The Wire Instruction Came From Your Supplier. Except It Didn’t.
Business Email Compromise in Kenya rarely looks like a hack. It looks like an ordinary email, from an ordinary sender, asking for something an ordinary sender would ask for — until forensic analysis of the header tells a different story.
Business Email Compromise (BEC) in Kenya is proven, not assumed. Digital forensic examiners recover and analyze the full raw email header — not just what appears on screen — to establish whether a message was spoofed from outside the organisation or sent from a genuinely compromised Microsoft 365 mailbox. That distinction determines who is liable, what a bank can act on, and what a court will accept as evidence.
Why Business Email Compromise Is Kenya’s Costliest Quiet Fraud
Business Email Compromise doesn’t trip antivirus software or trigger a firewall alert. It exploits trust between two humans who already do business with each other — a supplier and a client, a CFO and a bookkeeper, a law firm and its escrow client. That’s what makes Business Email Compromise in Kenya so difficult for finance teams to catch in the moment, and why forensic reconstruction after the fact is so often the only route back to the truth — and to any recoverable funds.
Three patterns account for most of the BEC matters instructed to forensic examiners in Kenya:
Fake Invoice Fraud
A genuine supplier relationship is hijacked mid-transaction. New “updated” bank details arrive on an invoice that looks identical to every previous one — because the template, logo and reference numbers were copied from a real, intercepted email.
CEO Fraud
An urgent instruction, apparently from a senior executive, requests an unusual same-day transfer — deliberately timed for when the real executive is travelling or unreachable to verify by phone.
Payroll & Account Diversion
HR or payroll receives a request, apparently from an employee, to update salary bank details — quietly redirecting future payroll to an account the employee never opened.
Spoofing vs. Compromise: Two Different Crimes, Two Different Evidence Trails
Every BEC case forensically resolves into one of two categories, and the distinction changes everything about liability and recovery:
Email Spoofing
The attacker never accessed the real account. Instead, they forge the “From” name and address so the message displays as if it came from a trusted sender, while it was actually sent through an entirely different mail server. Spoofing leaves its fingerprints in authentication results and the header’s server path — the account itself was never touched.
Account Compromise
Here, the attacker genuinely logged into the real mailbox, usually via a phished password or a stolen session token. The email genuinely came from the real account — the evidence trail instead lives in sign-in logs, new mailbox rules, and permission changes inside Microsoft 365, not in the header’s authentication fields.
Header Analysis: Reading What the Inbox Doesn’t Show You
Every email carries a raw header most people never see — a technical record of every server it passed through and every authentication check it was subjected to. This is the primary forensic artifact in a spoofing investigation.
What the Reader Sees vs. What the Header Actually Records
A simplified, illustrative header — annotated the way an examiner reads it during a Business Email Compromise investigation in Kenya.
Three fields do most of the work in a spoofing determination. SPF (Sender Policy Framework) checks whether the sending server is authorised to send on behalf of that domain. DKIM (DomainKeys Identified Mail) verifies a cryptographic signature tied to the domain, which a spoofer cannot forge without access to the domain’s private key. DMARC tells receiving servers what to do when SPF or DKIM fail — and its own pass/fail result, together with the alignment between the visible “From” and the technical “Return-Path,” is often the single clearest indicator an examiner presents to a court or a bank’s fraud team.
A subtly misspelled domain — an extra letter, a swapped character, a different top-level domain — is one of the most common spoofing techniques precisely because it survives a quick visual read. Forensic analysis compares every domain reference in the header character-by-character, which is where these near-identical impersonations are caught.
Microsoft 365 Investigations: What to Pull When the Mailbox Itself Was Compromised
When the evidence points to genuine account compromise rather than spoofing, the investigation moves from the header into Microsoft 365’s own audit and security infrastructure.
Unified Audit Log: records mailbox access, file access, and administrative actions — the primary timeline for establishing exactly when compromise occurred and what the attacker did with access.
Malicious forwarding rules: attackers frequently create a hidden rule that silently forwards or deletes specific incoming emails — commonly used to intercept invoice replies and hide them from the real account owner.
Azure AD sign-in records: reveal login location, device, and “impossible travel” patterns — a login from Nairobi followed minutes later by one from an unrelated country is a strong compromise indicator.
Mailbox delegate & permission changes: attackers sometimes grant themselves or another mailbox ongoing access rather than repeatedly logging in — a change examiners specifically check for.
Where This Sits in Kenyan Law
- Computer Misuse & Cybercrimes Act 2018: unauthorised access to a mailbox and forgery of an electronic message both form distinct criminal grounds under the Act.
- Evidence Act (Cap. 80), ss. 106A–106C: email headers and Microsoft 365 audit logs must be shown to be from a system in regular, properly functioning use before a Kenyan court will admit them.
- Data Protection Act 2019: governs how examiners lawfully extract and process mailbox and audit-log data belonging to employees during a corporate BEC investigation.
KES 4.1M Invoice, One Character Different in the Domain
A manufacturing client paid a long-standing supplier’s “updated” invoice, wired to a new account. The supplier later denied sending it. Header analysis showed the Return-Path domain differed from the genuine supplier domain by a single substituted character, with SPF and DKIM both failing outright. Microsoft 365 logs on the client’s own mailbox showed no compromise — the client’s account was never touched; the fraud was pure spoofing aimed at the finance team’s inbox.
Frequently Asked Questions
Can email spoofing be proven if the message looked completely legitimate?
Yes, in almost every case. What the reader sees in an inbox and what the raw header actually records are two different things. Even a convincingly formatted email carries SPF, DKIM and DMARC authentication results, and a Received-header path, that reveal whether it truly originated from the domain it claims to.
How long are Microsoft 365 audit logs available after a suspected BEC incident?
Retention depends on the organization’s licensing tier, but standard Unified Audit Log retention is materially shorter than most victims assume, and inbox rule and sign-in artifacts can be overwritten by ongoing account activity. Preserving logs and disabling further account changes as soon as BEC is suspected is the single most time-sensitive step.
What’s the forensic difference between a spoofed email and a fully compromised mailbox?
A spoofed email is sent from outside the victim’s real mailbox but forged to display a trusted name or address — it never touched the genuine account. A compromised mailbox means the attacker actually logged into the real account, which leaves a different evidence trail: sign-in logs, new inbox rules, and mailbox permission changes rather than header inconsistencies.
If the fraudulent payment already left Kenya, can forensic evidence still support recovery?
Yes — the forensic email trail is frequently what supports a bank’s fraud recall request or a cross-border legal recovery action, even after funds have moved. The email evidence establishes how and when the fraud occurred, which underpins the legal case even when the money itself has already crossed jurisdictions.
Suspect a Fraudulent Wire Instruction?
Email headers and Microsoft 365 logs age fast. Free, confidential case assessment for banks, corporates and law firms — response within 4 hours.