Skip to content
Skip to main content
Email Evidence Investigation walkthrough
Pathway: I have been given a suspicious email

A supplier-payment email has diverted £38,740. What happens next?

A convincing email has caused a business to pay a genuine supplier's invoice into the wrong account. This walkthrough follows the investigation from the original message and lookalike domain to the receiving account, the onward movement of the money and two developing suspects.

You do not need to become an email engineer before starting. At each stage, examine what has been established, decide which line of enquiry follows and use the linked cards when the technical detail becomes useful.

The working principle
Follow what was actually used. The familiar display name is presentation. The useful lines of enquiry lie in the preserved message, sending route, accounts, domain and money movement.
Reported payment
Original email
Sending route
Domain and account
Receiving account
Suspect or suspects
Responsibility

The lines of enquiry can run together. The bank need not wait politely while the email header is being admired.

Scenario note: This is a fictional but realistic training case. Names, organisations, accounts and returns are invented. The domains and IP addresses are reserved examples.

The case begins

Initial report
Reported conductSupplier-payment diversion
Amount£38,740
DiscoverySupplier reports invoice unpaid

Hartwell Fabrication regularly buys components from Ridgeway Components. Hartwell's finance officer receives an email in an existing invoice conversation saying that Ridgeway has changed bank accounts. The officer pays invoice RC-10482 using the replacement details.

The following morning Ridgeway asks why the invoice remains unpaid. Hartwell checks the payment and reports the matter. The money and the email now create separate but connected lines of enquiry.

Payment change - invoice RC-1048216 June 2026 · 16:42
FromMartin Cole - Ridgeway Components <accounts@ridgeway-componants.example>
ToAccounts Payable <payments@hartwell.example>
Reply-Toridgeway.payments@postbox.example

Hi Jamie,

We have moved our invoice account. Please use the replacement details on the attached notice for invoice RC-10482 and future payments.

Martin
Accounts Manager
Ridgeway Components

The display name looks familiar. The address underneath it contains componants, not components. One letter has done a surprising amount of work.

Follow the investigation

01 · Protect the money and preserve the evidence

The payment has left Hartwell, but the receiving bank may still be able to restrict, trace or recover some of it.

The immediate financial action is to notify the relevant financial institutions through the available fraud process, identify the payment precisely and seek appropriate restriction, recall or tracing action. Record who was contacted, when, the reference given and what happened next.

At the same time, preserve the original email, its complete header, attachment, underlying links and mailbox context. Do not reduce the evidence to the screenshot somebody helpfully pasted into a report.

Payment time17 Jun 2026
09:24 UTC
Amount£38,740
Payment referenceRC-10482
Receiving referencePAY-77421

  • Email: preserve the native message and full header.
  • Mailbox: retain the surrounding thread, rules and relevant audit material.
  • Attachment: keep the replacement-bank notice in its original relationship to the message.
  • Payment: retain the instruction, authorisation, transaction record and receiving details.
  • Witness account: establish what the finance officer saw, checked and did.
  • Business records: preserve the genuine invoice and earlier supplier correspondence for comparison.

Investigator action
Start the financial and email enquiries together. Speed matters to the money; completeness matters to the evidence.

EstablishedHartwell sent £38,740 to replacement details supplied in an email presented as coming from Ridgeway.
Still openWhether Ridgeway sent it, who controlled the sending infrastructure and who received or moved the money.

02 · Establish what the email actually represents

The message imitates Ridgeway, but its underlying addresses do not use Ridgeway's genuine domain.

The visible name, Martin Cole - Ridgeway Components, is what the recipient was invited to believe. The underlying From address is accounts@ridgeway-componants.example; Ridgeway's genuine domain is ridgeway-components.example.

The Reply-To address points somewhere else again: ridgeway.payments@postbox.example. That matters because a reply would leave the apparent supplier conversation and go to an account controlled elsewhere.

Genuine supplierridgeway-components.exampleUsed in established invoices and independently confirmed by Ridgeway.
Domain used in the emailridgeway-componants.exampleThe spelling is different even though the display name looks right.

The suspicious email appears beneath genuine messages about invoice RC-10482. That could mean the fraudster copied the subject and quoted text, obtained an earlier email, or gained access to one of the mailboxes. A familiar-looking thread does not prove that every message in it travelled through the same accounts.

