- Job title
- Marketing manager
- Sector
- Construction
- Organization type
- sole proprietorship
- Joined
- Nov 2023
- Message
- 230
We are an industrial construction chemicals distributor with 35 employees based in Saint Petersburg. Last Tuesday, our accounting manager's corporate email account was accessed without authorization. The attackers intercepted an existing thread with a supplier, sent a fake revised invoice claiming our bank details had changed, and tried to divert a payment of 3,800,000 RUB to another account. Luckily, the supplier's finance person verified it over the phone, and the fraud was caught just in time.
In our initial shock, we immediately changed all company email passwords and rebooted the on-prem mail server. An external cybersecurity consultant we spoke to told us, "Just changing passwords isn't enough, you need to run a full IS incident investigation; the attacker might have left a backdoor and you might have wiped the evidence."
How exactly is this incident investigation carried out? Can our in-house sysadmin handle it, or do we need to hire a digital forensics specialist? What do we need to preserve and what should we avoid doing until an inspection takes place?