Someone hacked my business email — what do I do?

A general response checklist for small businesses. Use an authorized administrator or incident-response provider for tenant changes and investigation.

N°001sectionfirst: contain it (do this in the next 10 minutes)

Section 01

First: contain it (do this in the next 10 minutes)

If you suspect someone is inside a business email account, speed matters more than understanding. Do these in order:

  • Change the account's password immediately — from a device you trust
  • Sign the account out of ALL sessions (Microsoft 365: admin center → user → Sign out of all sessions; Google: Admin console → user → Security → Sign out)
  • Turn on multi-factor authentication if it isn't already on
  • Check for inbox rules you didn't create — attackers add rules that forward, delete, or hide mail. Delete any you don't recognize
  • Check email forwarding settings and remove any external forwarding address you didn't set up
N°002sectionthen: look for what they left behind

Section 02

Then: look for what they left behind

An attacker may set up persistence that survives a password change. Have an authorized administrator check for:

  • Third-party apps granted access to the mailbox (these survive password resets — revoke anything unfamiliar)
  • New admin roles or delegated permissions on the account
  • New user accounts you didn't create
  • MFA methods (phone numbers, authenticator apps) you don't recognize on the account
N°003sectionwarn the people who might get robbed

Section 03

Warn the people who might get robbed

A compromised account may be used for payment fraud. Contact affected customers or vendors through a trusted channel and ask them to verify payment instructions before sending funds.

If money already moved, contact your financial institution and appropriate law-enforcement or reporting channels as quickly as possible. In the United States, ic3.gov is the FBI's Internet Crime Complaint Center. Recovery is not guaranteed.

N°004sectioncatch the next one sooner

Section 04

Catch the next one sooner

Many business email compromise cases leave supported audit events such as a suspicious sign-in, inbox-rule change, forwarding change, or risky app grant. InboxGuards checks available Microsoft 365 or Google Workspace audit records approximately every 5 minutes and alerts when a configured detection rule matches, with general response steps. $4 per user per month.

Start authorized audit monitoring

Customer-admin authorization · Read-only audit access · $4/user/mo