence
This alert page and the alert's exported JSON
The forwarding/inbox rules screen before you delete anything
The sign-in/audit log entry for the suspicious login
The invoice or payment-change email, with full headers
Wire confirmation, amount, and the receiving account details
InboxGuards is an automated alarm on your provider's audit logs. It is not a staffed SOC, not legal, banking or insurance advice, and it cannot recall a payment on your behalf. Timelines and recall outcomes are determined by your bank. Reported IP locations are estimates. Use this sheet as a starting checklist alongside your own advisors.
Critical — act on this now
CRIT
Email monitor created — a copy of dan@acmesupply.com's mail is now sent to an outside account
1. In the Google admin console, open Reporting > Email Log Search / Email monitors.
2. Delete the monitor you did not create.
3. Reset the admin account's password and sign out all sessions.
4. Review admin audit logs for other changes by this account.
InboxGuards · wire hold sheet
First 90 minutes
Printed Sep 5, 2026 · 11:47 AM · your organization · keep this with the person who approves payments
The alert that triggered this
[CRIT] Email monitor created — a copy of dan@acmesupply.com's mail is now sent to an outside account
detected: 2026-09-05 11:13 (11:13 UTC)
account: admin@acmesupply.com
source ip: 45.155.205.99
alert id: demo-8
Fill this in before you need it
Bank wire/fraud desk: Account manager: IT / MSP contact: Cyber insurer claims line: Policy number: Who can approve a hold:
Do these in order
1
Call the bank — by phone, not email
Ask for the wire/fraud desk and use the words "business email compromise" and "recall request". Every minute matters: recalls succeed far more often inside the first few hours. Do not send this request by email — the mailbox may still be read by the attacker.
2
Freeze any pending or scheduled payments
Pause outbound wires, ACH batches and scheduled vendor payments until the mailbox is confirmed clean. Verify new or changed bank details only by calling a number you already had on file — never a number from the email thread.
3
Lock the account
Reset the password, revoke all active sessions and refresh tokens, then require MFA. A password reset alone leaves the attacker signed in.
4
Delete the attacker's plumbing
Remove forwarding rules, inbox rules that move mail to hidden folders, added recovery emails/phones, delegated mailbox access, and any app password or connected app you don't recognize.
5
Screenshot before you clean up
Insurers and law enforcement will ask for evidence. Capture it now — cleanup destroys it.
6
Report it
File at ic3.gov (FBI IC3) and notify your cyber insurer. Many policies require notice within a short window, and a late notice can reduce or void a claim.
What to say when the bank picks up
“My name is at ____________. I need the wire fraud desk. We have a confirmed business email compromise. A wire sent on for went to an account we now believe is fraudulent. I am requesting a wire recall and a hold on any further outbound transfers on our accounts until I call back and confirm. Please give me a case or reference number before we hang up.”
Screenshot / save this evidence
This alert page and the alert's exported JSON
The forwarding/inbox rules screen before you delete anything
The sign-in/audit log entry for the suspicious login
The invoice or payment-change email, with full headers
Wire confirmation, amount, and the receiving account details
InboxGuards is an automated alarm on your provider's audit logs. It is not a staffed SOC, not legal, banking or insurance advice, and it cannot recall a payment on your behalf. Timelines and recall outcomes are determined by your bank. Reported IP locations are estimates. Use this sheet as a starting checklist alongside your own advisors.
HIGH
127 emails permanently deleted by accounting@acmesupply.com in one hour — possible evidence destruction
Sep 5, 2026 · 9:47 AMaccounting@acmesupply.com
Show more
1. Check the mailbox's Recoverable Items (Purges) folder before the deleted mail ages out.
2. Reset this user's password and sign out all sessions.
3. Review the mailbox for new inbox rules or forwarding.
InboxGuards · wire hold sheet
First 90 minutes
Printed Sep 5, 2026 · 11:47 AM · your organization · keep this with the person who approves payments
The alert that triggered this
[HIGH] 127 emails permanently deleted by accounting@acmesupply.com in one hour — possible evidence destruction
detected: 2026-09-05 09:47 (09:47 UTC)
account: accounting@acmesupply.com
alert id: demo-9
Fill this in before you need it
Bank wire/fraud desk: Account manager: IT / MSP contact: Cyber insurer claims line: Policy number: Who can approve a hold:
Do these in order
1
Call the bank — by phone, not email
Ask for the wire/fraud desk and use the words "business email compromise" and "recall request". Every minute matters: recalls succeed far more often inside the first few hours. Do not send this request by email — the mailbox may still be read by the attacker.
2
Freeze any pending or scheduled payments
Pause outbound wires, ACH batches and scheduled vendor payments until the mailbox is confirmed clean. Verify new or changed bank details only by calling a number you already had on file — never a number from the email thread.
3
Lock the account
Reset the password, revoke all active sessions and refresh tokens, then require MFA. A password reset alone leaves the attacker signed in.
