All guides

Business IT Support

Business email hacked? What to do before the attacker keeps access

A changed password is only one part of business-email recovery. If a mailbox may be compromised, protect any money in motion first, use an unaffected administrator or the email provider to contain the account, preserve a small incident timeline, and check the access paths attackers commonly leave behind — sessions, MFA methods, connected apps, roles, forwarding, and inbox rules.

A Tech Genie technician reviewing business email account security with a small-business owner

Guide updated

Start with simple checks. Get expert help when the fix needs more.

Contain the affected account through the responsible provider, then document what changed before normal access resumes.

If money or a payment change is involved

Call the bank or payment provider first. Account cleanup comes next.

The FBI's IC3 guidance says the originating financial institution should be contacted as soon as fraud is recognized to request a recall or reversal. Use a trusted number, not a number inside the suspicious email. Tech Genie cannot stop or recover a payment.

  1. Priority 1

    Protect money in motion

    If a transfer, invoice, payroll change, gift card, card payment, or bank-detail change is involved, call the originating bank or payment provider through a trusted number immediately. Ask about a recall or reversal, then file a detailed IC3 complaint.

  2. Priority 2

    Contain through the real provider

    Use an unaffected administrator account or the provider's official recovery path. Do not sign in through the suspicious email, call its phone number, or let the affected mailbox approve its own recovery.

  3. Priority 3

    Warn known recipients safely

    If the mailbox sent a malicious link or false payment request, warn the known recipients through an unaffected phone number, website, or account. Tell them not to click, pay, or reply to the suspect thread.

  4. Priority 4

    Preserve a small incident record

    Keep the suspicious message, timestamps, recipients, payment details, and provider case numbers under business control. Do not wipe devices or bulk-delete messages before evidence, insurer, or reporting needs are understood.

Choose the response before changing things

A fake message, a stolen mailbox, an affected device, and financial fraud are different problems.

More than one problem may be involved. Start with the highest-impact response, keep the responsible owner clear, and avoid treating every suspicious email as proof that the mailbox itself was hacked.

Email provider + domain owner

Spoofed or lookalike sender

Signal: The message looks real, but the full sending address or domain is different and the real mailbox shows no matching sent activity.

Next: Verify the request out of band, preserve the message, alert the impersonated party, and review domain-email authentication with the provider. Do not assume the real mailbox was accessed.

Microsoft 365 / Google Workspace admin

Mailbox account compromise

Signal: Unknown sent/deleted messages, sign-ins, forwarding, rules, recovery details, MFA methods, connected apps, or administrator changes appear.

Next: An unaffected authorized administrator should follow the provider's current containment checklist, review the whole suspicious time window, and document every approved change.

Device support + account provider

Affected computer or phone

Signal: A link or attachment was opened, software was installed, an MFA prompt was approved, or someone remotely controlled the device.

Next: Disconnect the affected device if malicious activity may still be active. Use another trusted device for account recovery, then plan a consent-based endpoint review before normal use.

Bank / insurer / counsel / incident responder

Financial, data, or legal incident

Signal: Money moved, payment instructions changed, private records may be exposed, or cyber insurance, reporting, or evidence could matter.

Next: Contact the bank first when money is involved. Preserve facts and bring in the insurer, counsel, provider, law enforcement, or a qualified forensic responder as the incident requires.

Provider-controlled containment

Follow the live Microsoft or Google checklist—not a copied command sequence.

Provider controls, labels, available logs, and licensing change. The authorized administrator should use the official documentation linked below and keep a record of the actions actually completed.

Microsoft 365

Microsoft says an affected account should be blocked as soon as possible. Its current response sequence covers account disablement or password reset, session revocation, MFA methods, connected applications, administrative roles, forwarding, inbox rules, sign-in and audit logs, and message trace.

  • Use an unaffected authorized administrator; if the affected identity is the only administrator or the tenant is locked out, use Microsoft's official business-support and tenant-recovery path.
  • Review sign-in and audit activity for the full suspicious time window, not only one IP address or one visible message.
  • Check registered MFA methods, user-consented apps, administrative roles, mailbox forwarding, and hidden or visible inbox rules before restoring normal access.
  • If the mailbox sent spam, the provider may also have restricted outbound mail and require a separate unblock step after recovery.

Google Workspace

Google tells administrators to suspend a suspected compromised user, investigate account and admin activity, revoke access paths, then restore access with new credentials and 2-Step Verification. Google notes that suspension resets sign-in cookies and OAuth tokens.

  • Use another authorized administrator; if the affected identity is the only administrator or access is lost, use Google's official administrator-account recovery path.
  • Review user and administrator log events, email activity, recovery details, connected devices, OAuth access, forwarding, filters, contacts, and other Gmail settings.
  • Follow the provider sequence for password reset, OAuth-token and app-password revocation, then carefully return access to the verified user.
  • Review the Workspace edition and available logs before promising how far back an investigation can see or what evidence exists.

Preserve useful facts

Keep a small incident packet under business control.

Provide enough context for the email provider and authorized responders without copying private business email into an intake form, text thread, or technician's personal device.

  • A short timeline with approximate times, who noticed the issue, and which account or device was involved
  • The full sender address, subject, recipients, message date, and payment or file-link context already visible in the provider
  • Known sent, deleted, forwarding, recovery, MFA, role, or connected-app changes without copying private mailbox contents into a service request
  • Bank, payment-provider, Microsoft, Google, insurer, and law-enforcement case numbers
  • Photos or screenshots only after checking they do not reveal passwords, MFA codes, recovery keys, account numbers, customer records, or private messages

Avoid a second failure

Do not rush into a password-only cleanup.

