REF-2026-0163 · Anonymised case record

    Financial Cybercrime Analysis

    3 min read · Last updated

    A supplier payment was diverted after an intrusion into a shared mailbox, combining a technical incident with a financial loss.

    Executive Summary

    A scheduled supplier payment was routed to an account controlled by a third party following the modification of banking details in an email thread. The modification originated from within the organisation's own mail environment.

    The engagement reconstructed the intrusion timeline, documented the manipulation of the correspondence and produced a package for the receiving bank and national reporting.

    Investigation Scope

    Scope covered both the technical intrusion and the financial diversion as a single timeline.

    • Reconstruction of authentication and mailbox access events
    • Documentation of message manipulation and rule creation
    • Reconstruction of the payment instruction chain
    • Preparation of bank recall support and regulatory notification material

    Technical Challenges

    Log retention in the mail platform was shorter than the intrusion window, so part of the timeline had to be reconstructed from message headers and endpoint artefacts rather than from platform logs.

    The manipulated thread had been partially deleted, requiring recovery of the original message state from counterparties.

    Investigation Methodology

    Technical and financial evidence were reconstructed in parallel and correlated at the end.

    • Extraction of available sign-in and audit records within retention
    • Header analysis of every message in the affected thread
    • Recovery of the unmodified thread state from counterparty mailboxes
    • Correlation of access events with the payment instruction timeline

    Blockchain Analysis

    A secondary portion of the diverted funds was converted into digital assets shortly after receipt. That portion was traced on-chain from the conversion point through consolidation to deposit addresses attributable to a centralised service.

    The fiat and on-chain segments were reported as one continuous timeline rather than as separate analyses.

    Evidence Collection

    Technical artefacts and financial records were preserved to a consistent standard so both could be relied on in the same submission.

    • Sign-in and audit exports with the retention limit documented
    • Full message headers and hash-verified copies of both thread states
    • Payment instruction records and on-chain conversion evidence

    Findings

    The investigation established unauthorised mailbox access preceding the change of banking details, the creation of a rule that concealed counterparty replies, and the onward conversion of a portion of the funds into digital assets.

    Gaps caused by log retention were stated explicitly rather than filled by inference.

    Outcome

    Documentation was delivered for bank recall support, insurer notification and national reporting, together with a short remediation summary of the access conditions observed.

    No outcome is promised in any engagement. The deliverable is a documented, verifiable evidentiary record.

    Lessons Learned

    Default log retention is frequently shorter than the dwell time of the intrusion it would need to explain.

    • Extend audit-log retention before an incident makes it relevant
    • Preserve mailbox state immediately, before remediation overwrites it
    • Verify banking-detail changes through a channel other than email

    Frequently asked questions

    Is a payment diversion a technical or a financial matter?
    Both, and it should be investigated as one timeline. Separating the intrusion analysis from the payment analysis usually weakens the evidentiary record institutions need.
    What if logs have already expired?
    Parts of the timeline can often be rebuilt from message headers, endpoint artefacts and counterparty records. Remaining gaps must be reported as gaps.
    Can documentation support a bank recall?
    It can provide the factual basis a recall request relies on. Whether a recall succeeds is determined by the receiving institution and the timing of the request.
    Author
    SEQRIA Research Team emblem
    SEQRIA Research TeamInvestigative research unit, SEQRIA
    • Cyber Intelligence
    • Blockchain Investigations
    • Digital Forensics

    The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.

    Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.

    About the research team

    Related case studies

    Request Confidential Consultation

    SEQRIA provides technical investigation, forensic analysis and evidentiary documentation. Outcomes are never guaranteed. Case intake is confidential and handled by email.

    cybersec@securida.info
    Intelligence Center