Investigator action
Compare the message identifiers and delivery headers of the genuine and suspicious messages. Establish whether the conversation is technically continuous or merely made to look continuous.

EstablishedThe payment-change message presented Ridgeway's identity but used a lookalike domain and unrelated reply route.
Still openHow the sender obtained the genuine invoice details and who controlled the lookalike domain and mailbox.

03 · Read the delivery and authentication records correctly

The message authenticated successfully - but for the fraudster's lookalike domain, not for Ridgeway.

Hartwell's preserved message includes the following excerpt:

Selected email-header fields
From: accounts@ridgeway-componants.exampleReply-To: ridgeway.payments@postbox.exampleReturn-Path: bounce@ridgeway-componants.exampleMessage-ID: <20260616.164218.8472@ridgeway-componants.example>Received: from mail.ridgeway-componants.example (203.0.113.84)Authentication-Results: spf=pass; dkim=pass; dmarc=pass
From identity presentedReceived recorded routeAuthentication domain checks

SPF, DKIM and DMARC have not failed. They show that the message used an authorised or aligned route for ridgeway-componants.example. They do not turn that lookalike into Ridgeway's genuine domain, and they do not identify the person at the keyboard.

Put simply: the authentication controls are doing their job. They are authenticating the wrong domain perfectly well.

A message trace from Hartwell's provider confirms receipt from 203.0.113.84 at 16:42:19 UTC. This gives the investigation a sending service, time and message identifier that can be used in the next provider enquiry.

EstablishedHartwell's provider received the message through infrastructure authorised for the lookalike domain.
Still openWhich service account submitted it and which person controlled that account or infrastructure.

04 · Follow the domain and sending account

Registration and provider returns connect the lookalike domain and mailbox to details associated with Ellis Ward.

A domain-registration lookup shows that ridgeway-componants.example was registered nine days before the email. Public details are privacy-protected, but the registrar and email-service provider are identifiable. Defined enquiries are made using the domain, mailbox, message identifier, sending IP address and exact time.

Provider and registrar return
Domain created7 Jun 2026, 11:08 UTC
Service accountSA-882041
Recovery emailellis.ward@postbox.example
Recovery mobileEnding 6142
Domain paymentCard ending 9031
Submission event16 Jun 2026, 16:42:18 UTC
The providers associate these details with the service accounts. The return does not by itself establish who supplied, possessed or used each detail.

Subscriber and financial records associate the recovery mobile and payment card with Ellis Ward. That makes Ellis a person of interest in the infrastructure line of enquiry. It does not yet prove Ellis personally registered the domain or sent the message; account details can be shared, misused or supplied by somebody else.

The account was accessed from more than one network, but the same browser identifier appears during domain setup, mailbox configuration and message submission. That continuity is more useful than treating a current IP lookup as a person's name.

Investigator action
Build the infrastructure timeline around the registration, account setup and sending event. Preserve the provider's audit records and identify what could connect the recurring browser or account activity to a device.

What the evidence suggestsAccounts associated with Ellis's contact and payment details were used to create and operate the lookalike sending arrangement.
What still requires proofWhether Ellis controlled the relevant browser, account and message submission - and whether anybody acted with Ellis.

05 · Follow the receiving account and onward money

Hartwell's payment entered an account in Sam Dyer's name and most of it moved to an exchange account associated with Ellis Ward.

The receiving institution preserves and supplies the account-opening, access and transaction records available through the appropriate process:

09:24Hartwell pays£38,740 sent with reference RC-10482.
09:26Receiving accountFunds credited to Greenway Trade Solutions, held by Sam Dyer.
09:51Onward transfer£34,000 sent to exchange customer AC-88214.
10:07Further movementDigital assets withdrawn from the exchange account.

The receiving account was opened eighteen days earlier using identity material and a live image associated with Sam Dyer. The same registered handset identifier appears during account opening, beneficiary creation and approval of the £34,000 onward transfer.

The exchange return identifies customer AC-88214 as an account verified in Ellis Ward's name. It records receipt of the £34,000 and a later withdrawal using that account.

Sam is now a suspect in the receiving-account line of enquiry. Ellis is a suspect in both the infrastructure and onward-money lines. Those are evidence-based investigative positions, not final conclusions about knowledge, agreement or responsibility.

