First hour: lock them out properly
The moment you know — or seriously suspect — that a business mailbox is compromised, the order of operations matters. Changing the password alone is not enough, because the attacker is usually holding live signed-in sessions that a password change does not always kill.
Do these three together, from a computer you trust:
- Change the password to something new and unrelated, ideally generated by a password manager.
- Sign out of all sessions everywhere. Google and Microsoft both have a button for this, and it is the step that actually evicts the intruder.
- Revoke app passwords and third-party app access on the account, since these survive password changes by design.
If the compromised account is an administrator, do all of this for the admin account first, before anything else — an attacker with admin can undo your fixes as fast as you make them.
Check what they left behind: rules and forwarding
Attackers plant quiet machinery inside mailboxes so they keep receiving your email after you lock them out. Before you relax, check three places.
- Forwarding. Look for any address you do not recognize receiving copies of your mail, in both the account settings and, on Microsoft, the mailbox-level setting your admin can see.
- Inbox rules. The classic malicious rule moves messages containing words like invoice, payment, or bank straight to a folder you never open, or deletes them, so you will not notice the fraud conversation happening in your name.
- Delegates and connected mailboxes. Confirm nobody has been granted access to read or send as you.
Delete anything you did not create, and screenshot it first — those screenshots are evidence of what the attacker was after.
Read the sign-in logs
Both Google Workspace and Microsoft 365 keep sign-in logs, and reading them answers the two questions everything else depends on: how long has the attacker been inside, and did they get into anything else?
Look for sign-ins from countries or cities where nobody on your team was, at hours that make no sense, and note the earliest suspicious entry — that is your compromise window. Then check whether other accounts show the same pattern, because the same phishing email usually went to the whole company, and the account you caught is not always the only one that fell.
While you are in the logs, check sent mail and deleted items for messages you did not write. Attackers often email your contacts from your account, and those messages define who you now need to warn.
Warn contacts and watch the money
Somewhere in the first day, warn the people who might be attacked through you. The main danger of a hacked business mailbox is not your secrets — it is that your customers and vendors trust emails from your address, and the attacker may have already sent them fake invoices or fake bank-detail changes.
Call or separately email anyone the attacker contacted, and tell your regular payment contacts specifically: if you received banking changes from us recently, they were fraudulent, and please verify any payment instruction by phone. This conversation is uncomfortable, and it is much better than the call where a customer tells you they wired money because of your email.
Internally, alert whoever pays your bills to slow down and verify everything for a couple of weeks, since attackers often strike your payables at the same time.
The notification question
Depending on what was in the mailbox, you may have a legal notification duty. Virginia, Maryland, and DC each have breach notification laws that can apply when personal information — things like social security numbers, driver's license numbers, or financial account details — was accessible to an intruder. Regulated industries and government contractors can carry additional, stricter duties.
Be honest about the mailbox contents: years of email often include scanned IDs, payroll files, or client records people forgot were there. If anything like that was inside, or you cannot rule it out, spend an hour with a lawyer familiar with breach law before deciding nothing needs reporting. If you carry cyber insurance, call the insurer early as well — many policies require prompt notice and will pay for exactly this advice.
Harden so it does not repeat
Once the fire is out, spend the next week making a repeat unlikely.
- Turn on MFA for every account in the company, not just the one that was hit. This single control would have prevented most of these incidents.
- Prefer app-based or hardware-key MFA over text messages, and deploy a password manager so no password is reused anywhere.
- Have an administrator review forwarding rules and third-party app access across all mailboxes, since you now know where to look.
- Write down what happened and the timeline while it is fresh — insurers, lawyers, and your future self all want that document.
- Brief the team on the phishing message that started it, because the best training example is the real one.
If you want a second set of eyes on the logs or the cleanup, this is exactly the sort of incident help we provide at HashWhales for small businesses around the DMV — but the sequence above is the whole playbook, and every step is doable today.
