More than one problem may be involved. Start with the highest-impact response, keep the responsible owner clear, and avoid treating every suspicious email as proof that the mailbox itself was hacked.
Email provider + domain owner
Signal: The message looks real, but the full sending address or domain is different and the real mailbox shows no matching sent activity.
Next: Verify the request out of band, preserve the message, alert the impersonated party, and review domain-email authentication with the provider. Do not assume the real mailbox was accessed.
Microsoft 365 / Google Workspace admin
Signal: Unknown sent/deleted messages, sign-ins, forwarding, rules, recovery details, MFA methods, connected apps, or administrator changes appear.
Next: An unaffected authorized administrator should follow the provider's current containment checklist, review the whole suspicious time window, and document every approved change.
Device support + account provider
Signal: A link or attachment was opened, software was installed, an MFA prompt was approved, or someone remotely controlled the device.
Next: Disconnect the affected device if malicious activity may still be active. Use another trusted device for account recovery, then plan a consent-based endpoint review before normal use.
Bank / insurer / counsel / incident responder
Signal: Money moved, payment instructions changed, private records may be exposed, or cyber insurance, reporting, or evidence could matter.
Next: Contact the bank first when money is involved. Preserve facts and bring in the insurer, counsel, provider, law enforcement, or a qualified forensic responder as the incident requires.