This case study details a cyber incident investigation conducted by Avalon for a health service provider regarding a business email compromise (BEC) that led to an unauthorized fund transfer of approximately $300,000. The client discovered fraudulent activity when following up on a payment that had not been received, only to learn that a payment had been made to a newly provided bank account. Avalon was tasked with analyzing suspicious activities within the client’s Microsoft 365 (M365) account and assessing the extent of the compromise. The investigation revealed that an unauthorized third party accessed the employee’s M365 account after the employee fell victim to a phishing attack. This access allowed the third party to manipulate email communications and ultimately facilitated the fraudulent transfer of funds. The findings were crucial for the client to maintain their business relationship and potentially for insurance claims.