Business Email Account Hacked? Step-by-Step Recovery Plan
What to do when a business email account is hacked: lock the attacker out, find hidden forwarding rules, check sent mail, notify contacts, and close the gap.
The first sign is usually a customer asking why you sent them a strange invoice, or a colleague noticing replies that never arrived. By then the attacker has probably been reading for days. Recovery is a specific sequence, and the order matters: lock them out first, then find what they changed, then tell the people who need to know. Here is the sequence for a small business with no security team.
Quick answer
Change the password from a clean device, end all sessions, enable two-factor authentication, then inspect and delete unknown forwarding rules, filters, recovery addresses, and app passwords. Review sent and deleted items to learn what the attacker did, notify affected contacts and your bank if payments were discussed, and check every other account that used the same password. Then fix the entry point.
Step 1: lock the attacker out (first 15 minutes)
- Use a device you trust, ideally not the one you suspect was infected. Sign in to webmail directly by typing the address, not via any link.
- Change the password to a new generated one of 16 or more characters. If you cannot sign in because the attacker changed it, use your provider's recovery flow or have your account administrator reset it.
- End all other sessions and revoke every app password, device token, and connected app you do not recognise. A password change alone may not disconnect a mail app already signed in.
- Enable two-factor authentication now, with an authenticator app or hardware key, and save the backup codes to your password manager.
Step 2: find what they changed (next 30 minutes)
- Rules and filters. Look for any rule that forwards mail externally, marks messages as read, or moves mail from specific senders (your bank, your customers) to an obscure folder or the bin. Attackers hide replies this way. Delete them all.
- Automatic forwarding settings, separate from rules in many providers. Turn off any forward you did not set.
- Recovery email and phone number. Restore yours; remove theirs.
- Signature and Reply-To. Attackers sometimes change the Reply-To so future customers answer to their address.
- Connected apps and API keys. Revoke anything unfamiliar, including send-API keys if your provider issues them.
- Contacts. Check for exported contacts or new entries with lookalike addresses.
Step 3: learn what they did
- Read Sent, Drafts, Deleted, and Archive for messages you did not write. Note recipients, dates, and any invoices or bank details mentioned.
- If your provider offers login history or per-message delivery logs, export them. OquMail keeps per-message delivery logs for outbound mail, which tells you exactly what left your domain and when.
- Search the inbox for password-reset emails from other services. Each one is a sign the attacker tried to pivot into that account.
- Check whether the attacker replied to genuine threads. Those are the customers most at risk of fraud.
Step 4: notify the people who need to know
- Anyone who received a message from the attacker. Tell them the account was compromised, which messages were not from you, and that any bank details or links in them are fraudulent.
- Your bank, if any payment instruction was sent or received while the account was compromised.
- Your team, so they know to distrust anything from that address in the affected window and to check their own rules.
- Your regulator or data-protection authority if personal data of customers was exposed and your jurisdiction requires notification; many set a 72-hour window.
- Your insurer, if you hold cyber cover; delayed reporting can void it.
Step 5: close the entry point
Ask how they got in. Common answers: the password was reused on a site that leaked; a phishing page captured it; a device had malware; a former employee still had access. Change the password on every account that shared it, run a malware scan on the device, and, if it was phishing, run the fifteen-minute team session on the six tells. If mail was being sent in your name from outside your account, that is spoofing rather than compromise, and the fix is SPF, DKIM, and a DMARC policy at quarantine or reject; OquMail guides you through those records with live DNS verification.
Mistakes that let them back in
- Changing the password but leaving the forwarding rule. The attacker keeps receiving copies of everything.
- Not revoking mail-app sessions. The phone they signed in from keeps syncing.
- Deleting the evidence. Keep the fraudulent emails with full headers for your bank and any investigation.
- Assuming it was only one mailbox. Check the mailboxes of anyone who received a message from the compromised account during the window.
Common questions
My contacts got spam "from" me but I see nothing in Sent. Was I hacked?
Possibly not. If the messages fail SPF and DKIM and do not appear in your sent folder or delivery logs, your address is being spoofed rather than your account compromised. Still check rules and sessions, then tighten DMARC.
Should I delete the account and start over?
Rarely necessary and usually harmful, because customers know the address. Recover it properly, keep it, and put two-factor authentication on it.
How long should I keep watching?
Re-check rules, forwards, and sessions weekly for a month. Attackers who lose access often try the old password on other services and probe again.
Free business email on your own domain
OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.
Get started free