Problem-Stage · Friday

What should a Hawaii business do the first 72 hours after a Microsoft 365 account compromise?

In the first 72 hours after a Microsoft 365 account compromise, a Hawaii business does five things in order: recall any fraudulent wire before it settles, file at ic3.gov to trigger the FBI Financial Fraud Kill Chain, contain the mailbox by revoking sessions and rotating credentials, preserve evidence including inbox rules and mail-forwarding, and notify the cyber insurance carrier. Wire recall success drops fast after 72 hours.

Why this is the biggest dollar risk a Hawaii SMB actually faces in 2026

The FBI IC3 2025 Internet Crime Report logged $3.046 billion in reported U.S. business email compromise losses across 24,768 complaints — $122,000 average, 86 percent moving by wire or ACH. Ransomware in the same report: $32.3 million. BEC is roughly 94 times the reported dollar exposure.

The Hawaii pattern is not exotic. A manager mailbox at a Honolulu firm gets phished during a neighbor-island trip, an OAuth consent goes to a look-alike Microsoft app, an inbox rule moves vendor mail into RSS Feeds, and two weeks later a $173,000 wire routes to a fraudulent “new remit-to” account. This post is the 72-hour response plan for that scenario, ordered so an owner, controller, or IT lead can work the checklist under stress.

Hour 0 to Hour 1: recall the wire, file with the FBI

If money has already moved, this is the only hour that matters. Every other control on the list is a follow-up.

Do not pause for internal debate. Do not wait for the mailbox owner to confirm. The dollar is moving on a clock; the callback buys time on that clock.

Hour 1 to Hour 4: preserve evidence before you contain

Do preservation first so the FBI report and the insurance claim have raw material.

Hour 4 to Hour 24: contain the mailbox and the tenant

Now you can move. In this order:

Assume the attacker is monitoring the mailbox during your response. Do not discuss the incident using the compromised account or same-tenant email until the tenant is clean.

Hour 24 to Hour 72: notify carriers, counsel, and required parties

What this looked like at a 34-person Honolulu firm last quarter

A 34-person Honolulu professional services firm — one downtown office in the Pioneer Plaza area, Microsoft 365 Business Premium tenant, QuickBooks Online, a Hawaii community bank on the operating account — ran this exact 72-hour sequence in Q2 2026 after a controller flagged an inbox rule she had not written.

What happened: a manager's mailbox had been quietly compromised for 11 days after an OAuth consent phish. The attacker set an inbox rule moving vendor mail into RSS Feeds, then replied to a legitimate vendor thread with new bank instructions from a look-alike domain. The controller almost sent a $91,400 wire before noticing the manager was cc'd on an outbound reply she had not sent.

The 72-hour timeline:

Total dollar loss: zero. Response time: ~40 hours across IT provider and staff. Insurance-covered cost: ~$18,000 in forensic labor and counsel review. Cost avoided: $91,400 wire plus Chapter 487N exposure.

The prevention layer worth putting in before the incident happens

Every control below is cheaper than the wire-recall phone call:

For related reading: our first 72 hours after a ransomware event, the 2026 Hawaii cyber insurance renewal checklist, and the Hawaii property management IT baseline.

Why HI Tech Hui is publishing the 72-hour Microsoft 365 playbook

HI Tech Hui has been the managed IT and cybersecurity provider for Hawaii businesses since 2014, operating from 401 Kamakee Street in Kakaako with a Cyberuptive-run security operations capability. Microsoft 365 mailbox compromise is the most common incident we work in any given month across the Hawaii SMB client base. If you take one thing from this post: put a callback-to-known-number policy on paper today, before you need it, and route every wire and payment-instruction change through it without exception.

Frequently asked questions

What should a Hawaii business do the first 72 hours after a Microsoft 365 account compromise?

In the first 72 hours after a Microsoft 365 account compromise, a Hawaii business does five things in order: recall any fraudulent wire before it settles, file at ic3.gov to trigger the FBI Financial Fraud Kill Chain, contain the mailbox by revoking sessions and rotating credentials, preserve evidence including inbox rules and mail-forwarding, and notify the cyber insurance carrier. Wire recall success drops fast after 72 hours.

What is business email compromise and why is it a bigger dollar risk than ransomware for a Hawaii SMB?

Business email compromise is fraud that uses a compromised or spoofed email account to trick a business into wiring money to an attacker. The FBI IC3 2025 report logged $3.046 billion in reported U.S. BEC losses across 24,768 complaints — roughly $122,000 average — against $32.3 million in direct ransomware losses. For a Hawaii SMB, BEC is about 94 times the reported dollar exposure.

How do I know if my Microsoft 365 mailbox has been compromised?

The clearest indicators are an inbox rule you did not create that moves messages to RSS Feeds, Deleted Items, or a rarely used folder; mail-forwarding turned on to an external address; sign-in logs from countries you do not travel to; sent items you did not write; and an OAuth application consent you do not recognize in Enterprise Applications. Any one of those is enough to open an incident.

How fast do I need to call the bank to recall a fraudulent wire?

Same hour, ideally same 30 minutes. The FBI IC3 Recovery Asset Team froze $679 million in redirected funds in 2025 with a 58 percent success rate, but that success rate depends on the victim reporting inside the first 24 hours with a complete transaction record. After the funds move to a second bank or off-ramp to cryptocurrency, recall becomes exponentially harder.

Who exactly do I call, and in what order, when a Hawaii business gets hit?

Call the bank's wire fraud desk first and request an immediate wire recall with routing, account, timestamp, and amount ready. File at ic3.gov within the same hour to activate the Financial Fraud Kill Chain. Notify the FBI Honolulu field office directly for local coordination. Call the cyber insurance carrier next; most policies require notice inside 24 to 72 hours. Then engage your managed IT provider for containment.

What Microsoft 365 evidence should I preserve before touching anything?

Before revoking sessions or resetting passwords, export the compromised mailbox using an eDiscovery search or PST export, capture full email headers for the fraudulent thread, snapshot inbox rules and mail-forwarding settings, export the Unified Audit Log for the affected user for the last 90 days, list all OAuth application consents, and list mailbox delegations. Preservation before containment is what makes the FBI report and the insurance claim work.

What Microsoft 365 controls should have prevented this and need to be turned on now?

Phishing-resistant multi-factor authentication on every user account, conditional access blocking sign-ins from outside the United States by default, mail-forwarding to external domains disabled at the tenant level, OAuth application consent restricted to admin approval, DMARC published at reject or quarantine, and a written callback-to-known-number rule before any wire or payment-instruction change is executed. That last one is the highest-return control on the list.

Does a Hawaii business have to report a Microsoft 365 compromise under state law?

Hawaii Chapter 487N requires notification to affected residents without unreasonable delay after a breach of unencrypted personal information, and notice to the Office of Consumer Protection when 1,000 or more Hawaii residents are involved. A Microsoft 365 mailbox holding customer Social Security numbers, driver's license numbers, or financial account numbers is squarely in scope. Consult counsel early to scope the notification window.

Bottom line for Hawaii business owners and controllers

A Microsoft 365 account compromise is a wire fraud incident on a clock. Call the bank fraud desk inside the first hour, file at ic3.gov the same hour, preserve mailbox evidence before you touch the account, contain the mailbox and the tenant in hours 4 to 24, and notify your cyber insurance carrier and outside counsel in hours 24 to 72. On the prevention side, publish a callback-to-known-number rule for every wire and payment-instruction change, today, on one page. That single control does more than any technical stack against a $3 billion problem.