This blog was written by Ronnie Tokazowski, CTO at Rexxfield and part time, Chief Fraud Fighter at Intelligence for Good to demonstrate what a Business Email Compromise (BEC) investigation looks like using Maltego Graph.
Commercial fraud and data breach investigations often begin after financial losses have already occurred, with the goal of understanding how the incident unfolded within the organization’s systems.
In a recent case, an enterprise construction and property-services company contacted the team after its bank flagged a fraudulent payment. The investigation revealed that an attacker had quietly maintained access to the company controller’s email account for several weeks. More significantly, two separate impersonation campaigns had been operating against the company at the same time. Initially, neither the client nor the investigators realized that the two campaigns were connected.
Investigating a Compromised Mailbox 🔗︎
The team had several sources of evidence available, including Google Workspace security logs, a complete mailbox export, and message-log data covering five domains. This provided a large volume of timestamps, senders, IP addresses, domains, and email events, but no obvious way to understand how all the pieces related to one another.
Rather than examining each log sequentially, the investigation team used Maltego to rebuild the case as a connected graph. The compromised mailbox, two flagged sign-in events, genuine and lookalike domains, fraudulent bank accounts, and the payment threads associated with each campaign were mapped as linked Entities.
The team then anchored the investigation around the first confirmed unauthorized access, setting this event as T=0. Every subsequent event was dated relative to this point, for example T+30, T+37, and T+44. This helped transform a collection of individual log entries into a network that investigators could navigate and analyze.
The team could begin asking more useful questions: Who was the compromised mailbox communicating with? Which contacts and domains were legitimate? When did suspicious Entities first appear? And how were different conversations and events connected?
Connecting Two Fraud Campaigns 🔗︎
Once the evidence was visualized in Maltego Graph, the structure of the attack became much clearer.
- At T=0, a sign-in from a network the account had never previously used triggered an alert, but still successfully cleared the account’s two-factor authentication device-approval prompt. At T+30, a second sign-in followed the same pattern.
- At T+37, the controller sent a legitimate dividend-distribution email. Within three hours, a homoglyph lookalike domain appeared and hijacked the thread, creating a parallel fraudulent version of the same conversation.
- At T+44, another campaign appeared.
A one-letter lookalike of the company’s legitimate materials vendor hijacked an active invoice thread the morning after the genuine estimate arrived. The attacker then introduced the first of three fraudulent bank-account instructions. When viewed simply as separate email conversations, the incidents appeared to be two independent impersonation campaigns.
Mapping the evidence in Maltego Graph revealed something different**: both campaigns were connected through the same compromised mailbox.**
What the Maltego Graph Revealed 🔗︎
One of the investigation’s most valuable findings did not come directly from the fraudulent emails. Instead, it came from the account’s blocked-sender list.
In the days following the appearance of the first impersonation domains, someone with access to the account blocked four genuine contacts: the real advisor, the real executive coach, a legitimate professional contact, and the real vendor.
Every one of these blocking actions originated from the same previously unrecognized network. At the same time, the lookalike domains impersonating these contacts were never blocked and continued reaching the controller’s inbox for several weeks.
Viewed individually, these actions appeared as scattered log entries across approximately two weeks. Mapped together, however, they revealed a clear pattern: someone appeared to be actively controlling which voices could reach the controller, blocking genuine contacts while allowing their fraudulent counterparts to remain active.
This provided investigators with a much clearer picture of how the attacker was attempting to manipulate communications inside the compromised mailbox.
Identifying the Domains That Never Spoke 🔗︎
The investigation also surfaced two lookalike domains that had not initially attracted attention. Neither domain had sent the controller a single message. Instead, they appeared as silent recipients copied into fraudulent email threads, allowing them to passively receive outgoing communications without participating directly in the conversation.
This suggested that the domains were serving a different role within the attack infrastructure. Rather than being used directly for impersonation, they appeared to function as observation points through which communications could be monitored.
Mapping these relationships allowed the investigators to distinguish between entities actively participating in conversations and those simply collecting information. The discovery demonstrates the value of looking beyond individual messages and examining the broader network around an investigation: who is communicating, who is receiving information, and what role does each entity appear to play?
Beyond Two-Factor Authentication 🔗︎
The investigation also highlighted an important security consideration. Both suspicious sign-ins successfully cleared the account’s two-factor authentication prompt. While two-factor authentication remains an important security measure, standard push- and SMS-based methods can still be targeted through phishing and social-engineering techniques.
Hardware security keys and passkeys provide stronger phishing resistance because authentication is linked to the legitimate domain rather than relying solely on a user approving a request or entering a code.
For organizations handling sensitive financial processes, particularly finance teams and accounts-payable mailboxes, strengthening authentication controls can therefore be an important additional layer of protection.
Following the Money 🔗︎
The disputed six-figure payment ultimately left the company’s account and reached one of the fraudulent accounts identified during the investigation.
At the time this content was written, Investigators was continuing to work with the client and its bank to trace and recover the funds. Early indications suggested that recovery could be successful, although banking timelines and recovery processes can be unpredictable.
A separate payment-redirection attempt connected to a smaller invoice had a different outcome. In that instance, the bank identified the fraud before the payment was completed, preventing any financial loss.
From Individual Events to a Connected Investigation 🔗︎
None of the individual pieces of evidence in this investigation were unusual on their own. They included timestamps, IP addresses, email addresses, domain information, sign-in events, blocked-sender actions, and bank-account details.
The value came from examining those pieces as a network rather than as a list. By anchoring events around a common point in time and mapping the relationships between Entities in Maltego Graph, the investigation team was able to uncover patterns that would have been far more difficult to identify in raw logs alone.
This approach reflects one of the broader principles of OSINT and link analysis: investigators are rarely interested only in individual pieces of information. They also need to understand how those pieces connect, when those relationships emerged, and what those connections reveal about the wider investigation.
Through the Maltego Grants Program, investigators, researchers, educators, NGOs, and trainers are putting investigative technology into practice where it can make a real difference. From uncovering complex fraud networks to connecting relationships across fragmented datasets, the community is turning digital evidence into meaningful insights that support research, education, and real-world investigations.
About the Author 🔗︎
Ronnie Tokazowski is a cybersecurity researcher with more than 15 years of experience in threat intelligence, scam analysis, and fraud prevention. His work focuses on business email compromise, romance scams, and pig-butchering fraud, and he works with law-enforcement agencies and financial institutions on attribution and asset recovery.

