A compromised business email can expose private information, give attackers access to other accounts, or lead to fraudulent payment requests. Move quickly, but avoid making changes from a device that may also be infected. Start by containing the account, then check connected devices and services. Preserve useful evidence and communicate with employees, vendors, and customers when needed. These steps can help limit further damage while you work to restore trust and secure your business.
Secure the Email Account
Use a trusted, updated device to sign in to the email provider. Change the password to a unique one that you do not use elsewhere. If you cannot sign in, contact the provider or your email administrator through a known, official channel and ask them to recover and secure the account.
Sign out of all active sessions and remove devices or apps you do not recognize. Check account recovery details, forwarding rules, inbox filters, delegated access, and connected apps. Attackers may add a hidden rule that copies messages or diverts replies. Turn on multifactor authentication and save recovery codes somewhere secure.
Check Devices and Connected Accounts
Look for signs that the computer or phone used to access email may be compromised, such as unfamiliar software, unexpected security alerts, or repeated login prompts. Disconnect a suspicious device from Wi-Fi or wired networks, but do not wipe it before you have considered whether evidence needs to be preserved. Run trusted security updates and scans, or ask a qualified professional to examine it.
Identify accounts that use the compromised email address for password resets, including banking, payroll, cloud storage, social media, and business software. Change passwords from a trusted device, starting with financial and administrator accounts. Review sign-in history and recent changes, revoke unknown sessions, and notify your bank promptly if payment details or transactions may be affected.
Limit Harm and Preserve Evidence
Save relevant evidence before deleting messages or changing settings: note the time you discovered the issue, keep suspicious messages and attachments, and capture unusual forwarding rules or sign-in alerts. Record what actions you take and when. Do not open suspicious links or attachments to investigate them; use your provider’s reporting tools or get technical help.
Check sent mail, deleted items, and message logs for fraudulent requests or data exposure. If anyone may have sent money to an attacker, contact the financial institution immediately and ask about stopping or recalling the transfer. Consider whether sensitive personal information was accessed, and follow applicable legal, contractual, and regulatory reporting requirements.
Communicate Clearly
Tell employees and key vendors through a separate, trusted channel that the account was compromised. Ask them not to act on recent payment, password, or document requests from the affected address until they verify them directly using a known phone number or another established contact method. Make sure staff know who is handling questions and what warning signs to report.
If customers may have received fraudulent messages or their information may have been exposed, contact them promptly with confirmed facts. Explain what happened, what information may be involved, what steps you have taken, and how they can verify legitimate messages from your business. Avoid speculation, include a safe way to reach you, and provide updates if the investigation changes what you know.
After containing the account, keep monitoring sign-ins, payment activity, and customer reports while you close any remaining security gaps. If the cause or scope is unclear, a cybersecurity professional can help investigate and prioritize next steps. North Loop Cyber works with small businesses in Minneapolis; contact the consultancy to discuss support.
