Discovering a compromised business email account is stressful, but the response matters more than the shock. Following the right sequence limits damage and speeds recovery significantly.

Step 1: Contain Immediately

  • Change the password immediately from a device you trust is clean.
  • Sign out of all active sessions — most platforms offer a "sign out everywhere" option in security settings.
  • Enable two-factor authentication if it was not already active.

Step 2: Check for Persistence

Attackers often leave a way back in even after a password change. Check for:

  • Unfamiliar forwarding rules silently copying mail to an external address.
  • New mailbox rules that auto-delete or hide security alerts.
  • Unrecognized connected apps or devices with account access.
  • New recovery email addresses or phone numbers added without your knowledge.

Step 3: Assess the Damage

  • Review sent mail for anything fraudulent sent during the compromise window.
  • Check whether the account was used to reset passwords on other connected services.
  • Identify any financial requests sent from the account that contacts may have acted on.

Step 4: Notify Affected Parties

Contact anyone who may have received fraudulent messages from the compromised account, warning them not to act on requests sent during the incident window — especially payment or banking-detail changes.

Step 5: Prevent Recurrence

  1. Enable 2FA if not already active, on this and every other account.
  2. Run a malware scan on the device likely used when credentials were captured.
  3. Review how the compromise likely happened (phishing, reused password, malware) and address that specific gap.

Why Checking for a Hidden Forwarding Rule Is the Step Most Often Skipped

Changing a compromised password feels like the fix, and for many incidents it is — but a sophisticated attacker's first action after gaining access is often to quietly add a mail forwarding rule sending a copy of everything to an external address, specifically so the compromise survives a password reset. This rule sits silently in mailbox settings, invisible unless someone specifically checks, and continues leaking every future email — invoices, client communication, password reset emails from other services — long after the "incident" appears resolved. Making a forwarding-rule check a mandatory, explicit step (not an optional afterthought) in any recovery process closes exactly this gap.

Frequently Asked Questions

Should we involve police or a cybercrime unit?

For fraud involving financial loss or attempts against contacts, filing a report creates a record that helps with any follow-up, including with banks.

How do we know if the attacker still has access?

Check the account's active sessions, forwarding rules and connected apps thoroughly — password change alone does not guarantee removal if persistence mechanisms remain.

Should we suspect other accounts too if one is compromised?

Yes, especially any account sharing the same or a similar password — treat a single compromise as a signal to review credential hygiene across every connected service, not just the account directly affected.

Need help securing a compromised account or preventing future incidents? See our secure email hosting or contact our support team.

Documenting the Incident as You Go

Beyond the technical recovery steps, keeping a simple timestamped record while responding — when the compromise was discovered, what was found in each check, when each remediation step was completed — serves two purposes: it creates the documentation a cybercrime report or insurance claim may later require, and it gives whoever is coordinating the response a clear record to hand off if the incident needs escalation to outside technical help partway through.