The first calls to make
Call your bank right away and ask it to attempt a recall of any wire and to notify the receiving bank, since recovery chances fall quickly with time. Business accounts generally fall outside consumer protection rules, so the bank agreement and commercial law will shape who bears the loss. File a report with the FBI's Internet Crime Complaint Center, which can sometimes help with freezing funds in cooperation with banks. Notify your cyber or crime insurer promptly, because many policies require early notice and approval before you hire certain vendors. If client or customer data may have been exposed, notification duties may also apply, and their timelines can run before the investigation is finished.
Containing systems without losing evidence
Disconnect affected machines from the network rather than shutting them off, so that memory and logs can still be examined. Reset credentials for compromised accounts and turn on stronger sign-in protections, while keeping a record of what was changed and when. Preserve email headers, server and login logs, payment records, and the message thread that led to the transfer. If a forensic firm is brought in, having counsel retain it may help protect parts of its work, though that depends on how the engagement is structured and its purpose. Avoid discussing the incident in widely shared channels until the scope is understood.
Who carries the loss
Once the immediate response is underway, the question becomes who bears the cost. That can involve the bank, the insurer, a vendor whose email was compromised, or an employee who followed procedure. In a first conversation we review the payment instructions, the bank's security procedures and whether they were followed, and your insurance coverage. We also look at contracts with vendors and customers that may assign risk for this kind of event. Some losses can be shifted or recovered, and some cannot, and knowing which early prevents wasted effort.