Business Email Hacked: How to Secure and Recover Your Account Fast
Tất cả bài viết

Business Email Hacked: How to Secure and Recover Your Account Fast

Vietify IT Team7 phút đọc

A compromised business email account can cause serious damage in minutes. Here's what to do — fast.

Your colleague received a strange email from your address asking them to click a link. Or a client called to say they got an invoice from you they didn't request. Or you simply can't log in to your own email account anymore. Whatever the sign, one thing is clear: your business email has been compromised.

Every minute counts. Here's what to do — in order.

Signs Your Business Email Has Been Hacked

Before panicking, confirm the compromise. Common indicators include:

  • You can't log in — password rejected despite being correct
  • Clients or colleagues report strange emails from your address (phishing links, fake invoices, odd requests)
  • Unrecognised sent items in your Sent folder
  • Password reset emails arriving that you didn't request
  • Inbox rules you didn't create — forwarding rules, auto-delete rules, or labels
  • Login activity from unknown locations — visible in Microsoft 365 or Google Workspace sign-in logs

Any one of these is enough to treat as a confirmed breach.

Step 1: Change the Password Immediately — From a Different Device

Do not change the password from the same computer or phone you normally use. If that device has malware, the attacker may capture the new password too.

Use a trusted device (a colleague's computer, your personal phone on mobile data, not the office WiFi) to:

  1. Go to account.microsoft.com (for Microsoft 365) or myaccount.google.com (for Google Workspace)
  2. Sign in — if you can't, use the account recovery option
  3. Change the password to something long and unique (at least 16 characters, not used anywhere else)
  4. Do not reuse any previous password

If you use the same password on other services (banking, CRM, social media), change those too — immediately.

Step 2: Enable Multi-Factor Authentication (MFA)

If MFA wasn't enabled before, enable it now. This is the single most effective protection against account takeover.

For Microsoft 365:

  1. Go to the Microsoft 365 Admin Center (admin.microsoft.com)
  2. Users → Active Users → Select the compromised account
  3. Under Multi-factor authentication, enable it and require re-registration
  4. Also go to Azure AD → Security → Conditional Access to enforce MFA organisation-wide

For Google Workspace:

  1. Go to admin.google.com
  2. Security → 2-Step Verification → Turn on enforcement

With MFA enabled, a stolen password alone is no longer enough to access the account.

Step 3: Check and Remove Malicious Inbox Rules

Attackers frequently create inbox rules to:

  • Forward all incoming email to an external address (they get copies of everything)
  • Auto-delete email responses that would alert the account owner
  • Mark emails as read to hide activity

In Microsoft Outlook Web (OWA):

  1. Go to outlook.office.com
  2. Settings → View all Outlook settings → Rules
  3. Delete any rules you didn't create

In Microsoft 365 Admin Center:

  1. Go to Exchange Admin Center → Recipients → Mailboxes
  2. Select the compromised account → Mailbox features → Email forwarding
  3. Disable any forwarding rules

In Gmail:

  1. Settings → See all settings → Filters and Blocked Addresses
  2. Also check Settings → Forwarding and POP/IMAP

Remove anything you didn't set up.

Step 4: Review Login History

Check where and when your account was accessed:

Microsoft 365:

  • Go to the Microsoft 365 Admin Center → Users → Select user → Sign-in logs
  • Look for logins from unfamiliar countries, IP addresses, or devices
  • If you see a login session still active from an attacker, go to Azure AD → Select user → Revoke all sign-in sessions

Google Workspace:

  • Admin console → Reports → Audit → Login audit

This tells you the scope: did the attacker just try to log in, or did they have extended access? This affects what notifications you need to send.

Step 5: Check What Was Sent or Accessed

Review the Sent Items folder for the time period the attacker had access. Look for:

  • Emails to clients requesting payments to new bank accounts (Business Email Compromise fraud)
  • Password reset requests for other services
  • Bulk forwards of sensitive documents
  • Emails to your contacts with malicious attachments or links

Also review OneDrive or Google Drive for any files that were downloaded or shared during the compromise period.

