Business email compromise (BEC) rarely looks like a Hollywood hack. It looks like a slightly off invoice, a “new banking details” note from someone you trust, or a mailbox that suddenly won’t sync. For Midwest SMBs and clinics, the losses come from hours of delay — not from missing an exotic zero-day.
This playbook is generic. It is not a substitute for your incident plan, and it does not describe any specific client. If you already have a managed security partner, call them first.
What “suspect BEC” usually looks like
- A coworker’s email asking you to change wire instructions — then they deny sending it when you call them.
- External partners reporting weird messages from your domain.
- Users locked out, MFA prompts they didn’t expect, or mail rules they didn’t create.
- Finance noticing a payment went to an unfamiliar account.
First hour — contain, then investigate
- Assume the session is hostile. From a known-good device (not the possibly compromised laptop), reset the password and revoke active sessions / sign the user out everywhere.
- Re-check MFA. If the attacker enrolled their own authenticator, reset MFA methods before declaring the account clean.
- Hunt for persistence. Look for mailbox forwarding, inbox rules that hide or auto-delete mail, delegated access, and OAuth apps with mail or files scopes.
- Preserve evidence lightly. Screenshot rules and app grants before deleting them. Note approximate times. Don’t wipe the machine until someone coordinating response says it’s safe.
- Finance out-of-band. If payment instructions may have changed, call banks and vendors on known phone numbers — not numbers from the suspicious email thread.
What not to do
- Don’t “wait and see” overnight hoping the phishing email was a one-off.
- Don’t reply to the attacker asking if the request is real.
- Don’t reset passwords from the same infected endpoint without containment guidance.
- Don’t invent a press narrative. Fix access, notify the right parties, document facts.
After containment — harden so it doesn’t recur
Most BEC survivors need the same follow-through: MFA everywhere that matters, external sender tagging, forwarding audits, DMARC moving toward enforcement, phishing simulations, and identity threat detection that catches mailbox takeover after a user is already phished. That program lives on our email security page — layered with Huntress or Guardz cyber, not a single filter logo.
If email is simply “down” rather than compromised, start at IT support or the Lincoln/Omaha outage guide at email down in Lincoln & Omaha. If you’re not sure which fork you’re on, call 531-625-2111 — we’ll triage outage vs compromise without a lecture.
Lincoln and Omaha — what “email hacked” usually means here
The searches we see from Nebraska are blunt: email hacked Lincoln Nebraska, business email compromised Omaha, phishing Microsoft 365 Lincoln. The pattern is the same whether you’re a Haymarket professional office or a West Omaha clinic: a payment-change email, a mailbox that forwards to an address nobody recognizes, or a user who clicked and now MFA prompts won’t stop.
- Lincoln: Hickman-based team, primary market, no retail storefront. Same-day triage is a drive, not a national dispatch. City hub: Lincoln managed IT.
- Omaha: Metro coverage including Bellevue, Papillion, La Vista, Gretna, and Elkhorn — still a service-area business, not an Omaha HQ. City hub: Omaha managed IT.
Clinics: start with behavioral health IT or healthcare so email hardening includes a BAA conversation. Construction offices: BEC against a draw is as common as jobsite theft — construction.
Related: cyber insurability self-check · Microsoft 365 management · Google Workspace management · phishing click playbook


