How To Recover a Hacked Business Email Account
September 16, 2026
Recovery is more than a password reset. A complete recovery covers credentials, tokens, rules, delegation, devices, and proof the attacker is gone.
Most companies "recover" a hacked email account in five minutes and get reinfected within a week, because the attacker never lost access. A real recovery has seven layers, and every one of them is a place persistence hides.
Credentials
Reset the password to a new, unique value — not a variant of the old one. Then check whether the same password is used anywhere else in the business, because credential reuse is how one mailbox becomes six.
Tokens and sessions
Revoke active sessions and refresh tokens. Tokens survive password changes, which is the single most common reason a compromise reappears the next day.
App passwords and OAuth grants
Delete legacy app passwords and review every third-party app with mailbox scope. Attackers increasingly install a benign-looking "mail reader" consent grant so they never need the password again.
Rules, forwarding, and delegation
Remove malicious inbox rules, external forwarding, and any delegate or "send as" permission that was added. Compare against a known-good baseline rather than eyeballing it.
MFA registration
If the attacker registered their own authenticator or phone number, resetting the password just hands them a fresh session. Purge unknown MFA methods and re-enroll the user in person or over a verified channel.
Devices and mail clients
Look for unfamiliar devices syncing the mailbox, and any mobile profile added during the compromise window. Remove them and require compliant, managed devices going forward.
Proof
Verification is the step people skip. Pull sign-in logs for the full compromise window, confirm no successful authentication from attacker infrastructure after containment, and confirm no rule or grant reappeared. That record is also what your insurer will want.
Platform-specific detail lives in our guides for Microsoft 365 account takeover recovery and Google Workspace compromise recovery.
The hard part is not knowing the list. It is running it under pressure, at 11pm, while also answering finance's question about a $180,000 payment that already left. That is the call we take.
Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.