Email Compromise Cleanup: The Checklist After Containment
September 16, 2026
Containment stops the bleeding. Cleanup is what stops the second incident. Here is what has to happen in the days after a BEC.
The dangerous week is the one after containment. The attacker is out of one mailbox, the panic has faded, and the conditions that made the compromise possible are still in place.
Identity hygiene across the business
Reset any account that shared a password with the compromised one. Audit privileged accounts, remove standing admin rights nobody uses, and check for service accounts excluded from MFA — those exclusions are where the next compromise starts.
Tenant-wide rule and grant audit
Do not only clean the affected mailbox. Enumerate forwarding rules, delegation, send-as rights, and OAuth grants across every mailbox. Compromises frequently touch more accounts than the one that was reported.
Close the entry path
If it was a token-stealing phishing page, phishing-resistant MFA is the answer, not more awareness training. If it was legacy authentication, disable it. If it was an unmanaged device, require device compliance. Match the fix to the actual technique.
Warn the counterparties
Anyone who exchanged payment information with that mailbox needs a phone call — not an email. Ask them to verify banking details with you by voice, and tell them to treat recent threads with suspicion. This is the step that stops your incident from becoming your customer's.
Rebuild the payment control
Most BEC losses are enabled by a process gap, not a technical one. Require out-of-band verbal verification for any change to bank details, use a known-good callback number, and split approval between two people above a threshold.
Monitor deliberately
Add detections for the technique used, alert on new forwarding rules and consent grants, and turn on dark web credential monitoring for the affected domain — leaked credentials often circulate before they are used again.
Write the after-action
One page. What happened, what worked, three changes with owners and dates. Then read it out loud at the next leadership meeting. A cleanup nobody documents is a cleanup that gets undone.
Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.