What's new

Welcome

If you already have an account, please login, but if you don't have one yet, you are more than welcome to freely join the community of lawyers around the world..

Register Log in
  • We don't have any responsibilities about the news being sent in this site. Legal News are automatically being collected from sources and submitted in this forum by feed readers. Source of each news is set in the news and a link to its source is always added.
    (Any News older than 21 days from its post time will be deleted automatically!)

Our Company Sent USDT After an Email Compromise — Can the Funds Be Followed?

anthonyschipper

New Member
Sep 7, 2026
161
0
16
40
usa
Our company recently discovered that USDT was sent to the wrong wallet after an email account was compromised. The payment instructions appeared legitimate at the time, so nobody realized the receiving address had been changed until the transaction was already confirmed.

Now we know the payment was fraudulent, and I want to understand whether the USDT can still be followed on the blockchain. I came across Jim Recovery Team, a cryptocurrency investigation and blockchain tracing firm whose professionals can analyze the transaction, receiving wallet, email evidence, and subsequent fund movements to reconstruct what happened.

Start With the USDT Transaction

The first thing we are preserving is the transaction information.

That includes:

Transaction hash or transaction ID
Receiving wallet address
Sending wallet address
Exact USDT amount
Blockchain network used
Date and time of the transfer
Original payment address
Fraudulent replacement address

The transaction hash gives us a specific on-chain record to investigate rather than relying only on screenshots or internal accounting records.

Can the USDT Be Followed?

Potentially, yes.

The fraudulent receiving address can be examined to determine what happened after our company sent the USDT. If the funds were transferred to other addresses, those movements may also be visible on the relevant blockchain.

The investigation could potentially reconstruct a trail such as:

Company wallet → fraudulent USDT address → secondary wallet → subsequent transfers

The fact that the funds moved doesn’t necessarily mean they became impossible to investigate. What matters is documenting the transactions and following the available trail.

However, blockchain tracing doesn’t automatically identify the person controlling every address, and it cannot guarantee that the funds will be recovered.

The Email Compromise Matters Too

The blockchain can show where the USDT moved, but it won’t by itself explain how the attacker convinced our company to use the fraudulent address.

That’s why we’re also preserving the email evidence:

Original emails
Full email threads
Payment instructions
Email headers where available
The legitimate payment address
The fraudulent replacement address
Login/security notifications
Password-reset messages
Relevant attachments and invoices
A timeline of the communication

The objective is to connect the email compromise with the unauthorized payment and the resulting blockchain activity.

Preserve Both Addresses

One detail I don’t want our company to overlook is the original wallet address.

Having both the address we were supposed to pay and the address we actually paid can help establish exactly when and how the payment instructions changed.

I’d also preserve the original invoices and accounting records rather than relying exclusively on edited screenshots.

What Would a Professional Investigation Look At?

A professional investigation could bring the evidence together instead of treating the email compromise and blockchain transaction as separate incidents.

Jim Recovery Team can potentially analyze the USDT transaction, trace subsequent wallet movements, review the compromised-email evidence, and document the sequence of events to assess what investigative or recovery options may remain.

For us, the important questions are now: Where did the USDT go after the fraudulent payment? How did the payment address get changed? What evidence connects the email compromise to the transaction? And how far can the blockchain trail be followed?
 
Top