Nine Signs Your Business Email Has Been Hacked
September 16, 2026
Attackers stay quiet on purpose. These are the signals that give away a compromised mailbox before an invoice gets paid to the wrong account.
A compromised mailbox rarely looks dramatic. The attacker's goal is to remain boring for as long as possible. These are the tells.
1. An inbox rule or filter nobody created. The single most reliable indicator. Forwarding to an external address, or moving anything mentioning invoices into a folder no one opens.
2. Missing replies. A vendor insists they answered and you never saw it. Something is deleting or diverting mail.
3. Sent or deleted items you do not recognize. Especially short messages to finance or to external counterparties.
4. Sign-ins from unfamiliar places or devices. Impossible travel, an unexpected country, an unknown user agent, or a mail client nobody in the company uses.
5. MFA prompts nobody triggered. Either someone is testing stolen credentials, or the attacker is trying to enroll a device.
6. A counterparty says your bank details changed. Treat this as confirmed compromise until proven otherwise — yours or theirs.
7. Mail from a lookalike domain. One character off, or a different TLD, continuing a real thread.
8. Password reset emails for other services. A mailbox is the master key to every account that resets through it.
9. Contacts report messages you never sent. Including internal phishing sent from a trusted internal address, which is how one compromise becomes many.
What to do with a suspicion
Do not investigate quietly for a week. Revoke sessions, check rules, preserve logs, and freeze pending payments from that mailbox. The cost of being wrong is an hour of inconvenience. The cost of being right and slow is a wire.
The full sequence is on our business email compromise response page, and the mechanics behind these signals are in how business email compromise happens.
Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.