Business Email Compromise Kenya: How Digital Forensics Uncovers Fake Invoices & CEO Fraud
Business Email Compromise Kenya · Digital Forensics The Wire Instruction Came From Your Supplier. Except It Didn’t. Business Email Compromise in Kenya rarely looks like a hack. It looks like an ordinary email, from an ordinary sender, asking for something an ordinary sender would ask for — until forensic analysis of the header tells a different story. 3Authentication checks every header must pass 90 DaysTypical M365 audit log window before evidence degrades 106AEvidence Act standard for email admissibility In short Business Email Compromise (BEC) in Kenya is proven, not assumed. Digital forensic examiners recover and analyze the full raw email header — not just what appears on screen — to establish whether a message was spoofed from outside the organisation or sent from a genuinely compromised Microsoft 365 mailbox. That distinction determines who is liable, what a bank can act on, and what a court will accept as evidence. Banks & Financial Institutions Corporates & Finance Teams Law Firms & Litigators Why Business Email Compromise Is Kenya’s Costliest Quiet Fraud Business Email Compromise doesn’t trip antivirus software or trigger a firewall alert. It exploits trust between two humans who already do business with each other — a supplier and a client, a CFO and a bookkeeper, a law firm and its escrow client. That’s what makes Business Email Compromise in Kenya so difficult for finance teams to catch in the moment, and why forensic reconstruction after the fact is so often the only route back to the truth — and to any recoverable funds. Three patterns account for most of the BEC matters instructed to forensic examiners in Kenya: 🧾 Fake Invoice Fraud A genuine supplier relationship is hijacked mid-transaction. New “updated” bank details arrive on an invoice that looks identical to every previous one — because the template, logo and reference numbers were copied from a real, intercepted email. 🧑💼 CEO Fraud An urgent instruction, apparently from a senior executive, requests an unusual same-day transfer — deliberately timed for when the real executive is travelling or unreachable to verify by phone. 💰 Payroll & Account Diversion HR or payroll receives a request, apparently from an employee, to update salary bank details — quietly redirecting future payroll to an account the employee never opened. “The logo is real. The signature block is real. The one thing that isn’t real is the path the email actually travelled to reach the inbox.” Spoofing vs. Compromise: Two Different Crimes, Two Different Evidence Trails Every BEC case forensically resolves into one of two categories, and the distinction changes everything about liability and recovery: Email Spoofing The attacker never accessed the real account. Instead, they forge the “From” name and address so the message displays as if it came from a trusted sender, while it was actually sent through an entirely different mail server. Spoofing leaves its fingerprints in authentication results and the header’s server path — the account itself was never touched. Account Compromise Here, the attacker genuinely logged into the real mailbox, usually via a phished password or a stolen session token. The email genuinely came from the real account — the evidence trail instead lives in sign-in logs, new mailbox rules, and permission changes inside Microsoft 365, not in the header’s authentication fields. Header Analysis: Reading What the Inbox Doesn’t Show You Every email carries a raw header most people never see — a technical record of every server it passed through and every authentication check it was subjected to. This is the primary forensic artifact in a spoofing investigation. Anatomy of a Spoofed Header What the Reader Sees vs. What the Header Actually Records A simplified, illustrative header — annotated the way an examiner reads it during a Business Email Compromise investigation in Kenya. From:Finance Director <[email protected]> Reply-To:[email protected] MISMATCH Return-Path:[email protected] DOMAIN Received:from unlisted-smtp-relay (unverified) by …UNRECOGNISED SERVER SPF:softfailFAIL DKIM:noneFAIL DMARC:fail, p=rejectFAIL FAIL Authentication check failed — strong spoofing indicator WARN Inconsistent but not conclusive alone PASS Consistent with genuine sender Three fields do most of the work in a spoofing determination. SPF (Sender Policy Framework) checks whether the sending server is authorised to send on behalf of that domain. DKIM (DomainKeys Identified Mail) verifies a cryptographic signature tied to the domain, which a spoofer cannot forge without access to the domain’s private key. DMARC tells receiving servers what to do when SPF or DKIM fail — and its own pass/fail result, together with the alignment between the visible “From” and the technical “Return-Path,” is often the single clearest indicator an examiner presents to a court or a bank’s fraud team. A subtly misspelled domain — an extra letter, a swapped character, a different top-level domain — is one of the most common spoofing techniques precisely because it survives a quick visual read. Forensic analysis compares every domain reference in the header character-by-character, which is where these near-identical impersonations are caught. Microsoft 365 Investigations: What to Pull When the Mailbox Itself Was Compromised When the evidence points to genuine account compromise rather than spoofing, the investigation moves from the header into Microsoft 365’s own audit and security infrastructure. AUDIT LOG Unified Audit Log: records mailbox access, file access, and administrative actions — the primary timeline for establishing exactly when compromise occurred and what the attacker did with access. INBOX RULES Malicious forwarding rules: attackers frequently create a hidden rule that silently forwards or deletes specific incoming emails — commonly used to intercept invoice replies and hide them from the real account owner. SIGN-IN LOGS Azure AD sign-in records: reveal login location, device, and “impossible travel” patterns — a login from Nairobi followed minutes later by one from an unrelated country is a strong compromise indicator. PERMISSIONS Mailbox delegate & permission changes: attackers sometimes grant themselves or another mailbox ongoing access rather than repeatedly logging in — a change examiners specifically check for. Where This Sits in Kenyan Law Computer Misuse & Cybercrimes Act 2018: unauthorised access to a mailbox and forgery of an electronic message both form distinct criminal grounds under