Discovering a compromised business email account is stressful, but the response matters more than the shock. Following the right sequence limits damage and speeds recovery significantly.

Step 1: Contain Immediately

  • Change the password immediately from a device you trust is clean.
  • Sign out of all active sessions โ€” most platforms offer a "sign out everywhere" option in security settings.
  • Enable two-factor authentication if it was not already active.

Step 2: Check for Persistence

Attackers often leave a way back in even after a password change. Check for:

  • Unfamiliar forwarding rules silently copying mail to an external address.
  • New mailbox rules that auto-delete or hide security alerts.
  • Unrecognized connected apps or devices with account access.
  • New recovery email addresses or phone numbers added without your knowledge.

Step 3: Assess the Damage

  • Review sent mail for anything fraudulent sent during the compromise window.
  • Check whether the account was used to reset passwords on other connected services.
  • Identify any financial requests sent from the account that contacts may have acted on.

Step 4: Notify Affected Parties

Contact anyone who may have received fraudulent messages from the compromised account, warning them not to act on requests sent during the incident window โ€” especially payment or banking-detail changes.

Step 5: Prevent Recurrence

  1. Enable 2FA if not already active, on this and every other account.
  2. Run a malware scan on the device likely used when credentials were captured.
  3. Review how the compromise likely happened (phishing, reused password, malware) and address that specific gap.

Frequently Asked Questions

Should we involve police or a cybercrime unit?

For fraud involving financial loss or attempts against contacts, filing a report creates a record that helps with any follow-up, including with banks.

How do we know if the attacker still has access?

Check the account's active sessions, forwarding rules and connected apps thoroughly โ€” password change alone does not guarantee removal if persistence mechanisms remain.

Need help securing a compromised account or preventing future incidents? See our secure email hosting or contact our support team.