Warn your contacts, your bank, and harden the account

    Anyone the attacker emailed may now be at risk too — use a different channel to warn them.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 1 min read

    BEC isn't a one-off — once your inbox has been used for fraud, you're a known target. Warning contacts on a different channel and adding a phishing-resistant 2FA method are the long-term protection.

    Why a hardware key matters here

    BEC almost always starts with phishing or session-token theft. A hardware key or passkey defeats both — even if they get the password, they can't log in.

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Communications Security