← All posts
Incident Response2 Jun 2026·2 min read·By

The first hour after you think an email account has been taken over

Share

A supplier asks why your bank details changed, and nobody in the office changed them. What to do in the first hour, in order.

It often starts with a phone call. A supplier rings to ask why the bank details on your last invoice changed. Nobody in your office changed them. Someone has been reading, and sending, from one of your mailboxes.

Business email compromise is common here, and it can cost more than ransomware because the money leaves through a normal bank transfer. Catch it early and you can limit the damage a lot. This is the order we'd work in. It assumes Microsoft 365 or Google Workspace, but the ideas carry over.

First 15 minutes: lock it down

  1. Reset the account password from a device you trust.
  2. Sign the user out everywhere. In Microsoft 365 that's "Revoke sessions" on the user in Entra ID; in Google Workspace, reset the user's sign-in cookies from the Admin console. A password change alone doesn't always end existing sessions.
  3. Check MFA is on, and remove any MFA method the user doesn't recognise. Attackers like to add their own.
  4. If money may have gone out, call your bank now. Don't wait for the investigation. Transfers can sometimes be stopped or recalled if the bank hears quickly.

Next 20 minutes or so: find what they changed

Attackers who get into a mailbox usually set things up so they can stay quiet. Look for:

  • Inbox rules, especially ones that move or delete mail containing words like "invoice", "payment" or "bank"
  • Forwarding to an outside address
  • Apps granted access to the mailbox that nobody recognises
  • Recent sent items and deleted items

Export the sign-in and audit logs now. Depending on your licence, retention can be short, and you'll want them later.

Rest of the hour: who needs to know

Check who the account emailed while it was compromised. If invoices or bank details went out, call those customers or suppliers (phone, not email) and tell them which details are real.

If the mailbox held customer personal data, think about your obligations under the Personal Data Protection Act. If it looks like part of something bigger, report it to Sri Lanka CERT|CC. Keep a simple written log of what you did and when. It helps whoever picks this up next, including an outside team if you bring one in.

Afterwards

The fix is nearly always the same: MFA for everyone, legacy authentication blocked, and a rule that any change to bank details is confirmed by phone on a number you already had. That last one costs nothing and stops most of these frauds.

Share

Comments (0)

No public comments yet.

Leave a comment

Comments are checked by hand before they go live.

Most read on the blog

  1. 1Zero trust when you have one IT person and three branches
  2. 2What we'd put on a one-page security update for the board
  3. 3Logging for companies that can't justify a SIEM yet
  4. 4Ransomware prep for mid-sized companies: start with the restore
  5. 5Is your guest Wi-Fi on the same network as the accounts PC?

Related posts