This is written to be followed by whoever is in the office when it happens, not only by a technical person. Print it and keep it somewhere that does not depend on email working.
The signs are usually mundane: a colleague says they received an odd message from you, replies arrive to mail you never sent, or messages disappear from a folder.
Minutes one to five: stop the access
Change the password on the affected account, then sign that account out of every session. A password change alone does not end a session that is already open, which is the mistake that keeps people locked in a loop.
If the account has a second factor, check whether a new device or phone number was registered on it. Remove anything you do not recognise.
Minutes five to fifteen: look for the rules
Check the mailbox for forwarding rules and for rules that move messages into an unused folder. This is how a quiet compromise is kept quiet, and it is the first thing to remove.
Check the account’s own forwarding setting as well as the rules inside the mailbox. They are two different places and both are used.

Minutes fifteen to thirty: find out what was reached
Look at the sign in history for the account: when, from where and from what. You are trying to establish the first unfamiliar sign in, because that is the start of the window.
Then list what that mailbox could reach. Shared mailboxes, calendars, files, any service where the same password was used. Change the password anywhere it was reused, and say plainly to the person that reuse is the thing to fix afterwards.
Minutes thirty to forty-five: warn the people who matter
If money could move, contact your bank and your finance team first. Any request to change payment details received during the window should now be treated as suspect and confirmed by phone.
Tell the colleagues and clients who corresponded with that mailbox during the window. A short, factual message is better than silence, and better than a long apology.
Minutes forty-five to sixty: write it down
Record the time you noticed, what you found, what you changed and who you told. This matters for two reasons: you may need it for an insurer or a regulator, and you will want it when deciding what to change.
If personal data was in the mailbox, take advice on whether the incident needs reporting, and note the clock starts from when you became aware.
What not to do
- Do not delete the mailbox or the account. You need what is in it.
- Do not reply to the attacker’s message or click anything in it to see what it does.
- Do not rely on the password change alone and go home.
- Do not keep it quiet to avoid embarrassment. Every hour of silence widens the damage.
The week after
Turn on a second factor everywhere if it was not already on. Review who holds administrator rights. Check whether any other account signed in from the same place. Then write the payment verification rule down, because compromise of a mailbox is usually about money rather than about data.
Finally, tell the staff what happened in plain terms. People report the next one faster when the last one was handled without blame.
The week after, and what to change
The first hour contains the damage. The week that follows decides whether it happens again, and it is the part that usually gets skipped once the immediate panic has passed.
Find out how the password was obtained. There are three common answers. It was reused from a service that was breached elsewhere. It was typed into a convincing fake sign in page. Or it was simple enough to guess. Each one leads to a different fix, so it is worth establishing which.
Check every other account that person holds. Not just work systems. If the password was reused, it was probably reused more than twice. This is the conversation where a password manager stops being a suggestion and becomes a requirement.
Review the whole organisation, not only the affected mailbox. Look for sign ins from the same place against other accounts, for forwarding rules anybody has set, and for accounts still active for people who have left. An attacker who found one way in usually tried the same approach elsewhere.
Turn on a second factor if it was not already on. This is the change that makes the same attack fail next time, and there is no better moment to get agreement for it than the week after an incident.
Write the payment rule down. Any change to a supplier’s bank details is confirmed by telephoning a number you already hold. No exceptions for urgency, because urgency is the tool being used. Tell the people who pay invoices, and tell them why rather than issuing it as a rule.
Tell the staff what happened. Plainly and without blame. The person who clicked is not the problem. The next person will report something suspicious within minutes rather than hours if they saw the last one handled calmly, and that reporting speed is worth more than any product.
Keep the written record. What you found, when, what you changed and who you told. An insurer may ask, a client may ask, and in twelve months nobody will remember the detail. It also gives you something to check against if a similar message arrives again.
Where to read more
Our cybersecurity page covers the controls that make this less likely, and the Microsoft 365 page covers sign in settings. If it is happening now, contact us and say so in the first line.