Business Email Compromise: What the Digital Evidence in a BEC Scam Can Actually Prove

A supplier emails new bank account details for a large invoice. The accounts team replies inside the existing thread, receives a polished confirmation, and pays. The real supplier later says the account was never changed. That is a Business Email Compromise scam, known almost universally as BEC, and at that point the question is not simply whether a suspicious email exists. The question is what the digital material can establish about authorship, access, timing, authority and loss, and on which side of the compromise the liability sits.

BEC is the payment redirection dispute that Australian solicitors and businesses most often need examined. Australian Government cyber guidance treats business email compromise as a serious fraud risk, while a recent Victoria Police fraud investigation supported by the Cybercrime Squad is a timely reminder that modern financial investigations commonly involve phones, computers and online records. Those records can be powerful, but only when the reasoning from record to conclusion is made explicit.

Start with the proposition that must be proved

In a BEC matter, a party may need to prove that an account was compromised, that a particular message originated from or passed through that account, that the payment instruction differed from an authorised instruction, and that the change caused the payment to go elsewhere. Each proposition needs different records.

A mailbox copy of the email may show visible sender, recipient, subject and body. It does not, by itself, prove who operated the account. Message headers may add routing and authentication results. Provider audit records may show sign-ins, mailbox rules, forwarding, consent grants or administrative changes. Accounting records may establish when the supplier details changed. Bank records may establish where the money went. A device examination may show saved credentials, browser sessions, malicious software, downloaded attachments or communications outside the business mailbox.

The case works because those records are compared. It fails when one record is asked to prove more than it can.

Which side of the compromise the liability sits on

A BEC scam has 2 businesses in it and only 1 of them was usually compromised. That is the commercial question underneath the forensic one, because the party whose systems let the offender in is the party facing the loss. It is answered from records, not from who feels wronged.

The starting point is the mail authentication posture of each domain. A domain publishing a strict sender policy but no message signing and no reporting and enforcement policy is a domain whose name can be presented convincingly by somebody else in a display name or a lookalike address. Where 1 side has that gap and the other does not, the gap is the argument, and it is available before anybody has been given access to a mailbox.

The next step is the direction of travel. Did the altered instruction come from inside the supplier's own mailbox, which points to a compromise on the supplier side, or from a lookalike domain registered to imitate it, which points to a failure of verification on the paying side, or from inside the paying business, which points somewhere else again. Sign-in records, mailbox rule history, message headers and domain registration dates each answer a different part of that, and the answer decides who bears the loss far more often than any question about whether the email looked convincing.

An email thread is content, not necessarily authorship

A familiar display name and a reply inside an existing conversation can make a message persuasive to a recipient. Neither proves that the supplier wrote it. A compromised mailbox can allow an offender to read prior correspondence, learn the language of the parties, wait for a genuine invoice, and reply at the moment a payment is expected.

The examination should therefore separate 3 questions. Did the message exist in the relevant mailbox? How did it travel? Who had the opportunity to send it? The first may be answered by preserved mailbox content. The second may depend on complete headers and provider records. The third may require sign-in logs, device evidence, mailbox rule history and evidence about shared access.

Early reporting matters, but so does preserving the material before normal retention, synchronisation or account remediation changes it.

Absence in a log is not automatically absence of an event

One of the most common reasoning errors is to treat a missing event as proof that nothing occurred. Cloud services do not expose the same audit detail on every licensing tier. Retention periods differ. A setting may not have been enabled when the event occurred. An export may cover only a selected date range, user, event type or workload. A portal may show a filtered view rather than the underlying record set.

A defensible conclusion states what was searched, the time zone, the date range, the account identifiers, the event categories, the licensing and retention conditions, and any export filters. If no suspicious sign-in appears, the conclusion is that none appeared in the examined records under those conditions. It is not that no suspicious sign-in occurred.

This distinction can decide a BEC liability question. If a party alleges that a mailbox was accessed 3 months earlier but the available audit tier retained only 30 days, the empty result does not rebut the allegation. It identifies a limitation in the surviving evidence.

