Why this is the biggest dollar risk a Hawaii SMB actually faces in 2026
The FBI IC3 2025 Internet Crime Report logged $3.046 billion in reported U.S. business email compromise losses across 24,768 complaints — $122,000 average, 86 percent moving by wire or ACH. Ransomware in the same report: $32.3 million. BEC is roughly 94 times the reported dollar exposure.
The Hawaii pattern is not exotic. A manager mailbox at a Honolulu firm gets phished during a neighbor-island trip, an OAuth consent goes to a look-alike Microsoft app, an inbox rule moves vendor mail into RSS Feeds, and two weeks later a $173,000 wire routes to a fraudulent “new remit-to” account. This post is the 72-hour response plan for that scenario, ordered so an owner, controller, or IT lead can work the checklist under stress.
Hour 0 to Hour 1: recall the wire, file with the FBI
If money has already moved, this is the only hour that matters. Every other control on the list is a follow-up.
- Call the sending bank's wire fraud desk or fraud operations desk directly. Not general customer service. Request an immediate wire recall. Have the following ready: sending account, receiving bank name, receiving routing number, receiving account number, exact wire amount, wire timestamp, and any transaction reference number.
- File a complaint at ic3.gov the same hour. The report takes 10 to 15 minutes. Specifically request FBI Financial Fraud Kill Chain activation. IC3's Recovery Asset Team froze $679 million in redirected funds in 2025 with a 58 percent success rate — but only when the report lands inside the first 24 hours with a complete transaction record.
- Notify the FBI Honolulu field office (911 Ala Moana Boulevard) for local coordination. Provide the same transaction detail as the IC3 filing.
- If the wire went international or through a correspondent bank, ask the sending bank to initiate a SWIFT gpi recall through the correspondent chain.
Do not pause for internal debate. Do not wait for the mailbox owner to confirm. The dollar is moving on a clock; the callback buys time on that clock.
Hour 1 to Hour 4: preserve evidence before you contain
Do preservation first so the FBI report and the insurance claim have raw material.
- Export the compromised mailbox using Microsoft Purview eDiscovery or a PST export. Do not delete or move any messages first.
- Capture full email headers on the fraudulent thread and every related message.
- Snapshot current inbox rules, mail-forwarding settings, and mailbox delegations for the compromised account and any account it corresponds with.
- Export the Microsoft 365 Unified Audit Log for the affected user for the last 90 days. Sign-ins, mailbox actions, admin actions, OAuth consents, everything.
- List OAuth application consents for the affected user under Enterprise Applications. Flag any consent granted in the last 90 days that you do not recognize.
- Preserve chain of custody. One person collects, one person witnesses, everything gets a timestamp and a hash.
Hour 4 to Hour 24: contain the mailbox and the tenant
Now you can move. In this order:
- Force-reset the password on the compromised account. Use a strong random passphrase; do not reuse anything.
- Revoke all active sessions and refresh tokens for the account.
- Enforce phishing-resistant MFA on the account. If MFA was already on and got bypassed, treat the token as stolen and rotate everything.
- Remove every inbox rule and mail-forwarding entry that was not there before.
- Revoke every OAuth consent the account granted. Then, at the tenant level, restrict OAuth consent to admin approval only.
- Check for and disable any mailbox delegations the account granted.
- Review admin roles for any elevation the account received.
- Pull sign-in logs for every user in the tenant to look for the same attacker pattern — same IP range, same user-agent string, same time window.
Assume the attacker is monitoring the mailbox during your response. Do not discuss the incident using the compromised account or same-tenant email until the tenant is clean.
Hour 24 to Hour 72: notify carriers, counsel, and required parties
- Notify the cyber insurance carrier. Most policies require notice inside 24 to 72 hours; failure to notify inside the window is a common denial reason.
- Engage outside counsel for the notification analysis under Hawaii Chapter 487N. A mailbox holding customer Social Security numbers, driver's license numbers, or financial account numbers is inside the notification scope.
