← Back to knowledge base
Security

What to do if your email account is compromised

Signs someone else is in your Microsoft 365 mailbox, the steps to lock them out, and what IT checks afterwards.

Last verified October 3, 2026

Take care: a wrong step here can lock you out or lose data. If you're unsure, stop and contact us.

Email account takeover is one of the most common and costly attacks on small businesses. Attackers quietly read mail, then send fake invoices or payment changes to your clients. Act fast.

Symptoms

  • Contacts receive emails from you that you didn’t send.
  • Messages you don’t recognise in Sent Items or Deleted Items, or emails go missing.
  • New inbox rules that move, delete or forward mail.
  • You’re told your mailbox is blocked from sending.
  • Unexpected sign-in or MFA prompts, or password changes you didn’t make.

Cause

Usually a password entered on a phishing page, or an MFA prompt approved by mistake. Attackers can also steal a signed-in session, which is why a password reset alone isn’t enough.

Fix

1. Call us now

Call, don’t email. The attacker may be reading your mailbox. We revoke all active sessions, which signs the attacker out everywhere, something you can’t do from your own account.

2. Change your password

Reset it from a device you trust: see Reset your work password. Use a new passphrase you’ve never used anywhere.

3. Check your sign-in methods

At aka.ms/mysecurityinfo, remove any phone number or authenticator app you don’t recognise.

4. Check inbox rules and forwarding

In Outlook on the web, open Settings › Mail › Rules and Forwarding. Note anything you didn’t create and tell us before deleting it: it’s evidence.

5. Warn your contacts

Once we’ve secured the account, let clients and suppliers know not to act on recent unusual requests, especially about payments or bank details.

If that didn’t work

For IT staff, following Microsoft’s guidance:

  • Disable the account or reset the password, then revoke sessions (Revoke-MgUserSignInSession).
  • Review MFA methods, consented applications and admin roles.
  • Check forwarding and hidden rules: Get-InboxRule -Mailbox <user> -IncludeHidden.
  • Review sign-in and audit logs, and run a message trace for mail the attacker sent.
  • If the mailbox was blocked for sending spam, remove it from Restricted entities in the Defender portal.

When to call us

Always, and immediately. If money was sent to a fraudulent account, also call your bank right away: the sooner they act, the better the chance of recovery.

Sources

Didn’t fix it? We can take a look.

Open a ticket