What the investigation file needs to establish
A business email compromise investigation file brings together the customer's report, payment records, beneficiary details, communications, and available account activity. Its purpose is to show investigators what happened, which sources support the chronology, and which contradictions or missing facts still need review.
For fraud operations teams, the repeatable work is gathering records across systems, comparing the original and changed instructions, and preparing a source-linked handoff. Keep reported facts, verified events, and unresolved questions distinct. The investigator and the bank's designated teams retain decisions about the case, customer response, reporting, and payment actions.
Urgent payment concerns. Evidence preparation must run alongside the bank's response process. Do not make a complete case narrative a prerequisite for escalating a payment concern to the authorized team.
The FBI's Internet Crime Complaint Center advises contacting the originating financial institution as soon as fraud is recognized to request a recall or reversal and relevant indemnification documentation, and filing a detailed IC3 complaint. Its September 2024 advisory stresses prompt contact while noting that financial institutions have different policies. A request is not a promise that funds can be stopped, frozen, or recovered. IC3 incident steps and 2024 advisory
Scope. This guide proposes a case-preparation method for U.S. bank fraud operations teams investigating a business customer's report of an email-related payment scam. It does not provide a payment-recovery service or a cybersecurity incident-response procedure. It is not a legal determination of authorization, liability, reimbursement, or reporting obligations. Account type, payment method, transaction facts, applicable law, network rules, agreements, and bank procedures matter. Route consumer-payment concerns through the bank's applicable procedures rather than treating this guide as a substitute.
Separate the scam description from the legal conclusion
A fraudulent email can impersonate a vendor, executive, or other trusted party. The compromise may involve a taken-over mailbox, a spoofed address, or a lookalike account. FinCEN's 2019 advisory explains that these schemes can affect payment methods beyond wires and can also target sensitive data. Its definition is broader than a single "hacked business email" pattern. FinCEN advisory, pp. 2–3 and 7
Record what the customer says without treating the initial label as a settled fact. "The customer entered the payment" and "the payment instructions were legitimate" are different statements. Likewise, a successful login does not resolve whether an instruction was fraudulent. Keep the evidence about who initiated, instructed, authenticated, and approved the payment separate from the legal assessment.
Use neutral case language until the relevant facts are established. For example, "customer reports that replacement beneficiary details arrived by email" is more precise than declaring the recipient a criminal or the transaction reimbursable. These wording choices are recommended investigation practice, not new legal standards.
Assemble the investigation evidence in five steps
1. Capture the minimum actionable report
Confirm the caller or reporting party through the bank's established verification procedures. Record when the bank received notice, the customer's contact details through a trusted channel, the reported payment date and amount, currency, beneficiary information, and available payment reference. Identify additional payments the customer believes may be affected.
Clearly label customer-reported information and bank-confirmed information. Note missing details, but send the information already available to the authorized payment-response team if it is sufficient for that team's process. Do not wait for original emails or a polished chronology before escalating an urgent concern.
2. Reconcile payment and beneficiary records
Trace the reported amount, currency, date, payment reference, and beneficiary details to the records available in the bank's approved systems. Compare original and replacement instructions. Record differences in beneficiary name, account details, destination, or verification history as evidence for investigation; a difference alone does not establish criminal intent.
Ask payment operations to confirm the payment's processing status and any action already taken. Add the source, timestamp, owner, and unresolved follow-up to the case file. Record a recall request separately from a confirmed return of funds. The authorized team determines available actions under the bank's procedures; the preparer's role is to preserve an accurate record of them. IC3 incident guidance
3. Preserve the communications and access evidence
Ask for the relevant original messages and attachments through an approved secure channel. Where available, preserve message headers, the original and changed payment instructions, invoices, relevant account activity, and the customer's account of the sequence. Do not rely solely on a screenshot if the original record can be preserved. Keep sensitive material in the bank's approved case system, not in this guide or an external writing tool.
Treat all disputed contact details as unverified. Confirm a vendor or customer using a previously established or independently verified channel, not the phone number inserted into the suspicious message. IC3 recommends secondary channels to verify changes in account information, while FinCEN describes verification through multiple means of communication. IC3 prevention guidance and FinCEN, p. 8
Where the facts suggest compromised accounts or systems, involve the appropriate security team under the incident-response process. Coordinate containment and evidence preservation rather than having the fraud analyst independently change systems or delete suspect messages. The preservation steps here are editorial recommendations; retention and security requirements come from the bank's applicable rules and procedures.
4. Reconstruct the chronology and resolve contradictions
Build a timeline that distinguishes when an event occurred from when someone reported it. Include the original invoice or instruction, the purported change, any verification attempt, payment initiation and release, discovery, bank notice, and response actions. Record the time zone when it matters to the sequence.
Connect each material event to a source and indicate whether it is confirmed, reported, inferred, or unresolved. Compare the customer's narrative with payment and access records. If sources conflict, preserve the conflict and identify the evidence needed to resolve it. Do not choose the most convenient version merely to complete the case summary.
5. Prepare questions and assign decision owners
Give the investigator a concise account of the suspected instruction change, the supporting payment and beneficiary records, the source-linked chronology, and the unresolved contradictions. For each open question, state the evidence needed, its owner, and the next review step. Keep downstream decisions visibly assigned.
