A suspicious sign-in, unexpected MFA prompt, strange sent mail or changed payment details can indicate a compromised email account. Act promptly, but avoid deleting evidence or making broad changes without recording what happened.
Contain the account quickly
Use a trusted administrator account to disable active sessions, reset the password and require fresh sign-in. Review and remove unfamiliar MFA methods, recovery details, application consents and delegated access. Keep a record of the time and actions taken.
If the user is signed in on a device that may be infected, isolate it from the network and have it assessed before returning it to service.
Check for persistence and fraud
Review mailbox forwarding, inbox rules, auto-replies, deleted items, sent mail, shared mailbox permissions and recent sign-in activity. Attackers often create rules to quietly copy conversations or hide payment-related messages.
Warn finance and relevant contacts using a known, trusted channel. Verify any payment instruction change by calling an independently known number—never a number in the suspicious email thread.
Understand the scope
Identify which information, contacts, files and connected services may have been exposed. Check whether the account had elevated privileges, access to mailboxes, cloud storage or third-party applications.
Preserve logs, headers and relevant messages for investigation. This is important if a bank, insurer, regulator, customer or law-enforcement agency needs evidence later.
Recover and strengthen
Restore access deliberately, patch affected devices, remove unauthorised rules and tokens, and review conditional access, MFA and administrator roles. Notify affected people based on the facts and the legal or contractual requirements that apply to your organisation.
Use the incident as a learning opportunity: improve approval processes for payments, train staff to identify impersonation, review phishing controls and run a tabletop exercise for the next incident.
Get help early when money or sensitive data is involved
If a payment may have been diverted, contact the bank immediately. If personal information may be involved, obtain privacy or legal advice about notification requirements. Podium IT can assist with technical containment and recovery, but the organisation remains responsible for business, legal and regulatory decisions.
Talk to Podium IT
Need a clear next step?
Send a secure enquiry and tell us what you are planning. Please do not include passwords, patient information or other sensitive data.
General information only. It is not legal, privacy or compliance advice; requirements should be assessed for your organisation.
