- The first ten minutes after discovering a compromised business email account determine how much damage is contained.
- Here is exactly what to do, in order.
Discovering a compromised business email account is stressful, but the response matters more than the shock. Following the right sequence limits damage and speeds recovery significantly.
Step 1: Contain Immediately
- Change the password immediately from a device you trust is clean.
- Sign out of all active sessions — most platforms offer a "sign out everywhere" option in security settings.
- Enable two-factor authentication if it was not already active.
Step 2: Check for Persistence
Attackers often leave a way back in even after a password change. Check for:
- Unfamiliar forwarding rules silently copying mail to an external address.
- New mailbox rules that auto-delete or hide security alerts.
- Unrecognized connected apps or devices with account access.
- New recovery email addresses or phone numbers added without your knowledge.
Step 3: Assess the Damage
- Review sent mail for anything fraudulent sent during the compromise window.
- Check whether the account was used to reset passwords on other connected services.
- Identify any financial requests sent from the account that contacts may have acted on.
Step 4: Notify Affected Parties
Contact anyone who may have received fraudulent messages from the compromised account, warning them not to act on requests sent during the incident window — especially payment or banking-detail changes.
Step 5: Prevent Recurrence
- Enable 2FA if not already active, on this and every other account.
- Run a malware scan on the device likely used when credentials were captured.
- Review how the compromise likely happened (phishing, reused password, malware) and address that specific gap.
Why Checking for a Hidden Forwarding Rule Is the Step Most Often Skipped
Changing a compromised password feels like the fix, and for many incidents it is — but a sophisticated attacker's first action after gaining access is often to quietly add a mail forwarding rule sending a copy of everything to an external address, specifically so the compromise survives a password reset. This rule sits silently in mailbox settings, invisible unless someone specifically checks, and continues leaking every future email — invoices, client communication, password reset emails from other services — long after the "incident" appears resolved. Making a forwarding-rule check a mandatory, explicit step (not an optional afterthought) in any recovery process closes exactly this gap.
Frequently Asked Questions
Should we involve police or a cybercrime unit?
For fraud involving financial loss or attempts against contacts, filing a report creates a record that helps with any follow-up, including with banks.
How do we know if the attacker still has access?
Check the account's active sessions, forwarding rules and connected apps thoroughly — password change alone does not guarantee removal if persistence mechanisms remain.
Should we suspect other accounts too if one is compromised?
Yes, especially any account sharing the same or a similar password — treat a single compromise as a signal to review credential hygiene across every connected service, not just the account directly affected.
Need help securing a compromised account or preventing future incidents? See our secure email hosting or contact our support team.
Documenting the Incident as You Go
Beyond the technical recovery steps, keeping a simple timestamped record while responding — when the compromise was discovered, what was found in each check, when each remediation step was completed — serves two purposes: it creates the documentation a cybercrime report or insurance claim may later require, and it gives whoever is coordinating the response a clear record to hand off if the incident needs escalation to outside technical help partway through.