If money was sent
If a client or your own company paid against a fraudulent invoice, the bank comes before anything technical. The FBI's Internet Crime Complaint Center advises contacting the financial institution immediately to request a recall or reversal and a hold-harmless letter or letter of indemnity, and says acting quickly may reduce or eliminate the loss. Then file a complaint at ic3.gov with the banking details. Do this in parallel with the technical steps below, and call (816) 631-1643: our partner ThrottleNet's Kansas City team can run the technical side while you are on the phone with the bank.
The first 60 minutes
This is the order Microsoft's own runbook for a compromised Microsoft 365 account uses. Each step closes a way the attacker stays in.
Disable the account, or reset the password
Disabling the account is Microsoft's preferred first step while the investigation runs. If you cannot disable it, reset the password to a strong, unique one, and do not send the new password by email, because the attacker may still be reading the mailbox. Reset app passwords too; they are not revoked by a password change.
Revoke every active session
A password reset alone does not log the attacker out. Revoking sign-in sessions invalidates the stolen credentials and refresh tokens immediately. An administrator does this in the Microsoft admin tools; it takes a minute.
Remove forwarding and inbox rules
Check mailbox-level forwarding and every inbox rule, including hidden ones, for anything that redirects, forwards or files mail out of sight. This is where most business email compromise persists.
Review MFA devices, consented apps and admin roles
Remove any authentication method or device you do not recognise, revoke any application the account consented to that should not be there, and remove any admin role the account should not hold.
Investigate before you re-enable
Read the sign-in logs from before the first symptom: IP addresses, locations, times. Read the sent items for the same period. Only then reset, re-enable, and remove the mailbox from Microsoft's restricted-senders list if it was blocked for sending spam.
What the attacker usually left behind
Hidden inbox rules
Rules named with a single character or a space, filing replies from the client into a folder nobody reads, so the fraud conversation stays invisible.
External forwarding
A copy of every message to an address outside the company, surviving a password reset if nobody removes it.
Consented applications
An OAuth app granted mailbox access, which keeps working after the password changes.
Extra MFA devices
An authenticator or phone number added by the attacker so they can pass the challenge you just turned on.
Elevated roles
An admin role added to the compromised account, or a second account created quietly.
Hijacked threads
Replies inserted into a real invoice conversation with "our bank details have changed", sent from your real address.
Who to call in Kansas City
The steps above need a Microsoft 365 administrator who has done them before and can read the logs. Our partner ThrottleNet's Kansas City team handles containment and recovery for compromised Microsoft 365 tenants as part of emergency support, and states a 90-second average response time from its own survey data. Say "hacked email" on the call and the sequence starts with containment, not sales. Two boundaries, stated plainly: forensic investigation for insurance or litigation, and legal notification obligations, are separate work, quoted separately and sometimes done by a different firm. A general outage is covered on the Emergency IT Support page.
Mailbox compromised right now?
The number reaches our partner ThrottleNet. Say "hacked email" and containment starts on the call.
Hacked mailbox FAQ
Is this phishing or a compromise?
Phishing is the email that tricks someone; compromise is what happens after they enter their password. If mail is being sent from your address, or rules and forwarding appeared that you did not create, treat it as a compromise and start the steps above.
Do we have to tell our clients?
Anyone who received a fraudulent message from your address should be told quickly and by a channel other than email, with instructions not to act on it. Whether a formal breach notification is required depends on what data was exposed and where your clients are; that is the legal question the boundary above refers to.
A client paid a fake invoice. Are we liable?
That depends on contracts, insurance and the facts. The immediate move is the bank recall and the IC3 report described above, from both companies, within hours rather than days.
Does cyber insurance cover this?
Many policies cover business email compromise, and most require notification within a set period and evidence preserved. Do not wipe the mailbox or the machine before the insurer has been contacted.
How do we stop it happening again?
Multi-factor authentication on every account with phishing-resistant methods for administrators, alerts on new inbox rules and forwarding, conditional-access policies, and a payment-verification rule that no bank-detail change is accepted by email alone. Prevention and ongoing security management are the subject of a separate site; this page is about the first hour.
