What to Do After a Business Email Account Is Compromised
A compromised business email account rarely announces itself clearly. It usually shows up as a client asking why an invoice looks different, a colleague mentioning a strange email that appeared to come from you, or a login alert nobody recognizes. Whatever the trigger, the response in the first hour matters more than almost any other part of dealing with the incident.
After a business email account is compromised, immediately reset the password and revoke all active sessions, check for forwarding rules and inbox rules the attacker may have added, review recent sign-in activity, notify anyone who may have received fraudulent messages, and check whether the account had access to financial systems that also need securing. This is general information, not legal advice; notify your insurer and consider legal counsel if client or financial data was involved.
Step one: contain the account immediately
- Reset the password immediately, using a strong, unique password.
- Revoke all active sessions and sign the account out of every device, not just the one in front of you.
- Enable or re-verify multi-factor authentication on the account.
- Disable the account temporarily if you cannot confirm containment quickly.
Check for hidden inbox rules
One of the most common tactics after an email account is compromised is creating a hidden forwarding rule or inbox rule that silently copies messages, particularly anything mentioning invoices, wire transfers, or passwords, to an external address. These rules often stay active even after the password has been changed, so check the mailbox rules specifically rather than assuming a password reset alone solves the problem.
In Microsoft 365, this means reviewing both inbox rules and mail forwarding settings in the admin center, since attackers sometimes configure forwarding at the transport level rather than through a visible inbox rule a user would notice.
Review sign-in activity and connected apps
- Check sign-in logs for locations and devices that do not match the legitimate user's normal pattern.
- Review any third-party applications the account has granted access to, since OAuth consent phishing is a common access method covered in our article on how hackers get into Microsoft 365 accounts.
- Revoke access for any application that was not deliberately and knowingly authorized.
- Check whether any new mail delegation or account permissions were added.
Dealing with a compromised email account right now?
We can help contain the account, check for hidden forwarding rules, and assess the scope of the compromise quickly.
Get Emergency HelpAssess what the attacker could have seen or sent
Once containment is underway, work through what the compromised mailbox actually had access to. This includes past sent and received emails containing sensitive information, contact lists that could now be targeted with follow-up phishing, and any fraudulent emails the attacker may have sent while inside the account, particularly ones asking for payment or banking detail changes.
Notify the people who need to know
- Clients or vendors who may have received a fraudulent email from the compromised account.
- Your bank if any financial instructions were sent or received while the account was compromised.
- Your cyber insurer, if a policy is in place, since many require prompt notification.
- Staff internally, so they know to be alert for follow-up phishing referencing the incident.
Check whether the compromise reached further than email
A compromised email account is frequently the first step, not the whole incident. If the account had access to financial systems, cloud storage, or was used to reset passwords elsewhere, those systems need to be checked as well. Our broader guide on what to do if your business has been hacked covers the wider incident response process beyond a single email account.
Fix the root cause, not just the symptom
Resetting a password addresses the immediate access but not necessarily how the attacker got in. If the root cause was a phishing email that stole a session token, or a lack of multi-factor authentication, or a reused password, that gap needs to be closed for every account in the business, not just the one that was compromised. Our Microsoft 365 security best practices guide covers the tenant-wide settings worth reviewing after any account compromise.
Preventing a repeat
- Enforce phishing-resistant multi-factor authentication on every account, not just the ones that were affected.
- Disable legacy authentication protocols tenant-wide.
- Roll out staff training that specifically covers the tactic used in this incident.
- Review and tighten conditional access policies for sign-in locations and device compliance.
Sources and further reading
Frequently asked questions
How do I know if my business email has been compromised?
Common signs include contacts reporting strange emails from you, sign-in alerts from unfamiliar locations, unexplained inbox rules, or sent items containing messages you never wrote.
Is changing the password enough to fix a compromised account?
Not on its own. Attackers often add forwarding rules, connect third-party apps, or keep sessions active that survive a simple password change, so those also need to be checked and revoked.
Do I need to notify clients if my email was hacked?
If clients may have received fraudulent messages, particularly anything involving payment instructions, notifying them promptly is important both practically and for maintaining trust. Consult legal counsel if sensitive data was exposed.
Should I report this to the police or a government body?
Businesses can report cybercrime incidents through the Canadian Centre for Cyber Security and, depending on the nature and scale of the incident, local police. This is general information, not legal advice.
How do I stop this from happening again?
Enforce multi-factor authentication, disable legacy authentication protocols, and review what specifically allowed the attacker in, whether phishing, a reused password, or a malicious app consent, then close that specific gap.
Joshua Arimoro
Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.
More about our teamNeed help responding to a compromised account?
Our team can contain the incident, assess the scope, and help you close the gap that allowed it to happen.
Technologies mentioned in this article
See what we support around each platform on our supported technologies hub.
Related services, locations, and resources
Related services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- Backing Up Primafact Case Files Properly
Case files in Primafact represent years of litigation work that can't be recreated. Here's what a proper ba…
- PCLaw Support for Ontario Law Firms: The IT Side of Running PCLaw
PCLaw handles billing, trust accounting, and time tracking for many Ontario firms. Here's what keeps it run…
- Protecting PCLaw Trust Accounting Data
Trust accounting data inside PCLaw deserves a distinct layer of protection. General infrastructure guidance…
- What Does a Sophos Firewall Actually Do for a Small Business?
A business-grade firewall does far more than block traffic at the edge. Here is what a device like a Sophos…
