- The first ten minutes after discovering a compromised business email account determine how much damage is contained.
- Here is exactly what to do, in order.
Discovering a compromised business email account is stressful, but the response matters more than the shock. Following the right sequence limits damage and speeds recovery significantly.
Step 1: Contain Immediately
- Change the password immediately from a device you trust is clean.
- Sign out of all active sessions โ most platforms offer a "sign out everywhere" option in security settings.
- Enable two-factor authentication if it was not already active.
Step 2: Check for Persistence
Attackers often leave a way back in even after a password change. Check for:
- Unfamiliar forwarding rules silently copying mail to an external address.
- New mailbox rules that auto-delete or hide security alerts.
- Unrecognized connected apps or devices with account access.
- New recovery email addresses or phone numbers added without your knowledge.
Step 3: Assess the Damage
- Review sent mail for anything fraudulent sent during the compromise window.
- Check whether the account was used to reset passwords on other connected services.
- Identify any financial requests sent from the account that contacts may have acted on.
Step 4: Notify Affected Parties
Contact anyone who may have received fraudulent messages from the compromised account, warning them not to act on requests sent during the incident window โ especially payment or banking-detail changes.
Step 5: Prevent Recurrence
- Enable 2FA if not already active, on this and every other account.
- Run a malware scan on the device likely used when credentials were captured.
- Review how the compromise likely happened (phishing, reused password, malware) and address that specific gap.
Frequently Asked Questions
Should we involve police or a cybercrime unit?
For fraud involving financial loss or attempts against contacts, filing a report creates a record that helps with any follow-up, including with banks.
How do we know if the attacker still has access?
Check the account's active sessions, forwarding rules and connected apps thoroughly โ password change alone does not guarantee removal if persistence mechanisms remain.
Need help securing a compromised account or preventing future incidents? See our secure email hosting or contact our support team.