
My Business Email Was Hacked: What Do I Do First?
October 5, 2026
If your business email was hacked, the first hours are critical. Immediately reset passwords, force sign-outs, and check for forwarding rules. This guide details the first steps to take to regain control and minimize damage after a business email compromise.
If you suspect your business email account has been hacked, you need to act immediately. The first few hours after a compromise are critical to containing the incident, protecting your company’s assets, and preventing further damage. Attackers who gain access to a business email account can intercept payments, steal sensitive data, and use your identity to defraud your customers and employees.
This guide provides a direct, actionable plan for what to do right now. Your immediate goals are to lock the attacker out, assess the damage, and begin the recovery process. Panic leads to mistakes; a calm, methodical approach will help you regain control.
If you are in the middle of an active business email compromise incident and need immediate assistance, our 24/7 response team is available to help. Contact us at /business-email-compromise.
First Steps to Take After a Business Email Hack
When an attacker has access to your email, they have a powerful foothold in your organization. They can read every message, access file attachments, and impersonate you. Follow these steps in order to re-secure your account and begin your investigation.
-
Reset the Account Password Immediately: The first and most important step is to change the password for the compromised account. Choose a long, complex password that is unique to this account. Do not reuse old passwords or variations of them.
-
Revoke All Active Sessions: Changing the password may not be enough to kick the attacker out. Most email platforms, including Microsoft 365 and Google Workspace, allow you to forcefully sign out all active sessions. In Microsoft 365, this can be done through the user's account settings in the Entra admin center (formerly Azure Active Directory) by selecting "Revoke sessions." This forces all devices and browsers to re-authenticate.
-
Enable Multi-Factor Authentication (MFA): If MFA was not already enabled on the account, turn it on now. Use a strong form of MFA, such as an authenticator app (like Microsoft Authenticator or Google Authenticator) rather than SMS text messages, which are vulnerable to SIM swapping attacks. If MFA was already on, the attacker may have bypassed it through a technique like MFA fatigue or consent phishing. It's still critical to ensure it is properly configured.
-
Check for Malicious Inbox Rules and Forwarding: This is a classic attacker technique. Once inside an account, they create inbox rules to automatically forward sensitive emails (like those containing keywords such as "invoice," "payment," or "wire transfer") to an external email address they control. They may also create rules to automatically delete these forwarded messages to hide their tracks. Carefully review all inbox rules, forwarding settings, and connected apps in the user’s mailbox settings. Delete any unauthorized email forwarding rules immediately.
-
Review Sign-in Logs: Examine the sign-in logs for the compromised account in your email platform’s admin center (e.g., Microsoft Entra ID Sign-in logs). Look for suspicious activity, such as logins from unusual geographic locations, multiple failed login attempts, or successful logins from unfamiliar IP addresses or devices. Note the times, locations, and IP addresses of any unauthorized access. This information is crucial for understanding the scope of the breach.
-
Scan for Changes to Mailbox and Account Permissions: Attackers may grant themselves or other accounts "Full Access" or "Send As" permissions to the compromised mailbox. In the Microsoft 365 Exchange admin center, check the mailbox delegation settings for the affected user to ensure no unauthorized accounts have been granted access.
-
Preserve Logs and Evidence: Do not delete anything. Preserve all relevant logs, including sign-in logs, the Unified Audit Log in Microsoft 365, and copies of any malicious emails or rules you find. Your ability to investigate and potentially report the incident depends on this data. The retention period for these logs often depends on your licensing level, so securing them quickly is vital.
What to Do if Funds Were Stolen
If the email hack resulted in fraudulent wire transfers or other financial theft, time is of the essence.
- Contact Your Bank Immediately: Call your financial institution and report the fraudulent transaction. Ask them to initiate a recall or reversal of the funds. The sooner you act, the higher the chance of recovery.
- Report to the FBI: File a complaint with the FBI’s Internet Crime Complaint Center (IC3) at ic3.gov. The IC3’s Recovery Asset Team (RAT) can work with the destination bank to freeze the funds, but they must be notified within the first 24-48 hours.
- Gather All Documentation: Collect all email threads, fraudulent invoices, and transaction details related to the wire fraud. This documentation is essential for your bank and law enforcement.
For a detailed guide on this specific scenario, see our post on what to do after a wire fraud incident.
When Should I Call for Incident Response Help?
While you can take the immediate containment steps above, a professional incident response firm is often necessary to manage the complexities of a business email compromise. An external team can ensure the attacker is fully eradicated and help you navigate the aftermath.
Consider calling for help if:
- You suspect the attacker still has access: If you've taken the initial steps but still see signs of malicious activity, you may not have found the attacker's persistence mechanism.
- Multiple accounts are compromised: A single hacked account is bad, but multiple compromised mailboxes suggest a wider, more systemic issue that requires a broader investigation.
- Sensitive data was exposed: If the compromised account contained protected health information (PHI), personally identifiable information (PII), financial records, or intellectual property, you may have legal and regulatory notification obligations. Understanding if a hacked email constitutes a data breach is complex.
- You need to determine the full scope: A proper investigation goes beyond one mailbox. It involves analyzing logs, searching for attacker activity across the environment, and determining exactly what the attacker accessed. This is often beyond the capabilities of an internal IT team.
- You have cyber insurance: Your insurance policy likely has specific requirements for how you must respond to an incident and when you need to notify them. A firm like Lyra Recovery is experienced in working with insurers and meeting their documentation standards.
Frequently Asked Questions
How can I know for sure if the attacker is gone?
Confirming attacker eviction requires a thorough investigation. It's not enough to just change a password. A complete remediation includes analyzing logs for signs of persistence (like OAuth apps or other compromised accounts), searching all mailboxes for malicious rules, and ensuring no other backdoors were created. This is a core part of a BEC incident response playbook.
Do I have to tell my customers or employees about this?
It depends. Notification requirements are dictated by various factors, including state and federal laws (like HIPAA for healthcare), contractual obligations, and the type of data that was exposed. You should consult with legal counsel to understand your specific email breach notification requirements.
How long will the investigation and recovery take?
The timeline for recovery varies significantly. A simple, quickly contained compromise might be resolved in a day or two. A more complex incident involving multiple accounts, data exfiltration, and financial fraud can take weeks to fully investigate and remediate. We provide more detail in our article on how long it takes to recover from BEC.
What if the hacked account was in Google Workspace?
The principles are the same, but the specific tools and locations for settings differ. You still need to reset the password, revoke sessions (using the "Sign out all other web sessions" feature), check for forwarding and filtering rules, and review audit logs in the Google Workspace Admin console. You can find our platform-specific guide here: Google Workspace Account Compromised: Recovery Steps.
Discovering a business email hack is a stressful event, but a structured response can make all the difference. By taking these initial steps, you can contain the immediate threat and create a stable foundation for a full investigation and recovery. However, attackers are sophisticated, and fully ejecting them from your environment requires expertise.
If you have been impacted by a business email compromise and require expert assistance to investigate the incident, secure your environment, and navigate the recovery process, our incident response team is ready to help. Contact us now through our emergency intake form.