All guides

Guide · Account security

Your business email got hacked. What to do in the first hour.

Move quickly, but do not turn a compromised mailbox into a company-wide guessing game. Stop the attacker, protect the money, preserve the evidence, and find out what else the account could reach.

Reviewed .

The short answer

If a business mailbox may be compromised, work in this order:

  1. If money moved, call the bank first. Use a known phone number, not one from the suspicious message. Ask about a recall or reversal immediately.
  2. Stop new access. Disable or block the affected account if you can do so safely, revoke active sessions, and reset the password from a device you trust.
  3. Remove the attacker’s ways back in. Check MFA methods, forwarding, inbox rules, delegates, recovery information, and connected applications.
  4. Preserve evidence. Keep the messages, headers, timestamps, sign-in records, and payment details. Do not begin by deleting everything suspicious.
  5. Find out what the account touched. Email is often a key to files, contacts, invoices, password resets, and other cloud services.
  6. Warn the right people through another channel. Tell employees, customers, or vendors who may receive fraudulent instructions from the account.

The FBI advises victims of business email compromise involving a transfer to contact the originating financial institution as soon as fraud is recognized and then file a report with the Internet Crime Complaint Center. Speed matters more than making the report perfect.

First: decide whether money is moving

Ask one question before getting lost in technical detail: Did anyone change a bank account, send a wire or ACH payment, buy gift cards, change payroll deposit information, or release goods because of an email?

If yes, call the bank or payment provider immediately. Ask for its fraud or wire department and request a recall, reversal, or hold. Then contact the real vendor, customer, executive, or employee using a phone number you already trust.

Do not reply to the suspicious email to verify it. If the mailbox is compromised, the attacker may be reading the conversation and answering as the person you are trying to reach.

The FBI’s business email compromise guidance makes the same point: contact the financial institution immediately and ask it to contact the institution that received the transfer.

Stop the attacker without losing the trail

Use a different, trusted device and a known-good administrator account if possible. Then:

  • Block or disable sign-in for the affected account while you investigate.
  • Revoke active sessions so a stolen browser session or refresh token cannot stay alive after a password change.
  • Reset the password to a new, unique value that is not a variation of the old one.
  • Review registered MFA methods and remove phone numbers, security keys, authenticator registrations, or recovery addresses you do not recognize.
  • Require MFA before returning the account to ordinary use. Prefer a phishing-resistant security key when practical; an authenticator app with number matching is a useful next choice.
  • Review applications the user has authorized. Remove unfamiliar or unnecessary access grants.

Changing the password alone is not enough. Microsoft’s current compromised-account response guidance includes revoking sessions, reviewing MFA devices and application consent, and investigating mailbox activity because attackers can preserve access in several places.

If the mailbox belongs to the only administrator, the owner, or a service account used by other systems, do not disable it blindly. Get qualified help and plan how to preserve access to the business while containing the account.

Check the places attackers use to hide

An attacker does not need to keep signing in if the mailbox quietly forwards the useful messages elsewhere.

Check for:

  • Inbox rules that forward, redirect, delete, hide, or move messages
  • External forwarding configured outside the visible inbox rules
  • New delegates or permissions on the mailbox
  • Unexpected changes to the display name, signature, reply-to address, or contact details
  • Deleted or archived messages that hide payment conversations
  • New MFA methods, recovery options, or trusted devices
  • Connected applications with permission to read mail or files
  • Changes to shared mailboxes, distribution groups, administrator roles, or password-reset settings

Microsoft lists suspicious forwarding, hidden inbox rules, unfamiliar sent messages, and changed mailbox details among the common signs of compromise. Look beyond the inbox the user normally sees.

Preserve evidence before cleaning everything up

Keep a simple incident log. Record who noticed the problem, when it began, what was changed, who was contacted, and what remains unknown.

Preserve:

  • Original suspicious messages and full message headers
  • Sign-in and audit logs
  • Message-trace results and relevant sent, deleted, junk, archive, and RSS-folder contents
  • Screenshots of malicious rules, forwarding, MFA methods, or application grants before removal
  • Payment instructions, bank confirmations, invoice changes, phone numbers, and account details
  • The names of customers, vendors, or employees who received suspicious messages

Do not forward sensitive evidence through the compromised mailbox. Store it somewhere the suspected attacker cannot reach. CISA explains why useful logging matters in its small-business logging guidance: activity records help establish what happened, when, and from where.

Find the boundary of the incident

The mailbox is not necessarily the whole incident. Ask:

  • Was the same password used anywhere else?
  • Could the account reset passwords for banking, payroll, domain registration, social media, line-of-business software, or other administrators?
  • Did the attacker open or download files from OneDrive, SharePoint, Google Drive, or another connected service?
  • Did the account send phishing messages to other employees or contacts?
  • Did anyone approve an unexpected MFA prompt?
  • Was the user’s computer infected, or were credentials entered into a fake sign-in page?
  • Were confidential, regulated, personnel, tax, health, or financial records exposed?

Review sign-in, audit, and message records without narrowing the search too early. The first suspicious sign-in may not be the first successful access.

If the evidence suggests broader device compromise, administrator access, regulated-data exposure, or continuing attacker activity, bring in an incident-response professional. Your insurer, counsel, regulator, or law-enforcement contact may also need to be involved.

Warn people without spreading confusion

Use a known-clean channel: another mailbox, a phone call, your website, or a message from a separate trusted account.

Keep the warning factual:

  • Identify the affected address.
  • State the time window you know about.
  • Say which requests recipients should distrust, such as payment changes, attachments, password resets, or gift-card requests.
  • Give a known phone number for verification.
  • Ask recipients not to reply to the suspect thread.

Do not claim that no data was exposed until the evidence supports it. “We are investigating” is more honest than reassurance you may have to retract.

What not to do

  • Do not continue the suspicious conversation by email.
  • Do not assume a password change ended every session.
  • Do not delete evidence before recording it.
  • Do not announce a breach more broadly than necessary before you understand the facts—but do not delay warnings that could prevent loss.
  • Do not reconnect a suspect device to sensitive systems merely to see whether the problem returns.
  • Do not wait for a scheduled appointment if money is moving or an active attacker still has access.

After the first hour

The next work is less dramatic and just as important:

  1. Complete the investigation and record the known timeline.
  2. Reset reused credentials and secure connected accounts.
  3. Confirm MFA on email, administrators, remote access, banking, payroll, and other high-impact services. CISA recommends requiring MFA across business systems and using the strongest practical method in its small-business MFA guidance.
  4. Remove unnecessary forwarding, legacy authentication, stale accounts, and excessive privileges.
  5. Review payment-change procedures. Require verification through a known second channel and consider two-person approval.
  6. Decide whether customers, employees, insurers, counsel, regulators, or law enforcement need formal notice.
  7. Write down what would make the next response faster: alternate administrator access, provider contacts, log retention, and a short incident checklist.

Bottom line

Protect the money, cut off access, remove persistence, preserve the evidence, and work outward from the mailbox to everything it could reach.

The first hour does not need to answer every question. It needs to stop the loss without destroying the information required to answer those questions later.