Step 6: Notify Affected Parties

If the attacker sent emails from your account, you need to warn recipients:

  • Send a clear notification from your now-secured account (or a new temporary one)
  • Explain that the previous emails were sent by an attacker, not you
  • Ask them not to click any links or open attachments from those emails
  • If you work in finance: explicitly warn any suppliers or clients who may have received altered payment instructions

This step is uncomfortable but essential. Clients who receive fraudulent payment requests and transfer money will hold you responsible if you don't act promptly.

Step 7: Scan for Malware on All Connected Devices

A compromised email is often symptomatic of a wider infection. After securing the account:

  1. Run a full malware scan on every device that had access to the email account (antivirus + Malwarebytes)
  2. Check for keyloggers or remote access tools — these may have been what allowed the initial compromise
  3. If you use Outlook or an email client, check for suspicious add-ins or extensions

If a device is heavily infected, consider a full rebuild rather than cleanup — it's more reliable.

Step 8: Audit Connected App Permissions

Many accounts have third-party apps connected via OAuth ("Sign in with Google/Microsoft"). These apps may retain access even after you change the password.

Microsoft 365:

  • Go to myapps.microsoft.com → Edit profile → Manage account → Privacy → Apps and services
  • Revoke access for any app you don't recognise

Google:

  • Go to myaccount.google.com → Security → Third-party apps with account access

Remove anything unfamiliar or that you no longer use.

What Happens If You Can't Recover Access?

If the attacker changed the password and you're locked out:

  1. Use the account recovery process (Microsoft or Google have phone/backup email verification)
  2. For Microsoft 365: contact your IT admin — they can reset the password and unlock the account from the Admin Center
  3. If you're the admin and can't get in: contact Microsoft support directly with proof of identity

This is one reason why every Microsoft 365 organisation should have at least two Global Administrators — if one is compromised, the second can recover it.

How Did This Happen? Common Causes

Understanding the entry point helps prevent recurrence:

  • Phishing email — you or a staff member clicked a link and entered credentials on a fake login page
  • Password reuse — the password was the same as one exposed in a previous data breach (check haveibeenpwned.com)
  • Weak password — short or predictable passwords are brute-forced quickly
  • No MFA — a stolen password with no second factor is trivial to use
  • Compromised device — malware captured credentials

Preventing This from Happening Again

The most effective protections, in order of impact:

  1. Enable MFA for all accounts — non-negotiable for business email
  2. Use unique passwords — a password manager makes this practical
  3. Conduct phishing awareness training — most breaches start with a click
  4. Keep devices updated and protected — endpoint security matters
  5. Review connected apps and permissions regularly
  6. Set up login alerts — Microsoft 365 and Google Workspace can email you on suspicious logins

Vietify Can Help

If your business email was compromised or you're not confident your Microsoft 365 or Google Workspace environment is properly secured, Vietify provides:

  • Email account recovery and audit
  • Microsoft 365 security hardening (MFA enforcement, Conditional Access)
  • Phishing awareness training for staff
  • Ongoing security monitoring

Contact us → or start with a free IT assessment to review your current security posture.

Vietify IT Services — Business IT security for companies in Da Nang and Vietnam.

Chia sẻ bài viết

Cần tư vấn IT cho doanh nghiệp?

Vietify IT cung cấp Managed IT từ 4.990.000đ/tháng. Phản hồi trong 30 phút.

Nhận tư vấn miễn phí

Bình luận

Đang tải bình luận…

Để lại bình luận

0/2000

Bình luận sẽ được kiểm duyệt trước khi hiển thị.

Xem tất cả bài viết

Cập nhật: 8/8/2026

Frequently asked questions about Vietify

Which businesses does Vietify IT Services support?
Vietify supports small and midsize businesses that need managed IT, security, software licensing, cloud, backup and device support in Da Nang and remotely.
Can I get advice before buying a service?
Yes. You can contact Vietify for a needs assessment, current-risk review and practical recommendations before making a decision.
Does Vietify provide VAT invoices and post-deployment support?
Yes. Vietify provides documentation and VAT invoices when required, plus technical support after deployment according to the agreed service scope.
Miễn phí · Không spam

Nhận tư vấn IT và bài viết mới qua email

Cộng thêm Checklist Bảo mật IT 2026 miễn phí — gửi thẳng vào hộp thư của bạn ngay bây giờ.

Không spam. Chỉ nội dung IT hữu ích. Tuân thủ PDPL 2025.