Why this matters
A compromised mailbox can be used to send fake invoices to clients, reset other passwords and steal sensitive data. Acting quickly limits the damage. These steps help you remove the attacker and close the gaps they used.
What you'll need
- A clean, trusted device
- Access to the email account or your IT administrator
- Your phone for MFA
Step-by-step instructions
Step 1
Change the password from a trusted device
Use a different, clean device to change the password to a new unique passphrase. If you cannot sign in, use the provider’s account recovery or ask your administrator.
Step 2
Sign out of all sessions
For Microsoft 365, admins can use "Sign out of all sessions" in the admin center. For personal accounts, use the security settings to sign out of other devices.
Step 3
Turn on or reset MFA
Remove any MFA methods you do not recognise and register your own authenticator app.
Step 4
Remove malicious rules and forwarding
Check inbox rules, forwarding settings and connected apps. Attackers often add rules that delete or move replies so you do not notice.
Step 5
Check sent items and contacts
Look for emails sent by the attacker. Warn anyone who received them, especially clients and suppliers who may have been sent payment requests.
Step 6
Change reused passwords
Change the password anywhere you used the same one, and any accounts that may have been reset using this email.
Step 7
Report it
Report the incident via ReportCyber at cyber.gov.au. Businesses may also need to assess obligations under the Notifiable Data Breaches scheme.
Summary
New password, signed-out sessions, fresh MFA and removed rules lock the attacker out. Warning your contacts stops the damage spreading.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.