forumNew topic

Our email was hacked and they told us an incident investigation is a must: Who does this and what gets logged?

HHavva O***Expert
Job title
Marketing manager
Sector
Construction
Organization type
sole proprietorship
Joined
Nov 2023
Message
230
#1

We are an industrial construction chemicals distributor with 35 employees based in Saint Petersburg. Last Tuesday, our accounting manager's corporate email account was accessed without authorization. The attackers intercepted an existing thread with a supplier, sent a fake revised invoice claiming our bank details had changed, and tried to divert a payment of 3,800,000 RUB to another account. Luckily, the supplier's finance person verified it over the phone, and the fraud was caught just in time.

In our initial shock, we immediately changed all company email passwords and rebooted the on-prem mail server. An external cybersecurity consultant we spoke to told us, "Just changing passwords isn't enough, you need to run a full IS incident investigation; the attacker might have left a backdoor and you might have wiped the evidence."

How exactly is this incident investigation carried out? Can our in-house sysadmin handle it, or do we need to hire a digital forensics specialist? What do we need to preserve and what should we avoid doing until an inspection takes place?

KKemal G***Member
Job title
Store associate
Sector
IT services
Organization type
medium-sized business
Joined
Apr 2023
Message
7

Doki · Incident response support · 2024

Most Helpful#2

Short answer: A cybersecurity incident investigation is a methodical digital forensics process that pinpoints the attacker's initial entry point, how long they lingered inside, what data they accessed, and whether they established persistence. Even if changing the password cuts off immediate access, it doesn't clean up forwarding rules or authorized external sessions created by the attacker.

Preserving digital footprints is the top priority during an investigation. The single biggest mistake is rebooting the server, because that wipes volatile connection data held in temporary memory (RAM). Here's what you need to do right away: 1) Check and export all inbound and outbound forwarding rules on the affected mailbox; attackers often set up stealth deletion rules to suppress warning notifications. 2) Immediately download access logs, login IP addresses, and failed attempts from the last 90 days, then back them up to a secure, read-only location. 3) Revoke third-party authorizations and app passwords linked to the account, and force-kill all active sessions from the admin console.

An internal sysadmin can only handle this investigation at a baseline level. If critical trade secrets were exchanged over corporate email or if you're taking legal action that requires official evidence, you must work with an independent digital forensics or incident response firm. A professional team will maintain chain-of-custody integrity, from gateway logs to server memory dumps and produce an official technical report.

İİlker T***Member
Job title
Co-founder
Sector
Security services
Organization type
20-person company
Joined
Apr 2022
Message
73
#3

By restarting the server, you probably already wiped the live network sockets and volatile attacker sessions from RAM. Panic moves like this from sysadmins usually destroy the exact evidence forensic analysts need most. Don't install or delete anything else on the system from here on out; just take a direct disk image right away.

OOkan F***Expert
Job title
Fintech product manager
Organization type
chain store
Joined
Aug 2023
Message
146
#4

Definitely check the mailbox forwarding rules. Attackers usually create stealth rules that forward any emails containing words like invoice, payment, receipt to an external address, or move incoming replies straight into the deleted items folder. Also archive the admin audit logs from your mail management console immediately.

MMert Y***Member
Job title
Purchasing manager
Sector
Accounting & advisory
Organization type
two-branch business
Joined
Mar 2023
Message
3

Doki · Log management setup · 2024

#5

What you need to do right now: run a sign-out of all sessions from the email admin console and enforce two-factor authentication for every single employee without exception. Even if the password was changed, unexpired session tokens can keep the attacker logged in.

ZZafer A***MemberCommunity member
Joined
Nov 2025
Message
152
#6

We went through this exact same invoice-swapping scheme last year at our logistics office in Moscow. We paid a local cybersecurity firm 450,000 RUB for the incident investigation. The analysis revealed that the attacker had gotten in through a phishing email on the accountant's machine and was silently monitoring our threads for 43 days.

