If a business email account is compromised, act quickly but do not panic-delete evidence. Block or secure the account, revoke active sessions, reset credentials from a trusted device, review MFA methods, check forwarding and inbox rules, preserve logs, inspect related accounts, and verify any payment or data exposure outside email.
A compromised mailbox can affect invoices, password resets, client conversations, confidential files, and trust. The first goal is containment. The second is understanding what the attacker did. The third is recovery and communication.
First Actions In The First Hour
- Stop using the affected device if malware or remote access is suspected.
- Block sign-in or change the password from a trusted administrator device.
- Revoke active sessions and refresh tokens where available.
- Preserve suspicious emails, screenshots, headers, sign-in logs, and alert details.
- Check and remove unknown MFA methods, app passwords, delegates, and mailbox permissions.
- Look for forwarding, redirect, delete, archive, and mark-as-read rules.
- Pause payment changes until they are verified by phone or another trusted channel.
Do not wipe the mailbox or device before evidence is captured. Cleanup matters, but early deletion can make it harder to understand the incident.
Business Scenario: The Owner Mailbox Is Used For Fraud
An owner’s mailbox sends a request to finance asking for an urgent supplier payment. The message sounds normal because it comes from the real mailbox and references an active project. The finance team hesitates and calls the owner directly. The owner did not send it.
The business blocks the account, revokes sessions, checks sign-ins, finds a new MFA method and an inbox rule hiding replies, then reviews sent mail and message traces. Clients and vendors tied to the suspicious thread are contacted through known phone numbers. Because the team preserved evidence and verified payments outside email, the response is faster and less speculative.
What To Check After The Account Is Secured
Account recovery is not finished when the password changes. Attackers often create persistence. Review the mailbox and tenant for changes that could survive a simple reset.
- Mailbox forwarding and inbox rules.
- Delegated access, shared mailbox permissions, and send-as permissions.
- New MFA methods, recovery details, app passwords, and connected applications.
- Recent sign-ins, device registrations, geographic anomalies, and failed attempts.
- Sent items, deleted items, archive folders, and search results for payment terms.
- Other accounts contacted by the attacker or affected by similar sign-in patterns.
Decide Who Needs To Be Told
Notification decisions depend on what happened. The business may need to contact internal leadership, affected clients, vendors, banks, legal counsel, insurance contacts, or privacy advisors. Do not promise a universal rule. Instead, base decisions on evidence: what mail was accessed, what was sent, whether data was exposed, and whether money movement was attempted.
When clients or vendors are contacted, use known phone numbers or verified contact records. Do not rely on the same compromised email thread to confirm payment details.
Recovery Checklist
- Confirm the affected account is secured and sessions are revoked.
- Remove malicious rules, forwarding, delegates, MFA methods, and connected apps.
- Reset passwords for related systems if password reuse is possible.
- Review administrator accounts and finance accounts for similar activity.
- Check whether invoices, banking details, payroll, or sensitive files were involved.
- Document timeline, actions taken, evidence preserved, and remaining questions.
- Improve MFA, email security, staff reporting, and payment verification after recovery.
Device trust is a key decision. If the user entered a password into a fake page from a clean device, the response may focus on account security. If the device downloaded a file, ran a macro, installed remote access software, or shows suspicious behaviour, isolate the device and inspect it before returning it to work. Do not use a suspect device to reset passwords.
Look beyond the affected mailbox. If the compromised user had access to SharePoint sites, Teams, OneDrive, shared mailboxes, accounting platforms, CRM systems, or password vaults, review those systems for access and activity. Email compromise often becomes a broader identity problem because email resets and approves access elsewhere.
After the immediate response, hold a short lessons-learned review. Identify how the attacker got in, which controls slowed or failed, what staff reported, and what should change. Useful improvements may include stronger MFA, payment verification, mailbox rule alerts, staff training, or tighter admin access.
Communication should be controlled until the facts are known. Avoid sending broad warnings that include speculation or technical details that may change. A short internal instruction can tell staff to pause risky actions, report related messages, and verify payments without claiming more than the evidence supports.
Next Step: Treat The Mailbox As An Incident, Not A Password Reset
Secure the account, preserve evidence, and review persistence before returning to normal work. OnlineV helps businesses respond to mailbox compromise through cybersecurity and Microsoft 365 security support. Useful related pages: cloud management, backup and disaster recovery, and cybersecurity insights.
Sources and further reading
Need Help Reducing Risk?
Separate urgent security gaps from noise
OnlineV can help review MFA, admin access, email risk, devices, backups, and offboarding so the next step is clear and realistic for your business.
Continue Reading