EstablishedThe diverted payment reached Sam's account; most of it then moved to an exchange account in Ellis's name.
Still openWho actually controlled each account and device, what Sam and Ellis knew, and who ultimately controlled the withdrawn assets.

Investigator action
Keep the account holder, account user and person responsible as separate propositions. Obtain the access records and device identifiers that allow each proposition to be tested.

06 · Test whether the email and money lines converge

Independent records now place Ellis in both lines of enquiry and associate Sam with the account that received and moved the payment.

Registrar · 7 JuneThe lookalike domain is created through the service account associated with Ellis's recovery and payment details.
Mailbox provider · 16 JuneThe fake supplier mailbox submits the payment-change email; the recurring browser identifier matches the setup activity.
Hartwell · 17 JuneThe finance officer authorises £38,740 to the replacement account.
Receiving account · 17 JuneSam's registered handset approves the onward transfer twenty-seven minutes after receipt.
Exchange · 17 JuneEllis's verified exchange account receives £34,000 and later records a withdrawal.
Witness and account contextFurther enquiries establish that Sam and Ellis know one another and were in regular contact during the relevant period.

The recurring appearance of Ellis-associated details is not one magical identifier that solves the case. Its value comes from independent providers recording Ellis in the creation of the sending arrangement and the receipt of the onward money.

Sam's position also requires testing. A bank account in Sam's name is not automatically a confession, but the account-opening image, continuing handset identifier and rapid onward transfer require an explanation.

Combined evidential positionEllis is connected to the lookalike infrastructure and onward exchange account. Sam is connected to the receiving account and movement of the diverted funds. Their relationship provides a further line of enquiry.
Still to testThe devices used, control of the accounts, source of the genuine invoice information, communications between them, knowledge, intent and any other participants.

07 · Plan the next operational action around the suspects

The investigation has reached two suspects and a defined set of questions that further enquiries, interview and device evidence can answer.

The next operational steps should test the case built so far rather than merely collect more digital material because it exists.

  • Which device created or administered the lookalike domain and mailbox?
  • Which device submitted the payment-change email?
  • How were the genuine invoice number, amount and conversation obtained?
  • Who controlled Sam's receiving account and registered handset?
  • Who controlled Ellis's exchange account and the withdrawn assets?
  • What communications passed between Sam and Ellis before and after the payment?
  • Were other lookalike domains, messages, receiving accounts or victims involved?
  • Is there an innocent or different explanation for any of the account activity?

Depending on the evidence and applicable process, further action may include interviews, searches, device seizure or examination, additional provider returns and financial tracing. The operational plan should identify the accounts, devices, dates, records and questions already known so that the next team is not handed a vague request to “check the phones for emails”.

Operational focus
Test account control, communications, access to the genuine invoice and movement of the proceeds. Look for evidence that confirms the developing case and evidence that provides another explanation.

Finding the email on a device associated with Ellis, or banking access on a device associated with Sam, would be important. It would still need to be interpreted alongside possession, timing, account activity and the wider evidence.

What the investigation has established

Original emailA payment-change message used Ridgeway's identity but a lookalike domain and separate reply route.
Sending arrangementProvider records associate the domain and mailbox with contact and payment details linked to Ellis Ward.
Receiving accountHartwell's £38,740 reached an account in Sam Dyer's name and was rapidly moved using its registered handset.
Onward money£34,000 reached an exchange account verified in Ellis Ward's name.
Still to proveDevice and account control, how the invoice data was obtained, each suspect's knowledge and intent, responsibility and any other participants.

The email moved the investigation because it exposed the infrastructure and accounts actually used. The financial records then provided an independent route to Sam and back to Ellis. Neither line carries the whole case on its own; together they justify treating both as suspects and asking much better questions.

Operational takeaway
Follow the message, the accounts and the money until the lines of enquiry meet. Preserve the original email, distinguish the displayed identity from the sending route, identify who controlled the lookalike infrastructure, trace the diverted payment and test the developing suspects against devices, communications and wider evidence.

If the evidence points somewhere else

This case follows a lookalike domain and two identifiable financial accounts. A different result changes the next line of enquiry:

Reference: EML-046Email Evidence