What should a company do if it suspects that an email account has been compromised?

Contain the incident from a trusted device: reset the password, revoke active sessions, verify MFA methods, review inbox and forwarding rules, inspect message headers and determine which users or external contacts received malicious messages. Preserve evidence before removing it.

Risks to review

  • Change only the password and leave malicious sessions, tokens or rules active.
  • Delete messages and logs before keeping evidence.
  • Reply to the attacker from the same compromised conversation.
  • Failure to warn those who received false invoices, links or instructions.

Safe recommendations

  1. Use a trusted computer to lock or reset the account and revoke active sessions.
  2. Change the password and re-register MFA methods after validating the user.
  3. Review inbox rules, forwarding, delegates, connected applications, and recovery methods.
  4. View login logs and message traces to establish scope and timing.
  5. Notify recipients of suspicious messages or financial requests through an independent channel.
  6. Preserve headings, schedules, and evidence; then correct the cause and document the incident.

Response to a compromised account

First 15 minutes

  • Confirm the incident through an independent channel and use a trusted device.
  • Preserve headers, alerts, timestamps and screenshots before deleting messages.
  • Temporarily lock the account or revoke active sessions and unknown methods.

First hour

  • Reset the credential and re-enrol MFA after validating the user.
  • Review rules, forwarding, delegates, connected applications and recovery methods.
  • Protect related administrator accounts and verify financial requests.

First 24 hours

  • Review sign-in logs and message traces to establish the scope.
  • Warn recipients of suspicious messages or payments through another channel.
  • Document the cause, decisions, owners and follow-up actions.

When to seek specialized help

  • Payments, sensitive data, or messages were sent from the compromised account.
  • The account is administrative or has access to files, billing, or multiple mailboxes.
  • Access cannot be revoked or unknown rules and sessions continue to appear.

Reference sources

These public sources provide general good-practice guidance. They do not replace an assessment of your environment.