VVildan V***VeteranCommunity member
Joined
Jun 2025
Message
329
#7

seriously incredible luck that the bank caught it at the last second, 3.8 million rubles is no small change. but the consultant is right they couldve easily breached another machine on the network besides that mailbox. honestly dont sleep on the investigation imo.

EElaMember
Job title
Psychologist
Joined
Aug 2024
Message
74
#8

Under Russian Federation legislation, you have statutory obligations regarding the protection of personal data and trade secrets. If the fallout extends beyond company walls and you plan to file a criminal complaint with law enforcement, a licensed expert report proving the chain of custody remained intact will be your only valid standing in court.

İİlker C***Member
Job title
Software developer
Sector
Machinery manufacturing
Organization type
sole proprietorship
Joined
Dec 2023
Message
52
#9

Invoice fraud like this isn't carried out randomly. The attacker had already mapped out your accounting workflow, your tone with the supplier, and your billing schedules. That means they've been lurking and observing for days or even weeks. Your internal team can only put out the visible fire; you definitely need an experienced external pair of eyes for root cause analysis.

HHavva S***Expert
Job title
Clinic manager
Sector
Real estate
Organization type
two-branch business
Joined
Jun 2023
Message
176
#10

Im a small business, let me explain from my side... tbh if permission and scope arent in writing dont start that test.

Good luck with that.

SSultan B***Member
Job title
Front office accounting
Sector
Security services
Organization type
8-person team
Joined
Feb 2025
Message
23
#11

Noted, thanks.

FFatma T***Member
Job title
Store associate
Sector
Energy
Organization type
8-person team
Joined
Jul 2024
Message
190
#12

Let me share what happened to me; it might be useful. When you try to change everything at once, nothing settles.

This is my opinion, I'm not claiming it's absolute truth.

RRabia B***ExpertCommunity member
Joined
Mar 2025
Message
232
#13

There's one point I'm curious about. Hasty decisions become decisions you have to fix six months later.

If I were you, I'd go this route.

RRecep B***ExpertCommunity member
Joined
Jun 2024
Message
111
#14

We need to make a distinction here. Taking measures without an inventory leaves doors you haven't seen open.

Taking measures without an inventory leaves doors you haven't seen open.

PPınar B***Member
Job title
Technical service technician
Sector
Packaging
Organization type
a company within a holding
Joined
Jul 2025
Message
263
#15

I think it's hard to be that definitive about incident investigation. Taking measures without an inventory leaves doors you haven't seen open.

Just leaving this note, it might be useful.

FFurkan K***New member
Job title
QA Tester
Sector
Catering
Organization type
120-person company
Joined
Sep 2026
Message
258
#16

Thanks, that was the answer I was looking for. Mistakes made on the incident investigation side are usually reversible but expensive.

If I were you, I'd go this route.

BBarış S***MemberCommunity member
Joined
Mar 2023
Message
79
#17

Quick summary for newcomers: Your time to detect an issue directly determines its cost.

Correct me if I'm wrong.

AAycan B***Member
Job title
Quality Assurance Manager
Sector
Automotive aftermarket
Organization type
40-person manufacturing company
Joined
Mar 2024
Message
6
#18

Could you elaborate on that? If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Most time waste accumulates in tasks waiting for approval. Correct me if I'm wrong.

ÖÖzgür K***MemberCommunity member
Joined
Nov 2023
Message
4
#19

Let me share what happened to me; it might be useful. Having backups accessible on the same network and with the same identity makes them part of the target.

Proven by experience.

VVeli Y***Member
Job title
Data Analyst
Sector
E-commerce
Organization type
40-person manufacturing company
Joined
Nov 2023
Message
91

Doki · Server maintenance contract · 2024

#20

Generally correct, but one part is missing. anyway everyone rushing into incident investigation gets stuck at the same point.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic