Business Email Compromise Kenya · Digital Forensics

The Wire Instruction Came From Your Supplier. Except It Didn’t.

Business Email Compromise in Kenya rarely looks like a hack. It looks like an ordinary email, from an ordinary sender, asking for something an ordinary sender would ask for — until forensic analysis of the header tells a different story.

3Authentication checks every header must pass
90 DaysTypical M365 audit log window before evidence degrades
106AEvidence Act standard for email admissibility
In short

Business Email Compromise (BEC) in Kenya is proven, not assumed. Digital forensic examiners recover and analyze the full raw email header — not just what appears on screen — to establish whether a message was spoofed from outside the organisation or sent from a genuinely compromised Microsoft 365 mailbox. That distinction determines who is liable, what a bank can act on, and what a court will accept as evidence.

Banks & Financial Institutions Corporates & Finance Teams Law Firms & Litigators

Why Business Email Compromise Is Kenya’s Costliest Quiet Fraud

Business Email Compromise doesn’t trip antivirus software or trigger a firewall alert. It exploits trust between two humans who already do business with each other — a supplier and a client, a CFO and a bookkeeper, a law firm and its escrow client. That’s what makes Business Email Compromise in Kenya so difficult for finance teams to catch in the moment, and why forensic reconstruction after the fact is so often the only route back to the truth — and to any recoverable funds.

Three patterns account for most of the BEC matters instructed to forensic examiners in Kenya:

🧾

Fake Invoice Fraud

A genuine supplier relationship is hijacked mid-transaction. New “updated” bank details arrive on an invoice that looks identical to every previous one — because the template, logo and reference numbers were copied from a real, intercepted email.

🧑‍💼

CEO Fraud

An urgent instruction, apparently from a senior executive, requests an unusual same-day transfer — deliberately timed for when the real executive is travelling or unreachable to verify by phone.

💰

Payroll & Account Diversion

HR or payroll receives a request, apparently from an employee, to update salary bank details — quietly redirecting future payroll to an account the employee never opened.

“The logo is real. The signature block is real. The one thing that isn’t real is the path the email actually travelled to reach the inbox.”

Spoofing vs. Compromise: Two Different Crimes, Two Different Evidence Trails

Every BEC case forensically resolves into one of two categories, and the distinction changes everything about liability and recovery:

Email Spoofing

The attacker never accessed the real account. Instead, they forge the “From” name and address so the message displays as if it came from a trusted sender, while it was actually sent through an entirely different mail server. Spoofing leaves its fingerprints in authentication results and the header’s server path — the account itself was never touched.

Account Compromise

Here, the attacker genuinely logged into the real mailbox, usually via a phished password or a stolen session token. The email genuinely came from the real account — the evidence trail instead lives in sign-in logs, new mailbox rules, and permission changes inside Microsoft 365, not in the header’s authentication fields.

Header Analysis: Reading What the Inbox Doesn’t Show You

Every email carries a raw header most people never see — a technical record of every server it passed through and every authentication check it was subjected to. This is the primary forensic artifact in a spoofing investigation.

Anatomy of a Spoofed Header

What the Reader Sees vs. What the Header Actually Records

A simplified, illustrative header — annotated the way an examiner reads it during a Business Email Compromise investigation in Kenya.

From:Finance Director <[email protected]>
Reply-To:[email protected]DOMAIN MISMATCH
Return-Path:[email protected]UNRELATED DOMAIN
Received:from unlisted-smtp-relay (unverified) by …UNRECOGNISED SERVER
SPF:softfailFAIL
DKIM:noneFAIL
DMARC:fail, p=rejectFAIL
FAIL Authentication check failed — strong spoofing indicator
WARN Inconsistent but not conclusive alone
PASS Consistent with genuine sender

Three fields do most of the work in a spoofing determination. SPF (Sender Policy Framework) checks whether the sending server is authorised to send on behalf of that domain. DKIM (DomainKeys Identified Mail) verifies a cryptographic signature tied to the domain, which a spoofer cannot forge without access to the domain’s private key. DMARC tells receiving servers what to do when SPF or DKIM fail — and its own pass/fail result, together with the alignment between the visible “From” and the technical “Return-Path,” is often the single clearest indicator an examiner presents to a court or a bank’s fraud team.

A subtly misspelled domain — an extra letter, a swapped character, a different top-level domain — is one of the most common spoofing techniques precisely because it survives a quick visual read. Forensic analysis compares every domain reference in the header character-by-character, which is where these near-identical impersonations are caught.

Microsoft 365 Investigations: What to Pull When the Mailbox Itself Was Compromised

When the evidence points to genuine account compromise rather than spoofing, the investigation moves from the header into Microsoft 365’s own audit and security infrastructure.

AUDIT LOG

Unified Audit Log: records mailbox access, file access, and administrative actions — the primary timeline for establishing exactly when compromise occurred and what the attacker did with access.

INBOX RULES

Malicious forwarding rules: attackers frequently create a hidden rule that silently forwards or deletes specific incoming emails — commonly used to intercept invoice replies and hide them from the real account owner.

SIGN-IN LOGS

Azure AD sign-in records: reveal login location, device, and “impossible travel” patterns — a login from Nairobi followed minutes later by one from an unrelated country is a strong compromise indicator.

PERMISSIONS

Mailbox delegate & permission changes: attackers sometimes grant themselves or another mailbox ongoing access rather than repeatedly logging in — a change examiners specifically check for.

Illustrative Matter · Nairobi · Corporate & Banking Instruction

KES 4.1M Invoice, One Character Different in the Domain

A manufacturing client paid a long-standing supplier’s “updated” invoice, wired to a new account. The supplier later denied sending it. Header analysis showed the Return-Path domain differed from the genuine supplier domain by a single substituted character, with SPF and DKIM both failing outright. Microsoft 365 logs on the client’s own mailbox showed no compromise — the client’s account was never touched; the fraud was pure spoofing aimed at the finance team’s inbox.

Header evidence and authentication failure documented to support the client’s bank fraud-recall request and onward legal action.

Frequently Asked Questions

Can email spoofing be proven if the message looked completely legitimate?

Yes, in almost every case. What the reader sees in an inbox and what the raw header actually records are two different things. Even a convincingly formatted email carries SPF, DKIM and DMARC authentication results, and a Received-header path, that reveal whether it truly originated from the domain it claims to.

How long are Microsoft 365 audit logs available after a suspected BEC incident?

Retention depends on the organization’s licensing tier, but standard Unified Audit Log retention is materially shorter than most victims assume, and inbox rule and sign-in artifacts can be overwritten by ongoing account activity. Preserving logs and disabling further account changes as soon as BEC is suspected is the single most time-sensitive step.

What’s the forensic difference between a spoofed email and a fully compromised mailbox?

A spoofed email is sent from outside the victim’s real mailbox but forged to display a trusted name or address — it never touched the genuine account. A compromised mailbox means the attacker actually logged into the real account, which leaves a different evidence trail: sign-in logs, new inbox rules, and mailbox permission changes rather than header inconsistencies.

If the fraudulent payment already left Kenya, can forensic evidence still support recovery?

Yes — the forensic email trail is frequently what supports a bank’s fraud recall request or a cross-border legal recovery action, even after funds have moved. The email evidence establishes how and when the fraud occurred, which underpins the legal case even when the money itself has already crossed jurisdictions.

Suspect a Fraudulent Wire Instruction?

Email headers and Microsoft 365 logs age fast. Free, confidential case assessment for banks, corporates and law firms — response within 4 hours.