A ThrottleNet engineer reviewing a mailbox and admin console across a laptop and two monitors

Signs the mailbox is compromised, from Microsoft's own list

Someone is sending email as you, to your clients, right now. Here is the first hour, in Microsoft's own order, and who to call in Kansas City.

A Hacked Company Mailbox in Kansas City: The First 60 Minutes

  • Inbox rules you did not create, especially ones that forward mail outside the company or move messages to Junk, Notes or RSS folders
  • Sent or deleted items you did not write, including invoices or "updated bank details" to clients
  • New external forwarding on the mailbox
  • Clients or vendors asking about an email you never sent
  • Unexplained password changes, lockouts or multi-factor prompts

If money was sent

If a client or your own company paid against a fraudulent invoice, the bank comes before anything technical. The FBI's Internet Crime Complaint Center advises contacting the financial institution immediately to request a recall or reversal and a hold-harmless letter or letter of indemnity, and says acting quickly may reduce or eliminate the loss. Then file a complaint at ic3.gov with the banking details. Do this in parallel with the technical steps below, and call (816) 631-1643: our partner ThrottleNet's Kansas City team can run the technical side while you are on the phone with the bank.

The first 60 minutes

This is the order Microsoft's own runbook for a compromised Microsoft 365 account uses. Each step closes a way the attacker stays in.

  1. Disable the account, or reset the password

    Disabling the account is Microsoft's preferred first step while the investigation runs. If you cannot disable it, reset the password to a strong, unique one, and do not send the new password by email, because the attacker may still be reading the mailbox. Reset app passwords too; they are not revoked by a password change.

  2. Revoke every active session

    A password reset alone does not log the attacker out. Revoking sign-in sessions invalidates the stolen credentials and refresh tokens immediately. An administrator does this in the Microsoft admin tools; it takes a minute.

  3. Remove forwarding and inbox rules

    Check mailbox-level forwarding and every inbox rule, including hidden ones, for anything that redirects, forwards or files mail out of sight. This is where most business email compromise persists.

  4. Review MFA devices, consented apps and admin roles

    Remove any authentication method or device you do not recognise, revoke any application the account consented to that should not be there, and remove any admin role the account should not hold.

  5. Investigate before you re-enable

    Read the sign-in logs from before the first symptom: IP addresses, locations, times. Read the sent items for the same period. Only then reset, re-enable, and remove the mailbox from Microsoft's restricted-senders list if it was blocked for sending spam.

What the attacker usually left behind

Hidden inbox rules

Rules named with a single character or a space, filing replies from the client into a folder nobody reads, so the fraud conversation stays invisible.

External forwarding

A copy of every message to an address outside the company, surviving a password reset if nobody removes it.

Consented applications

An OAuth app granted mailbox access, which keeps working after the password changes.

Extra MFA devices

An authenticator or phone number added by the attacker so they can pass the challenge you just turned on.

Elevated roles

An admin role added to the compromised account, or a second account created quietly.

Hijacked threads

Replies inserted into a real invoice conversation with "our bank details have changed", sent from your real address.

Who to call in Kansas City

The steps above need a Microsoft 365 administrator who has done them before and can read the logs. Our partner ThrottleNet's Kansas City team handles containment and recovery for compromised Microsoft 365 tenants as part of emergency support, and states a 90-second average response time from its own survey data. Say "hacked email" on the call and the sequence starts with containment, not sales. Two boundaries, stated plainly: forensic investigation for insurance or litigation, and legal notification obligations, are separate work, quoted separately and sometimes done by a different firm. A general outage is covered on the Emergency IT Support page.

Mailbox compromised right now?

The number reaches our partner ThrottleNet. Say "hacked email" and containment starts on the call.

Hacked mailbox FAQ

Is this phishing or a compromise?

Phishing is the email that tricks someone; compromise is what happens after they enter their password. If mail is being sent from your address, or rules and forwarding appeared that you did not create, treat it as a compromise and start the steps above.

Do we have to tell our clients?

Anyone who received a fraudulent message from your address should be told quickly and by a channel other than email, with instructions not to act on it. Whether a formal breach notification is required depends on what data was exposed and where your clients are; that is the legal question the boundary above refers to.

A client paid a fake invoice. Are we liable?

That depends on contracts, insurance and the facts. The immediate move is the bank recall and the IC3 report described above, from both companies, within hours rather than days.

Does cyber insurance cover this?

Many policies cover business email compromise, and most require notification within a set period and evidence preserved. Do not wipe the mailbox or the machine before the insurer has been contacted.

How do we stop it happening again?

Multi-factor authentication on every account with phishing-resistant methods for administrators, alerts on new inbox rules and forwarding, conditional-access policies, and a payment-verification rule that no bank-detail change is accepted by email alone. Prevention and ongoing security management are the subject of a separate site; this page is about the first hour.

Kansas City Business IT HelpCall (816) 631-1643