Business Email Hacked: How to Secure and Recover Your Account Fast
A compromised business email account can cause serious damage in minutes. Here's what to do — fast.
Your colleague received a strange email from your address asking them to click a link. Or a client called to say they got an invoice from you they didn't request. Or you simply can't log in to your own email account anymore. Whatever the sign, one thing is clear: your business email has been compromised.
Every minute counts. Here's what to do — in order.
Signs Your Business Email Has Been Hacked
Before panicking, confirm the compromise. Common indicators include:
- You can't log in — password rejected despite being correct
- Clients or colleagues report strange emails from your address (phishing links, fake invoices, odd requests)
- Unrecognised sent items in your Sent folder
- Password reset emails arriving that you didn't request
- Inbox rules you didn't create — forwarding rules, auto-delete rules, or labels
- Login activity from unknown locations — visible in Microsoft 365 or Google Workspace sign-in logs
Any one of these is enough to treat as a confirmed breach.
Step 1: Change the Password Immediately — From a Different Device
Do not change the password from the same computer or phone you normally use. If that device has malware, the attacker may capture the new password too.
Use a trusted device (a colleague's computer, your personal phone on mobile data, not the office WiFi) to:
- Go to account.microsoft.com (for Microsoft 365) or myaccount.google.com (for Google Workspace)
- Sign in — if you can't, use the account recovery option
- Change the password to something long and unique (at least 16 characters, not used anywhere else)
- Do not reuse any previous password
If you use the same password on other services (banking, CRM, social media), change those too — immediately.
Step 2: Enable Multi-Factor Authentication (MFA)
If MFA wasn't enabled before, enable it now. This is the single most effective protection against account takeover.
For Microsoft 365:
- Go to the Microsoft 365 Admin Center (
admin.microsoft.com) - Users → Active Users → Select the compromised account
- Under Multi-factor authentication, enable it and require re-registration
- Also go to Azure AD → Security → Conditional Access to enforce MFA organisation-wide
For Google Workspace:
- Go to
admin.google.com - Security → 2-Step Verification → Turn on enforcement
With MFA enabled, a stolen password alone is no longer enough to access the account.
Step 3: Check and Remove Malicious Inbox Rules
Attackers frequently create inbox rules to:
- Forward all incoming email to an external address (they get copies of everything)
- Auto-delete email responses that would alert the account owner
- Mark emails as read to hide activity
In Microsoft Outlook Web (OWA):
- Go to outlook.office.com
- Settings → View all Outlook settings → Rules
- Delete any rules you didn't create
In Microsoft 365 Admin Center:
- Go to Exchange Admin Center → Recipients → Mailboxes
- Select the compromised account → Mailbox features → Email forwarding
- Disable any forwarding rules
In Gmail:
- Settings → See all settings → Filters and Blocked Addresses
- Also check Settings → Forwarding and POP/IMAP
Remove anything you didn't set up.
Step 4: Review Login History
Check where and when your account was accessed:
Microsoft 365:
- Go to the Microsoft 365 Admin Center → Users → Select user → Sign-in logs
- Look for logins from unfamiliar countries, IP addresses, or devices
- If you see a login session still active from an attacker, go to Azure AD → Select user → Revoke all sign-in sessions
Google Workspace:
- Admin console → Reports → Audit → Login audit
This tells you the scope: did the attacker just try to log in, or did they have extended access? This affects what notifications you need to send.
Step 5: Check What Was Sent or Accessed
Review the Sent Items folder for the time period the attacker had access. Look for:
- Emails to clients requesting payments to new bank accounts (Business Email Compromise fraud)
- Password reset requests for other services
- Bulk forwards of sensitive documents
- Emails to your contacts with malicious attachments or links
Also review OneDrive or Google Drive for any files that were downloaded or shared during the compromise period.
Step 6: Notify Affected Parties
If the attacker sent emails from your account, you need to warn recipients:
- Send a clear notification from your now-secured account (or a new temporary one)
- Explain that the previous emails were sent by an attacker, not you
- Ask them not to click any links or open attachments from those emails
- If you work in finance: explicitly warn any suppliers or clients who may have received altered payment instructions
This step is uncomfortable but essential. Clients who receive fraudulent payment requests and transfer money will hold you responsible if you don't act promptly.
Step 7: Scan for Malware on All Connected Devices
A compromised email is often symptomatic of a wider infection. After securing the account:
- Run a full malware scan on every device that had access to the email account (antivirus + Malwarebytes)
- Check for keyloggers or remote access tools — these may have been what allowed the initial compromise
- If you use Outlook or an email client, check for suspicious add-ins or extensions
If a device is heavily infected, consider a full rebuild rather than cleanup — it's more reliable.
Step 8: Audit Connected App Permissions
Many accounts have third-party apps connected via OAuth ("Sign in with Google/Microsoft"). These apps may retain access even after you change the password.
Microsoft 365:
- Go to
myapps.microsoft.com→ Edit profile → Manage account → Privacy → Apps and services - Revoke access for any app you don't recognise
Google:
- Go to
myaccount.google.com→ Security → Third-party apps with account access
Remove anything unfamiliar or that you no longer use.
What Happens If You Can't Recover Access?
If the attacker changed the password and you're locked out:
- Use the account recovery process (Microsoft or Google have phone/backup email verification)
- For Microsoft 365: contact your IT admin — they can reset the password and unlock the account from the Admin Center
- If you're the admin and can't get in: contact Microsoft support directly with proof of identity
This is one reason why every Microsoft 365 organisation should have at least two Global Administrators — if one is compromised, the second can recover it.
How Did This Happen? Common Causes
Understanding the entry point helps prevent recurrence:
- Phishing email — you or a staff member clicked a link and entered credentials on a fake login page
- Password reuse — the password was the same as one exposed in a previous data breach (check haveibeenpwned.com)
- Weak password — short or predictable passwords are brute-forced quickly
- No MFA — a stolen password with no second factor is trivial to use
- Compromised device — malware captured credentials
Preventing This from Happening Again
The most effective protections, in order of impact:
- Enable MFA for all accounts — non-negotiable for business email
- Use unique passwords — a password manager makes this practical
- Conduct phishing awareness training — most breaches start with a click
- Keep devices updated and protected — endpoint security matters
- Review connected apps and permissions regularly
- Set up login alerts — Microsoft 365 and Google Workspace can email you on suspicious logins
Vietify Can Help
If your business email was compromised or you're not confident your Microsoft 365 or Google Workspace environment is properly secured, Vietify provides:
- Email account recovery and audit
- Microsoft 365 security hardening (MFA enforcement, Conditional Access)
- Phishing awareness training for staff
- Ongoing security monitoring
Contact us → or start with a free IT assessment to review your current security posture.
Vietify IT Services — Business IT security for companies in Da Nang and Vietnam.
Chia sẻ bài viết
Cần tư vấn IT cho doanh nghiệp?
Vietify IT cung cấp Managed IT từ 4.990.000đ/tháng. Phản hồi trong 30 phút.
Bình luận
Đang tải bình luận…
Để lại bình luận
Cập nhật: 8/8/2026