4
Delete the attacker's plumbing
Remove forwarding rules, inbox rules that move mail to hidden folders, added recovery emails/phones, delegated mailbox access, and any app password or connected app you don't recognize.
5
Screenshot before you clean up
Insurers and law enforcement will ask for evidence. Capture it now — cleanup destroys it.
6
Report it
File at ic3.gov (FBI IC3) and notify your cyber insurer. Many policies require notice within a short window, and a late notice can reduce or void a claim.
What to say when the bank picks up
“My name is at ____________. I need the wire fraud desk. We have a confirmed business email compromise. A wire sent on for went to an account we now believe is fraudulent. I am requesting a wire recall and a hold on any further outbound transfers on our accounts until I call back and confirm. Please give me a case or reference number before we hang up.”
Screenshot / save this evidence
This alert page and the alert's exported JSON
The forwarding/inbox rules screen before you delete anything
The sign-in/audit log entry for the suspicious login
The invoice or payment-change email, with full headers
Wire confirmation, amount, and the receiving account details
InboxGuards is an automated alarm on your provider's audit logs. It is not a staffed SOC, not legal, banking or insurance advice, and it cannot recall a payment on your behalf. Timelines and recall outcomes are determined by your bank. Reported IP locations are estimates. Use this sheet as a starting checklist alongside your own advisors.
Critical — act on this now
CRIT
Impossible travel: mike@acmesupply.com signed in from Omaha, NE and Lagos, Nigeria 42 minutes apart
1. Treat the credentials as stolen — reset Mike's password immediately.
2. Sign the account out of all sessions.
3. Confirm MFA is enabled.
4. Check the mailbox for new rules or forwarding.
InboxGuards · wire hold sheet
First 90 minutes
Printed Sep 5, 2026 · 11:47 AM · your organization · keep this with the person who approves payments
The alert that triggered this
[CRIT] Impossible travel: mike@acmesupply.com signed in from Omaha, NE and Lagos, Nigeria 42 minutes apart
detected: 2026-09-05 10:56 (10:56 UTC)
account: mike@acmesupply.com
source ip: 102.89.34.10
alert id: demo-6
Fill this in before you need it
Bank wire/fraud desk: Account manager: IT / MSP contact: Cyber insurer claims line: Policy number: Who can approve a hold:
Do these in order
1
Call the bank — by phone, not email
Ask for the wire/fraud desk and use the words "business email compromise" and "recall request". Every minute matters: recalls succeed far more often inside the first few hours. Do not send this request by email — the mailbox may still be read by the attacker.
2
Freeze any pending or scheduled payments
Pause outbound wires, ACH batches and scheduled vendor payments until the mailbox is confirmed clean. Verify new or changed bank details only by calling a number you already had on file — never a number from the email thread.
3
Lock the account
Reset the password, revoke all active sessions and refresh tokens, then require MFA. A password reset alone leaves the attacker signed in.
4
Delete the attacker's plumbing
Remove forwarding rules, inbox rules that move mail to hidden folders, added recovery emails/phones, delegated mailbox access, and any app password or connected app you don't recognize.
5
Screenshot before you clean up
Insurers and law enforcement will ask for evidence. Capture it now — cleanup destroys it.
6
Report it
File at ic3.gov (FBI IC3) and notify your cyber insurer. Many policies require notice within a short window, and a late notice can reduce or void a claim.
What to say when the bank picks up
“My name is at ____________. I need the wire fraud desk. We have a confirmed business email compromise. A wire sent on for went to an account we now believe is fraudulent. I am requesting a wire recall and a hold on any further outbound transfers on our accounts until I call back and confirm. Please give me a case or reference number before we hang up.”
Screenshot / save this evidence
This alert page and the alert's exported JSON
The forwarding/inbox rules screen before you delete anything
The sign-in/audit log entry for the suspicious login
The invoice or payment-change email, with full headers
Wire confirmation, amount, and the receiving account details
InboxGuards is an automated alarm on your provider's audit logs. It is not a staffed SOC, not legal, banking or insurance advice, and it cannot recall a payment on your behalf. Timelines and recall outcomes are determined by your bank. Reported IP locations are estimates. Use this sheet as a starting checklist alongside your own advisors.
HIGH
Dormant account woke up: oldintern@acmesupply.com signed in after 94 days of inactivity
1. Confirm with the account owner that this sign-in was them.
2. If the account should no longer be in use, disable it.
3. Otherwise reset the password and sign out all sessions.
InboxGuards · wire hold sheet
First 90 minutes
Printed Sep 5, 2026 · 11:47 AM · your organization · keep this with the person who approves payments
The alert that triggered this
[HIGH] Dormant account woke up: oldintern@acmesupply.com signed in after 94 days of inactivity
detected: 2026-09-05 05:47 (05:47 UTC)
account: oldintern@acmesupply.com
source ip: 185.220.101.45
alert id: demo-7
Fill this in before you need it
Bank wire/fraud desk: Account manager: IT / MSP contact: Cyber insurer claims line: Policy number: Who can approve a hold:
Do these in order
1
Call the bank — by phone, not email
Ask for the wire/fraud desk and use the words "business email compromise" and "recall request". Every minute matters: recalls succeed far more often inside the first few hours. Do not send this request by email — the mailbox may still be read by the attacker.
2
Freeze any pending or scheduled payments
Pause outbound wires, ACH batches and scheduled vendor payments until the mailbox is confirmed clean. Verify new or changed bank details only by calling a number you already had on file — never a number from the email thread.
3
Lock the account
Reset the password, revoke all active sessions and refresh tokens, then require MFA. A password reset alone leaves the attacker signed in.
4
Delete the attacker's plumbing
Remove forwarding rules, inbox rules that move mail to hidden folders, added recovery emails/phones, delegated mailbox access, and any app password or connected app you don't recognize.
5
Screenshot before you clean up
Insurers and law enforcement will ask for evidence. Capture it now — cleanup destroys it.
6
Report it
File at ic3.gov (FBI IC3) and notify your cyber insurer. Many policies require notice within a short window, and a late notice can reduce or void a claim.
What to say when the bank picks up
“My name is at ____________. I need the wire fraud desk. We have a confirmed business email compromise. A wire sent on for went to an account we now believe is fraudulent. I am requesting a wire recall and a hold on any further outbound transfers on our accounts until I call back and confirm. Please give me a case or reference number before we hang up.”
Screenshot / save this evidence
This alert page and the alert's exported JSON
The forwarding/inbox rules screen before you delete anything
The sign-in/audit log entry for the suspicious login
The invoice or payment-change email, with full headers
Wire confirmation, amount, and the receiving account details
InboxGuards is an automated alarm on your provider's audit logs. It is not a staffed SOC, not legal, banking or insurance advice, and it cannot recall a payment on your behalf. Timelines and recall outcomes are determined by your bank. Reported IP locations are estimates. Use this sheet as a starting checklist alongside your own advisors.
HIGH
Sign-in from unusual location (7,400 miles from office)
1. Confirm with Mike whether he is traveling.
2. If not, reset his password immediately and revoke all sessions.
3. Review his sent items and inbox rules for tampering.
InboxGuards · wire hold sheet
First 90 minutes
Printed Sep 5, 2026 · 11:47 AM · your organization · keep this with the person who approves payments
The alert that triggered this
[HIGH] Sign-in from unusual location (7,400 miles from office)
detected: 2026-09-05 08:47 (08:47 UTC)
account: mike@acmesupply.com
source ip: 185.220.101.45
alert id: demo-2
Fill this in before you need it
Bank wire/fraud desk: Account manager: IT / MSP contact: Cyber insurer claims line: Policy number: Who can approve a hold:
Do these in order
1
Call the bank — by phone, not email
Ask for the wire/fraud desk and use the words "business email compromise" and "recall request". Every minute matters: recalls succeed far more often inside the first few hours. Do not send this request by email — the mailbox may still be read by the attacker.
2
Freeze any pending or scheduled payments
Pause outbound wires, ACH batches and scheduled vendor payments until the mailbox is confirmed clean. Verify new or changed bank details only by calling a number you already had on file — never a number from the email thread.
3
Lock the account
Reset the password, revoke all active sessions and refresh tokens, then require MFA. A password reset alone leaves the attacker signed in.
4
Delete the attacker's plumbing
Remove forwarding rules, inbox rules that move mail to hidden folders, added recovery emails/phones, delegated mailbox access, and any app password or connected app you don't recognize.
5
Screenshot before you clean up
Insurers and law enforcement will ask for evidence. Capture it now — cleanup destroys it.
6
Report it
File at ic3.gov (FBI IC3) and notify your cyber insurer. Many policies require notice within a short window, and a late notice can reduce or void a claim.
What to say when the bank picks up
“My name is at ____________. I need the wire fraud desk. We have a confirmed business email compromise. A wire sent on for went to an account we now believe is fraudulent. I am requesting a wire recall and a hold on any further outbound transfers on our accounts until I call back and confirm. Please give me a case or reference number before we hang up.”
Screenshot / save this evidence
This alert page and the alert's exported JSON
The forwarding/inbox rules screen before you delete anything
The sign-in/audit log entry for the suspicious login
The invoice or payment-change email, with full headers
Wire confirmation, amount, and the receiving account details
InboxGuards is an automated alarm on your provider's audit logs. It is not a staffed SOC, not legal, banking or insurance advice, and it cannot recall a payment on your behalf. Timelines and recall outcomes are determined by your bank. Reported IP locations are estimates. Use this sheet as a starting checklist alongside your own advisors.
1. Check whether forwarding to gmail address was set up intentionally.
2. If not, disable forwarding in Exchange settings.
3. Audit recent messages that were forwarded.
✓ Acknowledged
LOW
Multiple failed sign-in attempts (12 in 5 minutes)