A filtered view proves what it was asked to show

Filters are useful and dangerous. A search for messages sent to 1 supplier may quickly isolate the altered invoice thread. It says nothing about messages to an intermediary, deleted drafts, forwarding rules, other aliases or communications through a personal account. A date filter may exclude the reconnaissance that made the later fraud possible.

The examiner should preserve the source, record the filter, export the result, and retain enough unfiltered context to test whether the filter itself shaped the conclusion. Screenshots can document what was visible, but they should not replace the underlying export where that export is available.

Document extraction can silently change meaning

BEC disputes often involve PDF files, Word documents and scanned approvals. The method used to read them matters.

Plain text extraction from a marked-up document can silently retain words that are visibly struck out. A review based only on extracted text may therefore attribute wording to the final document that a reader of the rendered page would understand had been deleted. The correct comparison examines both the visible rendering and the document structure.

Optical character recognition has a different limitation. In a comparison of printed material against certified text, OCR can make a true match fail, but it cannot make non-matching printed text pass falsely. The comparison is therefore safe in 1 direction only. A confirmed match can support consistency with the certified text, while a mismatch must be checked against the image before it is treated as a substantive difference. Fonts, scanning quality, skew and compression can all affect recognition.

These are not technical footnotes. If the disputed bank account appears in a scanned approval, a single mistaken character may decide whether the document matches the authorised instruction.

Acquisition tools do not define the evidence

The Australian Federal Police describes digital forensics as part of a wider forensic science capability. That is the right frame. A tool can acquire or parse material, but it does not decide what happened.

Mobile forensic tooling, including products such as Cellebrite, may obtain different results depending on the device model, operating system version, lock state, encryption, application version, acquisition method and lawful access available. A logical extraction may provide active application data while omitting deleted, encrypted, unsupported or cloud only material. A file system extraction may expose more structure, but a parsed report still reflects what the parser recognised. An unsupported field is not necessarily absent from the source.

For a BEC matter, the useful question is not whether a named tool was used. It is whether the acquisition captured the relevant mail, browser, messaging and authentication artefacts, whether originals were preserved, whether timestamps were normalised correctly, and whether important exclusions were documented.

Build the opinion from converging records

A strong examination might show that the genuine supplier email arrived at 9:12 am, an unfamiliar sign-in preceded a new forwarding rule, the altered instruction was sent at 9:26 am, the accounts system changed the bank details at 9:41 am, and the payment followed that afternoon. Device or provider records might connect some of those events. Bank material might establish the destination.

Even then, the opinion should distinguish between what is directly recorded and what is inferred. Records may establish that an account performed an action. They may not identify the human at the keyboard. A shared mailbox, delegated access, remote session or stolen token can complicate attribution. The gap should be stated, not filled with confidence.

What businesses and solicitors should preserve first

Preserve the original messages with full headers, not only screenshots or forwarded copies. Record the affected accounts, aliases, shared mailbox access and relevant administrators. Export available audit logs before retention advances. Preserve the invoice versions, approval records, accounting changes and bank communications. Record the mail authentication records published by both domains, because they change. Record the time zone used by each system. Keep originals read only and work from verified copies.

If personal information may have been exposed, the Office of the Australian Information Commissioner's Notifiable Data Breaches guidance may also be relevant. Legal, regulatory and recovery steps can proceed in parallel with evidence preservation, but remediation should be recorded because password resets, rule deletion and device rebuilding can change the evidence.

The value of digital forensic work in a BEC scam is not a larger collection of screenshots. It is a tested account of what each record can show, what it cannot show, and how the records fit together. That is what allows a solicitor, business or court to separate a persuasive story from a proposition the evidence can actually support.

About the author

Simon Smith is a digital forensic IT expert witness, the principal of Official Intelligence Pty Ltd in Melbourne, and a prominent Business Email Compromise investigator. He gives expert evidence on header analysis, SPF, DKIM and DMARC authentication, mailbox audit logs, session token replay and forwarding rule abuse in invoice redirection and payment fraud matters, and has resolved many BEC scams by identifying which side of the compromise the liability sits on. He gives evidence as an independent expert and accepts instructions from solicitors and from businesses directly. Official Intelligence is at www.ofi.com.au and the expert witness practice at www.expertwitness.com.au.