Why the first destination matters
When a Central Florida office suspects fraud, account takeover, malware, or data exposure, the first question is often: who should we call? The answer depends on what happened, whether money moved, whether systems remain available, and whether the business needs technical assistance, law-enforcement reporting, or regulatory advice.
A resource route helps prevent two common mistakes. The first is delaying action while staff search for a perfect explanation. The second is sending sensitive information to an unverified contact that appeared in a suspicious message. Start with official websites typed into the browser or reached through a known internal contact list.
This guide does not replace legal advice, a cyber-insurance requirement, or an organization’s incident-response plan. It is a practical map for owners and office managers.
If money was sent or payment instructions changed
Treat suspected business email compromise as time-sensitive. The FBI describes BEC as a scheme in which criminals impersonate a trusted source or compromise a legitimate business email account to cause an unauthorized transfer or obtain sensitive information.
Immediate actions include:
- Contact the sending financial institution using a trusted number.
- Ask whether a recall or hold can be requested.
- Preserve the email, headers, invoices, payment records, and related messages.
- Do not continue the conversation through the suspicious email thread.
- Report the incident to the FBI’s Internet Crime Complaint Center at https://www.ic3.gov.
The FBI specifically advises businesses to verify changes in account numbers or payment procedures using a separate communication channel. Use a phone number already on file or another independently verified source, not a number included in the suspicious request.
Source: https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise
Source: https://www.ic3.gov/CrimeInfo/BEC
This route is particularly relevant to offices that handle payroll, vendor payments, real-estate transactions, legal settlements, construction draws, or client deposits. The office does not need to determine the attacker’s identity before contacting the bank or filing a report.
If the incident involves a Florida business or suspected cybercrime
The Florida Department of Law Enforcement Cybercrime Office provides statewide information about reporting cybercrime and describes its mission as investigating complex cybercrimes, supporting technical investigations, training investigators, and sharing information with the public.
Businesses can begin at the FDLE Cybercrime Office page:
https://www.fdle.state.fl.us/FCO
FDLE’s common cybercrime guidance identifies phishing, vishing, smishing, malware, social engineering, identity theft, and business email compromise as examples of cybercrime affecting organizations and individuals. The page also points users toward related reporting and prevention resources.
Source: https://www.fdle.state.fl.us/fco/common-cybercrime-complaints-2026
For an immediate physical danger or life-threatening emergency, use 911. A cyber incident involving no physical emergency should still be documented carefully, including dates, affected accounts, known financial losses, and the names of systems or vendors involved.
If suspicious activity needs to be reported
FDLE also maintains a suspicious-activity reporting route. This is different from a technical help desk and should not be treated as a substitute for emergency services. Businesses should read the site’s public-records notice before submitting personal or business information.
Resource: https://sar.fdle.state.fl.us/
The office manager should coordinate internally before submitting a report when possible. Preserve a copy of what was submitted, the confirmation information, and any attachments. If the incident may involve an employee, customer, or patient, avoid broadly forwarding sensitive material while the facts are still being established.
If technical containment is needed
CISA provides small and medium-sized business resources covering MFA, phishing, passwords, software updates, backups, logging, encryption, and incident information sharing.
Resource: https://www.cisa.gov/small-and-medium-sized-business-resources
For a suspected account compromise, the office’s IT provider or managed service provider may need to revoke active sessions, reset credentials, inspect mailbox rules, remove unauthorized forwarding, review administrator changes, and preserve logs. Do not wipe affected devices before deciding whether evidence should be preserved. If ransomware or destructive malware is suspected, disconnecting affected systems from the network may reduce spread, but the office should coordinate with its technical provider before taking actions that could eliminate evidence or disrupt safe restoration.
CISA’s incident-reporting resources can be found at:
https://www.cisa.gov/report
If the office belongs to a regulated or specialized industry
Industry requirements may change the reporting and preservation process. Healthcare organizations may need to evaluate HIPAA obligations. Financial firms may have regulatory, contractual, or customer-notification duties. Defense suppliers may face government-contract requirements. Professional offices may hold attorney-client, patient, tax, or other sensitive information.
Do not assume that filing an IC3 or FDLE report satisfies every notification duty. Ask counsel or the relevant compliance contact to evaluate the facts, affected data, contracts, insurance policy, and jurisdictional requirements.
For defense and aerospace businesses, FloridaCommerce has described the Florida Aerospace and Defense Portal as a resource connecting small and medium-sized businesses with contracting opportunities and cybersecurity training and assessment resources.
Resource: https://floridajobs.org/news-center/DEO-Press/2023/08/08/floridacommerce-announces-launch-of-the-florida-aerospace-and-defense-portal
Availability, eligibility, and program details should be verified directly before relying on a resource.
Build the route before an incident
A useful office resource card should list:
- The bank’s fraud department and relationship contact.
- The IT provider’s emergency number.
- The cyber-insurance carrier and breach-response instructions.
- The owner and incident decision-maker.
- Legal counsel and privacy or compliance contacts.
- IC3, FDLE Cybercrime Office, and CISA reporting links.
- The location of offline backups and current vendor contacts.
Confirmed versus uncertain
Confirmed: FBI, IC3, FDLE, and CISA provide official reporting or guidance routes. Their functions are different, and one report does not automatically replace another.
Uncertain: The appropriate legal notification, investigative response, or technical remedy depends on the specific facts. A public resource page cannot determine whether a particular Central Florida business has met every contractual or regulatory duty.
The best time to verify these routes is before the office needs them. Save the official pages in a secure internal reference, print the essential contact details, and review them during the next continuity exercise.