- Engage a forensic firm if the compromise touched multiple accounts, admin accounts, or any account with access to customer regulated data. The insurance panel firm is fine; the carrier usually requires it.
- Document a timeline for the record. Time of detection, time of first bank call, time of first IC3 filing, time of containment, time of insurance notice. This timeline is the difference between a covered claim and a denied claim.
- If you have a bank fraud loss under Hawaii Revised Statutes on record, coordinate with the bank's legal and the FBI on a joint recovery approach.
What this looked like at a 34-person Honolulu firm last quarter
A 34-person Honolulu professional services firm — one downtown office in the Pioneer Plaza area, Microsoft 365 Business Premium tenant, QuickBooks Online, a Hawaii community bank on the operating account — ran this exact 72-hour sequence in Q2 2026 after a controller flagged an inbox rule she had not written.
What happened: a manager's mailbox had been quietly compromised for 11 days after an OAuth consent phish. The attacker set an inbox rule moving vendor mail into RSS Feeds, then replied to a legitimate vendor thread with new bank instructions from a look-alike domain. The controller almost sent a $91,400 wire before noticing the manager was cc'd on an outbound reply she had not sent.
The 72-hour timeline:
- Hour 0: Controller called the community bank's fraud desk. Wire held.
- Hour 1-2: IC3 filing submitted with Financial Fraud Kill Chain request. FBI Honolulu field office notified.
- Hour 3-4: Mailbox export, headers, inbox-rule snapshot, OAuth consent list, 90-day audit log all preserved. One rogue OAuth consent to a “Microsoft eDiscovery Helper” app that was not from Microsoft.
- Hour 5-8: Password reset, session revocation, FIDO2 MFA re-enforced, inbox rules and forwarding cleared, OAuth consent revoked, tenant-level consent restricted to admin approval.
- Hour 12: Sign-in logs pulled for all 34 users. Same attacker IP probed two other mailboxes with no successful sign-in.
- Hour 20-48: Insurance carrier notified, panel forensic firm engaged, outside counsel confirmed no customer PII was accessed — Chapter 487N not triggered.
- Hour 72: Post-incident report filed with carrier; callback-to-known-number policy published to staff.
Total dollar loss: zero. Response time: ~40 hours across IT provider and staff. Insurance-covered cost: ~$18,000 in forensic labor and counsel review. Cost avoided: $91,400 wire plus Chapter 487N exposure.
The prevention layer worth putting in before the incident happens
Every control below is cheaper than the wire-recall phone call:
- Phishing-resistant MFA on every account (FIDO2 or Windows Hello for Business preferred over SMS or app-push).
- Conditional access blocking sign-ins from outside the U.S. by default.
- Tenant-level OAuth consent restricted to admin approval.
- Tenant-level restriction on external mail-forwarding.
- DMARC at reject or quarantine on every owned domain, cousin domains included.
- One-page callback-to-known-number policy for every wire, ACH, banking change, or payroll routing change — number comes from the internal directory, not the email.
- Dual authorization above a defined dollar threshold on outbound payments.
- Quarterly phishing simulations using Hawaii owner and vendor impersonation scenarios.
For related reading: our first 72 hours after a ransomware event, the 2026 Hawaii cyber insurance renewal checklist, and the Hawaii property management IT baseline.
Why HI Tech Hui is publishing the 72-hour Microsoft 365 playbook
HI Tech Hui has been the managed IT and cybersecurity provider for Hawaii businesses since 2014, operating from 401 Kamakee Street in Kakaako with a Cyberuptive-run security operations capability. Microsoft 365 mailbox compromise is the most common incident we work in any given month across the Hawaii SMB client base. If you take one thing from this post: put a callback-to-known-number policy on paper today, before you need it, and route every wire and payment-instruction change through it without exception.