  • Do not reply to the suspicious thread, use its link, or call a number inside it to verify the request.
  • Do not send Tech Genie passwords, MFA codes, recovery keys, mailbox exports, private messages, attachments, customer records, or payment data.
  • Do not assume one password change ends access; active sessions, tokens, apps, recovery methods, roles, forwarding, and rules also matter.
  • Do not factory-reset a phone, wipe a computer, delete the mailbox, or purge suspicious mail before evidence and escalation needs are understood.
  • Do not promise customers that nothing was viewed or copied just because one scan or account check looks clean.

Owner-approved recovery order

Restore trust in the account, the device, and the business workflow.

  1. 1. Name the owner and platform

    Confirm the business owner, authorized administrator, affected user, domain owner, Microsoft or Google tenant, reseller, and provider support contact before changing the account.

  2. 2. Contain known access paths

    Follow the provider's current response checklist for the account, sessions or tokens, authentication methods, apps, roles, forwarding, rules, and recovery details. Record who approved each change.

  3. 3. Investigate the relevant window

    Review provider logs, sent activity, suspicious settings, devices, and known recipient reports from before the first symptom through containment. A missing log is not proof that nothing happened.

  4. 4. Review affected devices

    If a link, download, browser session, MFA prompt, or remote-access tool was involved, inspect the device under an approved scope. A malware scan is useful evidence, not a guarantee of complete safety.

  5. 5. Restore and communicate

    Return access only to the verified user, confirm expected mail flow, warn known recipients through a clean channel, and coordinate any broader notification with the responsible provider, insurer, counsel, or authority.

  6. 6. Close the gaps that caused repeat risk

    Document administrators, recovery ownership, phishing-resistant MFA options, payment-change verification, connected apps, forwarding policy, device updates, backups, and the next review date.

Prevention that fits a small business

Turn one recovery into a simpler, supportable system.

Owner-controlled account map

Keep a current list of the domain host, email provider, reseller, administrators, recovery contacts, licensing, and official support contacts without storing passwords in the service notes.

Stronger sign-in and recovery

Require MFA for important accounts, prioritize phishing-resistant methods for administrators where supported, and periodically verify that recovery email, phone, security keys, and backup administrators still belong to the business.

Payment-change verification

Require a known phone number or other independent channel before staff accept new bank details, urgent transfers, gift-card requests, payroll changes, or vendor payment instructions.

A review schedule that matches risk

A recurring plan can track account inventory, important provider alerts, privileged roles, suspicious forwarding, connected apps, devices, backups, and support history. It is not a 24/7 SOC unless a separate service explicitly provides that coverage.

Know when local IT support stops

Data exposure, regulated records, major loss, and legal evidence need incident-specific specialists.

Tech Genie can help with account and device triage, authorized provider checks, and documentation. It does not provide forensic certification, breach-scope determination, legal or compliance advice, financial recovery, cyber-insurance decisions, or a 24/7 security operations center.

Owner-controlled local support

What a scoped visit can do.

Identify the platform and authorized administrator, organize the timeline, assist with provider-documented checks, inspect an affected computer within an approved scope, and leave a prioritized recovery and prevention list. The owner types credentials and approves every meaningful change.

Recover, document, then prevent repeats

Get help without putting mailbox credentials or private messages into a form.

Share only the platform, affected user count, timing, visible symptom, ZIP code, and whether money or business data may be involved. Keep passwords, codes, private email, attachments, and customer records under business control.

How Tech Genie helps

Solve the problem and make it easier next time.

Tech Genie identifies the cause, handles the agreed work, and explains what changed and what to do next.

Build a clear incident timeline, identify the responsible email platform and authorized administrator, and separate bank/provider actions from device work.
Assist the authorized owner with provider-documented checks and approved endpoint scanning while the owner keeps passwords, MFA codes, recovery keys, private mail, and customer records under direct control.
Document recovery gaps and prevention priorities for business email, devices, backups, payment verification, and recurring care. Tech Genie does not provide forensic certification, legal advice, financial recovery, or a 24/7 security operations center.

FAQ

Quick answers before booking.

What should a business do first if email may be hacked?

If money was sent or payment instructions changed, contact the bank or payment provider first using a trusted number and report the incident to IC3. For the mailbox, use an unaffected administrator or the provider's official recovery path to contain access. Do not use a link or phone number from the suspicious message.

Is changing the email password enough?

No. Microsoft and Google both document additional access paths that may need review, including active sessions or tokens, MFA and recovery methods, connected applications, forwarding, filters or inbox rules, administrator roles, and account activity.

Can Tech Genie prove what an attacker read or copied?

No. Normal IT support can document visible account and device findings, but it cannot guarantee what someone viewed, copied, sent, or retained. Incidents involving regulated data, legal evidence, cyber insurance, or major loss may need the provider, insurer, counsel, law enforcement, or a qualified forensic responder.

Should customers or vendors be notified?

Warn known recipients quickly through an unaffected channel if the compromised mailbox sent a malicious link or false payment request. If personal, regulated, or confidential data may have been exposed, preserve the facts and get incident-specific guidance from the insurer, counsel, provider, or appropriate authority because notification duties vary.

Keep troubleshooting