Financial Cybercrime Analysis
3 min read · Last updated
A supplier payment was diverted after an intrusion into a shared mailbox, combining a technical incident with a financial loss.
Executive Summary
A scheduled supplier payment was routed to an account controlled by a third party following the modification of banking details in an email thread. The modification originated from within the organisation's own mail environment.
The engagement reconstructed the intrusion timeline, documented the manipulation of the correspondence and produced a package for the receiving bank and national reporting.
Investigation Scope
Scope covered both the technical intrusion and the financial diversion as a single timeline.
- ›Reconstruction of authentication and mailbox access events
- ›Documentation of message manipulation and rule creation
- ›Reconstruction of the payment instruction chain
- ›Preparation of bank recall support and regulatory notification material
Technical Challenges
Log retention in the mail platform was shorter than the intrusion window, so part of the timeline had to be reconstructed from message headers and endpoint artefacts rather than from platform logs.
The manipulated thread had been partially deleted, requiring recovery of the original message state from counterparties.
Investigation Methodology
Technical and financial evidence were reconstructed in parallel and correlated at the end.
- ›Extraction of available sign-in and audit records within retention
- ›Header analysis of every message in the affected thread
- ›Recovery of the unmodified thread state from counterparty mailboxes
- ›Correlation of access events with the payment instruction timeline
Blockchain Analysis
A secondary portion of the diverted funds was converted into digital assets shortly after receipt. That portion was traced on-chain from the conversion point through consolidation to deposit addresses attributable to a centralised service.
The fiat and on-chain segments were reported as one continuous timeline rather than as separate analyses.
Evidence Collection
Technical artefacts and financial records were preserved to a consistent standard so both could be relied on in the same submission.
- ›Sign-in and audit exports with the retention limit documented
- ›Full message headers and hash-verified copies of both thread states
- ›Payment instruction records and on-chain conversion evidence
Findings
The investigation established unauthorised mailbox access preceding the change of banking details, the creation of a rule that concealed counterparty replies, and the onward conversion of a portion of the funds into digital assets.
Gaps caused by log retention were stated explicitly rather than filled by inference.
Outcome
Documentation was delivered for bank recall support, insurer notification and national reporting, together with a short remediation summary of the access conditions observed.
No outcome is promised in any engagement. The deliverable is a documented, verifiable evidentiary record.
Lessons Learned
Default log retention is frequently shorter than the dwell time of the intrusion it would need to explain.
- ›Extend audit-log retention before an incident makes it relevant
- ›Preserve mailbox state immediately, before remediation overwrites it
- ›Verify banking-detail changes through a channel other than email
Frequently asked questions
- Is a payment diversion a technical or a financial matter?
- Both, and it should be investigated as one timeline. Separating the intrusion analysis from the payment analysis usually weakens the evidentiary record institutions need.
- What if logs have already expired?
- Parts of the timeline can often be rebuilt from message headers, endpoint artefacts and counterparty records. Remaining gaps must be reported as gaps.
- Can documentation support a bank recall?
- It can provide the factual basis a recall request relies on. Whether a recall succeeds is determined by the receiving institution and the timing of the request.

- Cyber Intelligence
- Blockchain Investigations
- Digital Forensics
The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.
Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.
About the research teamRelated case studies
Request Confidential Consultation
SEQRIA provides technical investigation, forensic analysis and evidentiary documentation. Outcomes are never guaranteed. Case intake is confidential and handled by email.
cybersec@securida.info