954-539-5678Free audit
Menu

Cybersecurity · Incident response

Your business email was hacked. Here is what to do, in order

A step-by-step response for Microsoft 365 and Google Workspace mailboxes, including the hidden rules and connected apps attackers leave behind.

Lock the account and sessions

Hunt for rules and forwarding

Warn contacts by phone

Get your free Technology Health Assessment

30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.

The short answer

If a business email account is hacked, lock the account first: disable it or reset the password from a clean device, then sign the user out of every session, because a password reset alone does not kick out an attacker who already has a session token. Next, remove any unknown MFA methods, delete forwarding and inbox rules the attacker created, revoke suspicious connected apps and check the account’s admin roles.

Then work out what the attacker did: read the sign-in and audit logs, check sent and deleted items, and warn anyone who may have received fake payment requests by phone. If money moved, call your bank immediately and file a complaint at ic3.gov. The steps below follow Microsoft’s and Google’s own guidance for compromised accounts.

Signs the mailbox is compromised

Microsoft’s guidance lists these common symptoms. Any one of them is reason to act.

  • Contacts report odd emails from you, often about invoices, payments or shared documents.
  • Inbox rules you did not create, especially rules that forward mail outside the company or move messages to folders like RSS Subscriptions, Notes or Junk.
  • Strange messages in Sent Items or Deleted Items.
  • The account is blocked from sending because it sent spam.
  • Unexplained password changes, lockouts or MFA prompts you did not trigger.
  • Changed email signatures or contact details.

Step 1: lock the account

  • Disable the account during the investigation if you can. Microsoft calls this the preferred option.
  • If you cannot disable it, reset the password from a different, clean computer. Use a long, unique password and never send it to the user by email, since the attacker may still be reading the mailbox.
  • If the user reused that password anywhere else, change it there too: banking, payroll, vendor portals.
  • Delete app passwords. Microsoft notes they are not revoked automatically when the password changes.

Step 2: kick the attacker out

  • Microsoft 365: revoke all sign-in sessions for the user in the Microsoft Entra admin center (or with the Revoke-MgUserSignInSession command). This invalidates existing tokens.
  • Google Workspace: in the Admin console, reset the user’s password and sign them out of all sessions, then review their 2-Step Verification settings, as Google’s compromised-account guide describes.
  • Remove unknown MFA methods, such as a phone number or authenticator the user does not recognize. Attackers often register their own so they can get back in.
  • Turn on MFA if it was not already enforced. Use an authenticator app or passkey rather than text messages where possible.

Step 3: find what the attacker left behind

This is the step most people miss, and it is why the same mailbox gets used again a week later.

  • Inbox rules. Look for rules that forward, redirect, delete or move messages, especially ones with keywords like invoice, payment, wire or the names of your clients. In Microsoft 365, some rules are hidden from Outlook, so ask your admin to check with PowerShell including hidden rules.
  • Mailbox forwarding. Check for forwarding set at the mailbox level, separate from rules.
  • Delegates. In Gmail and Outlook, check whether another account was given access to the mailbox.
  • Connected apps. Review apps the user granted access to their mail or files and remove anything unfamiliar. Malicious apps keep access even after a password reset.
  • Admin roles. Confirm the account did not gain admin rights, and remove any that are not needed.
  • Other accounts. If the attacker had access to OneDrive or Google Drive, check sharing links created recently.

Want to know whether your email is set up to prevent this? Our free Technology Health Assessment takes about 30 minutes of data collection. The next day you get a plain-language report rating your cybersecurity and IT operations, including email security and MFA coverage, with the next steps in order. It is yours to keep, with no obligation. Book your assessment.

Step 4: work out what happened

  • Sign-in logs: check IP addresses, locations and times, starting a few weeks before anyone noticed. Note the first suspicious sign-in.
  • Sent and deleted items: list every message the attacker sent, and to whom. Attackers often delete replies to hide their tracks.
  • Audit logs: Microsoft’s unified audit log and Google’s admin audit logs show rule creation, file access and other actions. Export them before they age out.
  • Payment conversations: look for threads where bank details were changed or invoices were resent. This is where the real losses happen.

Step 5: warn people the right way

  • Call clients, vendors and staff who received messages from the account. A phone call beats an email that looks just like the attacker’s.
  • Tell them plainly: ignore any request to change bank details or pay a new invoice that came from this address during the affected dates, and confirm any payment by phone using a number you already have.
  • Send a short follow-up email from the secured account once it is clean, so there is a written record.

Step 6: if money or data left the business

  • Call your bank’s fraud line immediately and ask for a recall of any wire or ACH payment. The FBI’s 2025 Internet Crime Report says its Recovery Asset Team helped freeze about 58 percent of the funds in the cases it acted on, and stresses that time is critical.
  • File a complaint at ic3.gov with full transaction details, regardless of the amount.
  • Call your cyber insurer before hiring outside help, since many policies require it.
  • Ask your attorney whether personal data in the mailbox triggers breach notification under state law, HIPAA or a contract. This is general information, not legal advice.

If the hacked account is an admin or the owner’s

A compromised administrator account is more serious than a regular mailbox, because the attacker may have changed settings for the whole company.

  • Check for new user accounts, new admin role assignments and changes to MFA or conditional access policies made during the affected period.
  • Review organization-wide mail flow and forwarding rules, not only the user’s own inbox rules.
  • Look for newly registered applications or consent grants that apply to all users.
  • Rotate passwords for other admin accounts and any service accounts the attacker could have seen.
  • Treat it as a full incident: involve your IT provider and insurer, and preserve the audit logs before making large changes.

The owner’s mailbox is a favorite target for the same reason: staff are used to acting quickly on the owner’s requests. If it was hit, warn your bookkeeper and finance staff first.

Stop it from happening again

  • Enforce MFA for every mailbox, including shared and service accounts.
  • Block automatic forwarding to external addresses by default.
  • Get alerts when new inbox rules or forwarding are created.
  • Limit which apps users can grant access to company data.

Our Microsoft 365 security settings guide walks through these controls. JLB USA’s cybersecurity services include MFA, email security and access reviews for businesses with about 25 to 100 employees.

Book it now

Pick a time for your 30 minutes

Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.

Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.

Questions we hear

Is changing the password enough after an email hack?

No. Attackers may still have active sessions, their own MFA method, inbox rules, forwarding or connected apps. Revoke sessions and remove all of those too.

How do I check for hidden inbox rules in Microsoft 365?

An admin can run Get-InboxRule with the IncludeHidden option in Exchange Online PowerShell. Some malicious rules do not appear in Outlook’s rule list.

Should I tell my clients my email was hacked?

Yes, especially anyone who received messages during the affected period. Call them, and tell them to confirm any payment request by phone using a known number.

What if money was sent because of the hacked email?

Call your bank’s fraud department immediately to request a recall, then file a complaint at ic3.gov. The faster you act, the better the chance funds can be frozen.

Related services

Want to know where your business stands?

Pick a time for my free assessmentCall 954-539-5678