Cybersecurity · Incident response
A step-by-step response for Microsoft 365 and Google Workspace mailboxes, including the hidden rules and connected apps attackers leave behind.
Lock the account and sessions
Hunt for rules and forwarding
Warn contacts by phone
30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.
If a business email account is hacked, lock the account first: disable it or reset the password from a clean device, then sign the user out of every session, because a password reset alone does not kick out an attacker who already has a session token. Next, remove any unknown MFA methods, delete forwarding and inbox rules the attacker created, revoke suspicious connected apps and check the account’s admin roles.
Then work out what the attacker did: read the sign-in and audit logs, check sent and deleted items, and warn anyone who may have received fake payment requests by phone. If money moved, call your bank immediately and file a complaint at ic3.gov. The steps below follow Microsoft’s and Google’s own guidance for compromised accounts.
Microsoft’s guidance lists these common symptoms. Any one of them is reason to act.
This is the step most people miss, and it is why the same mailbox gets used again a week later.
Want to know whether your email is set up to prevent this? Our free Technology Health Assessment takes about 30 minutes of data collection. The next day you get a plain-language report rating your cybersecurity and IT operations, including email security and MFA coverage, with the next steps in order. It is yours to keep, with no obligation. Book your assessment.
A compromised administrator account is more serious than a regular mailbox, because the attacker may have changed settings for the whole company.
The owner’s mailbox is a favorite target for the same reason: staff are used to acting quickly on the owner’s requests. If it was hit, warn your bookkeeper and finance staff first.
Our Microsoft 365 security settings guide walks through these controls. JLB USA’s cybersecurity services include MFA, email security and access reviews for businesses with about 25 to 100 employees.
Book it now
Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.
Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.
No. Attackers may still have active sessions, their own MFA method, inbox rules, forwarding or connected apps. Revoke sessions and remove all of those too.
An admin can run Get-InboxRule with the IncludeHidden option in Exchange Online PowerShell. Some malicious rules do not appear in Outlook’s rule list.
Yes, especially anyone who received messages during the affected period. Call them, and tell them to confirm any payment request by phone using a known number.
Call your bank’s fraud department immediately to request a recall, then file a complaint at ic3.gov. The faster you act, the better the chance funds can be frozen.