If you think an account has been broken into, the order of actions matters. Doing the right things in the wrong sequence lets an attacker back in through a door you have not closed yet.
Do this first, in this order
- Use a device you trust. If the machine may be infected, everything you type on it — including the new password — may be captured. Use a different computer or a phone.
- Secure the email account before anything else. Email resets every other account you own. Change its password, then check its recovery address and phone number for changes you did not make.
- Change the password on the affected account, then any account that shared that password. If it was reused, all of those are compromised too.
- Revoke active sessions. Changing a password does not always sign out sessions that are already open. Look for a "sign out everywhere" or active-sessions option and use it. Without this, the attacker stays logged in.
- Re-check two-factor settings. Attackers commonly add their own second factor so they retain access after a password change. Remove anything you do not recognise, then re-enrol your own and generate fresh backup codes.
- Check for forwarding rules and filters on the mailbox. A hidden rule that copies mail to an external address, or that deletes messages containing certain words, is one of the most common and most damaging things left behind. It is also easy to miss because nothing looks wrong.
- Check for added contacts, API keys and connected applications on any affected portal. Remove what you do not recognise.
Then tell us
Open a High priority ticket, or call if your email is affected. Tell us which account, what you noticed, when, and what you have already changed. Reporting early is always the right call — nobody is criticised for it, and the cost of finding out late is very high.
What to look for while you wait
- Sent items you did not send, and deleted items you did not delete.
- Password reset emails for other services that you did not request. This usually means the mailbox was used to attack something else.
- Changes to bank details or payment instructions on any invoice or document sent from your organisation. Invoice fraud is a frequent motive and it is aimed at your customers, not you.
- Login notifications from unfamiliar places.
Preserve the evidence
Do not delete the suspicious messages or wipe the machine yet. Headers, logs and timestamps are how the entry point gets identified. If it is not identified, it is likely to be used again.
Tell the people affected
If a mailbox was compromised, anyone who corresponded with it may receive convincing follow-up attacks from the real address. Warn them, by a channel other than that mailbox. If customer or personal data may have been accessed, your organisation may have notification obligations — check them promptly rather than after the fact.
Afterwards
Work out how it happened. A reused password, a phishing page, an unpatched device and a shared login are the usual answers, and each has a specific fix. Changing the password without finding the cause means it happens again.