How you find out
Typical signs: a customer or supplier asks about an email you did not send; a member of staff reports a login they did not make or an MFA prompt they did not trigger; sent items or deleted items contain messages nobody wrote; an inbox rule appears that forwards or deletes mail; a payment goes astray; Microsoft or your monitoring raises a risky sign-in alert.
If you have a managed provider or a SOC, call them first and skip to what they tell you. [TO CONFIRM: our emergency contact route and hours; state accurately whether out-of-hours response is available and to whom.] If you are on your own, the sequence below is written for an administrator to follow.
The first hour: contain
Do these in order. Speed beats perfection.
- Revoke the account's sessions and reset its password from the Microsoft 365 admin centre or Entra ID. Revoking sessions signs the attacker out everywhere, including phones and browsers already logged in. Do not just change the password; a live session survives that.
- Remove and re-register MFA methods on the account. Attackers who get in often add their own phone as an MFA method to keep access.
- Check and remove inbox rules and forwarding, in Outlook and in Exchange admin: forwarding to external addresses, rules that move or delete messages, rules named with a single character or a dot.
- Check for other changes: new app registrations or consented apps, new admin role assignments, changes to other users, new mail flow rules at tenant level.
- Check the sign-in log for the account: where the attacker came from, since when, and whether the same source hit other accounts. If it did, repeat steps 1 to 3 for them.
- If a payment may have been redirected, call the bank now, before anything else on this list is finished. Recalls work in hours, not days.
- Tell staff briefly: what happened, that some emails from the account may be fake, and to report anything odd.
Do not delete the mailbox, wipe the device or "clean up" emails yet. That is evidence, and it is also how you find out what was taken.
Not sure which of these applies to your business? Ask an engineer.
Book a Discovery CallWhat to preserve
- The sign-in logs and audit log for the period (unified audit logging must already be on; if it is not, switch it on now for next time).
- Copies of the phishing email that started it, with headers.
- Screenshots of the rules, forwarding and app consents found before removal, or export them.
- A timeline: who noticed what, when, and what was done. Write it as you go.
- Any fraudulent emails sent from the account, and the list of who received them.
This is what your insurer, the bank, the police and the ICO will ask for, and it is what tells you the scope of the breach.
Who to tell, and by when
| Who | When | Why |
|---|---|---|
| Your bank | Immediately if money is involved | Recall attempts and fraud monitoring. |
| Your IT provider or SOC | Immediately | Containment, investigation, recovery. |
| Your cyber insurer | As soon as practical, usually the same day | Most policies require prompt notification and provide incident response. |
| Action Fraud (England, Wales, NI) or Police Scotland | Once contained | Reporting fraud and cybercrime. |
| The ICO | Within 72 hours of becoming aware, if personal data was likely accessed and there is a risk to individuals | UK GDPR breach notification. Document the decision either way. |
| Affected customers and suppliers | Once you know who received fraudulent mail | So they do not act on it, and because the ICO may require it if there is a high risk to them. |
| Staff | Same day | Awareness and reporting. |
If in doubt about the ICO, phone their helpline; deciding not to report is a decision that should be written down with reasons.
Recover and close the gap
- Find out how it happened. Almost always a phished password with MFA absent, not enforced, or approved by fatigue. Sometimes a consented malicious app. Occasionally a shared or legacy-protocol login.
- Fix the cause for everyone, not just the victim: MFA enforced, legacy authentication blocked, app consent restricted, external forwarding blocked, alerts for new rules.
- Review what was accessible. What the account could see is what may have been taken. This drives the ICO decision and customer notifications.
- Restore anything deleted from the recycle bin or backup; see the backup guide for the windows.
- Write it up and brief the business: what happened, what changed, what staff should do differently.
The Microsoft 365 security checklist is the list of things that should have been in place; the 24/7 SOC guide explains how this gets found at 2am instead of three weeks later.
How Black Sheep Support helps
For managed clients, this sequence is our job: our monitoring raises the alert, our engineers contain and investigate, and we handle the evidence, the write-up and the fixes. [TO CONFIRM: emergency response availability and hours for managed clients, and whether we take on incident response for businesses that are not clients.]
If you are not a client and you are reading this mid-incident, follow the first-hour steps, then call us on 01273 942560 during business hours. [TO CONFIRM.] We would rather help you contain it than watch it get worse.
Want a second opinion before you buy licences?
We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.
Frequently asked questions
What is the first thing to do if an email account is hacked?
Revoke the account's sessions and reset the password from the admin centre, then remove and re-register MFA methods and delete any forwarding or inbox rules. Revoking sessions matters: changing the password alone does not sign the attacker out.
Do we have to tell the ICO?
If personal data was likely accessed and there is a risk to individuals, UK GDPR requires notification within 72 hours of becoming aware. If you decide it is not reportable, write down why. The ICO helpline can advise.
Should we wipe the laptop?
Not first. Most Microsoft 365 compromises are a stolen password, not malware on the device. Contain the account, preserve evidence, then check the device with Defender and reset it if there is any sign of malware.
How do we know what the attacker saw?
The audit log and sign-in log show what the account did and from where; the account's permissions show what it could reach. Both need unified audit logging to have been on beforehand.
Can we get redirected money back?
Sometimes, if the bank is told within hours. Call them before anything else if a payment is involved, then report to Action Fraud or Police Scotland.
How do we stop it happening again?
MFA enforced for everyone with legacy authentication blocked, app consent restricted, external forwarding blocked, alerts on new inbox rules, and someone watching the alerts. That combination stops the overwhelming majority of repeats.
Discuss incident preparedness
Have the plan before you need it. We will check whether your tenant would let you contain an incident in an hour, whether the evidence would exist, and who would be watching.
- Whether audit logging, alerts and MFA are in the state this guide assumes.
- A one-page incident plan with your contacts and decisions filled in.
- What monitoring and response we would provide, and when.
- The fixes that make the next attempt fail.
Sources
Prices and product facts on this page were checked against the following Microsoft pages on the dates shown.
- 1.ICO: Personal data breaches, a guide (72-hour notification) · accessed 10 September 2026
- 2.Action Fraud: reporting fraud and cyber crime · accessed 10 September 2026
- 3.Microsoft Learn: Responding to a compromised email account · accessed 10 September 2026
What has changed on this page
- 10 September 2026Page published. Our emergency availability marked for confirmation.

