Local Melbourne technicians available

CareersRemote supportContact
All insights

Insights · Cyber Security

What to do if a business email account is compromised

A practical first-response guide for suspected business email compromise: contain access, preserve evidence, check forwarding rules, protect payments and recover safely.

A suspicious sign-in, unexpected MFA prompt, strange sent mail or changed payment details can indicate a compromised email account. Act promptly, but avoid deleting evidence or making broad changes without recording what happened.

Contain the account quickly

Use a trusted administrator account to disable active sessions, reset the password and require fresh sign-in. Review and remove unfamiliar MFA methods, recovery details, application consents and delegated access. Keep a record of the time and actions taken.

If the user is signed in on a device that may be infected, isolate it from the network and have it assessed before returning it to service.

Check for persistence and fraud

Review mailbox forwarding, inbox rules, auto-replies, deleted items, sent mail, shared mailbox permissions and recent sign-in activity. Attackers often create rules to quietly copy conversations or hide payment-related messages.

Warn finance and relevant contacts using a known, trusted channel. Verify any payment instruction change by calling an independently known number—never a number in the suspicious email thread.

Understand the scope

Identify which information, contacts, files and connected services may have been exposed. Check whether the account had elevated privileges, access to mailboxes, cloud storage or third-party applications.

Preserve logs, headers and relevant messages for investigation. This is important if a bank, insurer, regulator, customer or law-enforcement agency needs evidence later.

Recover and strengthen

Restore access deliberately, patch affected devices, remove unauthorised rules and tokens, and review conditional access, MFA and administrator roles. Notify affected people based on the facts and the legal or contractual requirements that apply to your organisation.

Use the incident as a learning opportunity: improve approval processes for payments, train staff to identify impersonation, review phishing controls and run a tabletop exercise for the next incident.

Get help early when money or sensitive data is involved

If a payment may have been diverted, contact the bank immediately. If personal information may be involved, obtain privacy or legal advice about notification requirements. Podium IT can assist with technical containment and recovery, but the organisation remains responsible for business, legal and regulatory decisions.

Talk to Podium IT

Need a clear next step?

Send a secure enquiry and tell us what you are planning. Please do not include passwords, patient information or other sensitive data.

Encrypted in transit Securely stored

This form uses server-side validation, bot protection and rate limiting. For urgent support, call us directly.

General information only. It is not legal, privacy or compliance advice; requirements should be assessed for your organisation.