Frequently asked questions
What should a Hawaii business do the first 72 hours after a Microsoft 365 account compromise?
In the first 72 hours after a Microsoft 365 account compromise, a Hawaii business does five things in order: recall any fraudulent wire before it settles, file at ic3.gov to trigger the FBI Financial Fraud Kill Chain, contain the mailbox by revoking sessions and rotating credentials, preserve evidence including inbox rules and mail-forwarding, and notify the cyber insurance carrier. Wire recall success drops fast after 72 hours.
What is business email compromise and why is it a bigger dollar risk than ransomware for a Hawaii SMB?
Business email compromise is fraud that uses a compromised or spoofed email account to trick a business into wiring money to an attacker. The FBI IC3 2025 report logged $3.046 billion in reported U.S. BEC losses across 24,768 complaints — roughly $122,000 average — against $32.3 million in direct ransomware losses. For a Hawaii SMB, BEC is about 94 times the reported dollar exposure.
How do I know if my Microsoft 365 mailbox has been compromised?
The clearest indicators are an inbox rule you did not create that moves messages to RSS Feeds, Deleted Items, or a rarely used folder; mail-forwarding turned on to an external address; sign-in logs from countries you do not travel to; sent items you did not write; and an OAuth application consent you do not recognize in Enterprise Applications. Any one of those is enough to open an incident.
How fast do I need to call the bank to recall a fraudulent wire?
Same hour, ideally same 30 minutes. The FBI IC3 Recovery Asset Team froze $679 million in redirected funds in 2025 with a 58 percent success rate, but that success rate depends on the victim reporting inside the first 24 hours with a complete transaction record. After the funds move to a second bank or off-ramp to cryptocurrency, recall becomes exponentially harder.
Who exactly do I call, and in what order, when a Hawaii business gets hit?
Call the bank's wire fraud desk first and request an immediate wire recall with routing, account, timestamp, and amount ready. File at ic3.gov within the same hour to activate the Financial Fraud Kill Chain. Notify the FBI Honolulu field office directly for local coordination. Call the cyber insurance carrier next; most policies require notice inside 24 to 72 hours. Then engage your managed IT provider for containment.
What Microsoft 365 evidence should I preserve before touching anything?
Before revoking sessions or resetting passwords, export the compromised mailbox using an eDiscovery search or PST export, capture full email headers for the fraudulent thread, snapshot inbox rules and mail-forwarding settings, export the Unified Audit Log for the affected user for the last 90 days, list all OAuth application consents, and list mailbox delegations. Preservation before containment is what makes the FBI report and the insurance claim work.
What Microsoft 365 controls should have prevented this and need to be turned on now?
Phishing-resistant multi-factor authentication on every user account, conditional access blocking sign-ins from outside the United States by default, mail-forwarding to external domains disabled at the tenant level, OAuth application consent restricted to admin approval, DMARC published at reject or quarantine, and a written callback-to-known-number rule before any wire or payment-instruction change is executed. That last one is the highest-return control on the list.
Does a Hawaii business have to report a Microsoft 365 compromise under state law?
Hawaii Chapter 487N requires notification to affected residents without unreasonable delay after a breach of unencrypted personal information, and notice to the Office of Consumer Protection when 1,000 or more Hawaii residents are involved. A Microsoft 365 mailbox holding customer Social Security numbers, driver's license numbers, or financial account numbers is squarely in scope. Consult counsel early to scope the notification window.
Bottom line for Hawaii business owners and controllers
A Microsoft 365 account compromise is a wire fraud incident on a clock. Call the bank fraud desk inside the first hour, file at ic3.gov the same hour, preserve mailbox evidence before you touch the account, contain the mailbox and the tenant in hours 4 to 24, and notify your cyber insurance carrier and outside counsel in hours 24 to 72. On the prevention side, publish a callback-to-known-number rule for every wire and payment-instruction change, today, on one page. That single control does more than any technical stack against a $3 billion problem.