Business email compromise — investigation and remediation
Identified and documented a coordinated BEC attempt targeting a planned vendor payment. Traced the compromise to a third-party consultant's breached credentials. Performed domain forensics on lookalike domains, analyzed SPF, DKIM, and DMARC gaps, and completed a Google Workspace security audit. Delivered abuse reports to the registrar and to Google and hardened org-wide email controls.
No funds were lost in that transaction.