Business Email Compromises (BEC) continue to plague organizations world-wide, inflicting catastrophic, financial damages. This presentation will be live demo of an actual BEC using the same TTP’s criminal organizations are currently employing to attack their victims. We will dissected each step of the scheme and learn how to identify pre-attack signatures to help detect and defend against an imminent attack. We will explore several tools and methods to conduct incident response to identify the attacker and his/her actions on your system. Of interest, we will explore the previously undocumented Office365 Activities API to access once-undisclosed logs that are incredibly detailed and helpful when conducting BEC incident response. Lastly, we will discuss tips and best practices when coordinating with law enforcement.