IC3 advises filing a detailed complaint with relevant banking information. FinCEN's advisory also emphasizes collaboration among fraud, AML, compliance, legal, business, and cybersecurity functions. Use the bank's procedures to assign the complaint, law-enforcement contact, financial-crime review, and customer communications rather than leaving them implicit. IC3 and FinCEN, p. 2
Treat recovery actions, a crime complaint, and the bank's reporting analysis as separate tasks. Do not assume one completes the others. This guide does not decide whether a SAR is required or specify filing thresholds, deadlines, or current form instructions. Route those decisions to the bank's designated BSA/AML function using current requirements.
Give the customer a factual update about actions actually taken, outstanding information, and the next contact. Do not promise a recovery, imply that another institution has frozen funds without confirmation, or offer a legal outcome before the authorized team has assessed it.
Practice an investigation handoff
The fictional example below tests a conflicting chronology, an unverified contact channel, and an unsupported outcome statement. Explore both choices at each stage to see what evidence the investigator needs. The exercise does not transmit a payment, request a recall, or collect customer information.
Build a case file that separates actions from outcomes
The following structure is a suggested handoff, not a regulator-mandated form. Keep links to restricted supporting material inside approved bank systems.
| Case field |
What to capture |
Common mistake to avoid |
| Notice and identity |
Report time, verified contact channel, customer account of events |
Treating unverified callback details as trusted |
| Payment facts |
Amount, currency, reference, relevant parties, system-confirmed status |
Repeating the customer's payment status as a confirmed fact |
| Response actions |
Owner, channel, request time, acknowledgment, next step |
Reporting a recall request as a recovery |
| Evidence inventory |
Original messages, instructions, source locations, relevant records |
Losing context by retaining only a cropped screenshot |
| Chronology |
Event time, report time, source, unresolved differences |
Merging conflicting accounts into a single asserted narrative |
| Decision handoffs |
Recovery, security, reporting, legal and customer-response owners |
Assuming an IC3 complaint completes every obligation |
At closure or transfer, distinguish the amount sent, the amount confirmed returned if any, unresolved exposure, and the basis for the recorded outcome. Apply the bank's access controls and record-management requirements. No person should have to infer an approval from a blank field.
Connect investigation preparation to governed automation
Bretton's documented scam and authorized-fraud use case brings customer activity, payment context, and beneficiary risk into the investigation. Its platform describes agents gathering evidence, applying the bank's policy, and drafting a case for team approval. Those capabilities connect directly to the case-preparation work in this guide. Bretton platform and fraud use case
The checks below are suggested requirements to evaluate for a bank's particular records and procedures. They are not a claim that Bretton performs payment recalls, recovers funds, or has every BEC-specific check preconfigured.
Automation can be evaluated for assembling records, extracting payment references, comparing instructions, and drafting a chronology with citations. Test it with conflicting dates, time zones, lookalike names, changed beneficiary instructions, and missing evidence. A plausible narrative that smooths over a contradiction is a failure, even if it reads well.
Keep payment actions and final decisions within the bank's authorized processes. A generated summary should not trigger an unreviewed transfer, recall, account restriction, reimbursement decision, or report. When an input is unverified, the output should preserve that uncertainty and the source attribution. These are proposed control boundaries, not claims that a specific tool already performs every task.
Measure case preparation quality and rework
Track preparation time alongside the share of material timeline events linked to a source, unresolved contradictions by owner and age, and files returned because evidence is missing or a narrative overstates the facts. Define the measures consistently and compare cases with similar payment methods, evidence availability, and complexity. Faster drafting alone does not establish a better investigation.
Track urgent payment escalation separately so case preparation never delays the authorized response team. Recovery outcomes belong in a separate operational record and are not evidence that an investigation-preparation tool guarantees returned funds. This guide sets no universal response window; the cited IC3 guidance calls for prompt institution contact.
Common questions
Should an investigator finish the narrative before a recall is requested?
Do not make narrative completion the gate for urgent payment-response routing. Collect the actionable details required by the bank's process and coordinate evidence work in parallel. The authorized payment team determines what action is available.
Does a familiar sender name prove the instruction is genuine?
No. FinCEN describes both compromised accounts and impersonation through spoofed or lookalike addresses. Check the instruction through an established or independently verified channel, especially when account information changes.
Does a recall request mean the funds will come back?
No. IC3 notes that institution policies differ, and FinCEN states that recovery is not assured. Record the request and the actual response separately. Do not report recovered funds until the outcome is confirmed.
Does calling a case BEC settle liability or reimbursement?
No. BEC describes a fraud pattern, not a complete legal classification. Preserve the initiation and authorization evidence and route the applicable-law and customer-response questions to the bank's authorized teams.
Sources and applicability
Sources checked October 1, 2026. The workflow, timeline labels, checklist, and fictional exercise are editorial recommendations. The 2019 FinCEN advisory is used for the stated fraud patterns, verification principles, coordination, and recovery limitation, not as a substitute for checking current reporting rules.
-
FBI Internet Crime Complaint Center, Business Email Compromise. Incident response and prevention guidance.
-
IC3, Business Email Compromise advisory, September 11, 2024. Prompt institution contact, recovery requests, policy differences, and complaints. Historical loss statistics from this source are intentionally not presented as current figures.
-
FinCEN Advisory FIN-2019-A005, July 16, 2019. Coordination on p. 2; definitions on pp. 2–3; verification and recovery limits on p. 8.
-
Bretton platform and use cases. Product source for scam and authorized-fraud investigation support, customer activity, payment context, beneficiary risk, and case preparation for team approval.
For a broader view of evidence preparation, see Bretton's case-file automation guide.