VETERAN-OWNED · NEBRASKA-BASEDIncident now (531) 625-2113

Insights · 2026-10-04

Business email compromise: what the mailbox actually does

SAINT Cybersecurity · Specialist note · Not a Lincoln or Omaha location page

Business email compromise is a decision someone was persuaded to make. The message asks accounts payable, payroll, or an owner to change where money goes. Sometimes the From line is a look-alike. Sometimes it is a real mailbox that already forwards mail the sender never wrote.

This is the specialist note. It is not a Lincoln or Omaha service page. A Lincoln business that wants the local commercial team starts at cybersecurity services in Lincoln. The first-hour checklist, if money may already be moving, stays on the technology site: what to do when you suspect business email compromise.

What monitoring can see

A managed detection practice watches for the residue of a mailbox that is no longer only the employee’s:

Those are signals a person can investigate. They are not a promise that every fraudulent wire will be stopped, and they are not a statistic about how often Nebraska businesses are targeted. SAINT does not publish a detection rate on this page.

Huntress or Guardz — one design on an engagement, not both stacked for show — is the monitoring layer when that is what was scoped. SAINT coordinates the client conversation. This page does not claim SAINT staffs a private global SOC.

What no sensor sees

The expensive version of this attack often never needs malware. Someone calls the number printed in the email, hears a confident voice, and releases the payment. Mailbox telemetry cannot hear that call.

The control is dull on purpose. Payment changes get confirmed on a number that was already on file — the vendor master, the last invoice you trusted, the owner’s known mobile — not on a number that arrived in the same thread. A display name is not a From address. Urgency is not authorization.

After the payment question

If the mailbox might be involved, the work is identity first: sessions, the password, MFA methods the user did not enroll, and the rules that would keep the attacker in after the password changes. Wiping a laptop before anyone has looked at those rules throws away the only clues you had.

Cyber insurance questionnaires later ask whether MFA was on, whether forwarding was reviewed, and whether someone could show the trail. That is an evidence problem. It is not a certification, and this article is not a claim that a control set guarantees a claim will be paid.

Where to go next

Active suspicion belongs on the incident page, then the desk line (531) 625-2111. Do not put a new payment through while you are still reading.

Related specialist notes: ransomware for a Nebraska business and what a free security assessment actually covers. The free assessment is a gap list. It is not a promise that BEC becomes impossible.

All insightsCybersecurity services in LincolnFree assessment