The first hour after discovering a business email account has been compromised determines how much damage the attacker manages to do โ€” acting in the right order matters more than acting fast in the wrong order.

Step 1: Change the Password Immediately, From a Trusted Device

Do this first, before investigating anything else โ€” every minute the attacker retains access is a minute they can do more damage or lock you out entirely. Use a device you're confident is clean, since a compromised password sometimes traces back to malware on the device itself, which would just leak the new password too.

Step 2: Revoke All Active Sessions

Changing the password alone doesn't necessarily end an attacker's already-active login session on most platforms โ€” separately revoke all active sessions/devices (available in every major platform's security settings) to force every existing connection, including the attacker's, to re-authenticate with the new password.

Step 3: Check for a Silently Added Forwarding Rule

A common attacker move is adding a forwarding rule that quietly copies all incoming mail to an external address, allowing continued access to future correspondence (password resets for other accounts, financial information) even after you've changed the password. Check your forwarding and filter settings specifically for any rule you don't recognize, and remove it.

Step 4: Check for New, Unfamiliar Admin or Recovery Settings

An attacker with sufficient access sometimes adds a recovery phone number or backup email under their control, or (on a domain-admin account) creates a new user account for persistent access. Review recovery options and, if this is an admin-level account, the full user list for anything unfamiliar.

Step 5: Enable Two-Factor Authentication If It Wasn't Already On

If the account didn't have 2FA before the compromise, this is the moment to add it โ€” it prevents the same password-based attack vector from working again even if credentials leak a second time.

Step 6: Assess What the Attacker Could See

Review what sensitive information โ€” financial details, client data, other account credentials sent via email in the past โ€” sat in the compromised mailbox's history, since an attacker with access could have read all of it, not just sent new mail.

Step 7: Notify Affected Contacts If Warranted

If the attacker sent phishing or fraudulent messages from your account before you regained control, a brief, direct notice to your real contacts (through a separate, confirmed-secure channel โ€” not the compromised account itself) warning them to disregard any suspicious recent messages limits the attack's spread to your network.

Step 8: Investigate How It Happened

Once immediate containment is done, understanding the actual entry point (a reused leaked password, a successful phishing click, an unpatched device) informs what specifically needs to change to prevent a repeat โ€” treating the incident as a one-off without this step often just delays the next one.

A Short Post-Incident Checklist

  1. Password changed and sessions revoked โ€” done immediately.
  2. Forwarding rules and recovery settings checked for anything unfamiliar.
  3. 2FA enabled if it wasn't already.
  4. Sensitive information in the mailbox history assessed for exposure.
  5. Affected contacts notified through a separate, trusted channel if needed.
  6. Entry point identified and the specific gap closed.

Working through this list in order, rather than jumping straight to "how did this happen," limits damage while the account is still actively at risk.