Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a business email account may be compromised, contact your IT administrator or security lead through a trusted channel, stop using the account for sensitive actions, and contain access promptly. Then check for ways the attacker could return, investigate what was accessed or sent, warn affected people, and restore the account only after unauthorized access paths have been removed. The exact controls and logs depend on the email provider; the steps below describe Microsoft 365 where noted.

What should you do first?

  1. Contact the right person using a trusted channel. Tell your organization’s IT administrator or security lead that the account may be compromised. Do not rely on the possibly compromised mailbox to coordinate the response. If your organization has no internal responders, contact its established IT or security provider.
  2. Stop sensitive activity from the affected account. Do not use it to approve payments, change payroll or supplier details, send credentials, or share sensitive files while access is in question.
  3. Contain access. For Microsoft 365, Microsoft’s account-compromise guidance recommends disabling the affected account during investigation. Have a trusted administrator reset its credentials and revoke active sign-in sessions. A password change alone should not be treated as proof that all attacker access has ended.
  4. Preserve useful information. Avoid deleting suspicious messages, rules, or account changes before responders can record them. Keep relevant message details and transaction records.

If payment instructions or a transfer may have been affected, contact the bank and business counterparty promptly using independently verified contact details. Do not use phone numbers or links supplied in a suspicious message.

How do you stop the attacker from getting back in?

After containing the account, check for changes that could preserve access or quietly expose incoming mail. In Microsoft 365, Microsoft’s guidance calls for reviewing authentication methods, application permissions, administrative roles, mailbox forwarding, and inbox rules. Remove only changes that are unauthorized, and preserve records responders may need.

Review sign-in methods and permissions

  • Inspect registered MFA devices and methods for additions the account owner does not recognize.
  • Review applications the user has consented to and remove unauthorized permissions.
  • Verify whether the account has administrative roles it should not have.
  • Check for unusual account-profile changes as part of the investigation.

Inspect forwarding and inbox rules

Look for mailbox-level forwarding and inbox rules that redirect or forward mail, or quietly move or hide messages. Include hidden rules in the review. CISA’s Exchange Online baseline warns that “Adversaries can use automatic forwarding to gain persistent access to a victim’s email.” That guidance is specific to Exchange Online; other providers have different controls and terminology.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Thetis Nano-C for Business - USB C FIDO2 Security Key L1 MFA & Passkey Access for School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesfore - 2 Pack
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • USB TYPE C Connectivity & DONGLE Design: Designed for PCs, Macs, laptops, iPhones, and Android devices that utilize a USB-C port. Plug and stay, or carry it on a keychain. (Item Size: 0.73 x 0.60 x 0.30 inches)
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC functionality is not supported.

How can you find out what happened?

Use account and mail records to establish the likely activity window, affected data, and people who may need a warning. For Microsoft 365, Microsoft’s investigation guidance covers Microsoft Entra sign-in logs and risk reports, audit records, sent messages, and message trace. Start with records immediately before the suspected compromise and follow the activity through remediation.

  • Sign-ins: Review timestamps, IP addresses, locations, and whether each sign-in succeeded or failed. These details help establish activity; they do not necessarily identify an attacker conclusively.
  • Audit activity: Examine relevant audit records for the period around the suspected compromise and response. Look for suspicious account or configuration changes.
  • Mail activity: Inspect sent items and use message trace to identify suspicious messages and recipients.
  • Connected files: Investigate associated SharePoint folders and OneDrive files as well as the mailbox. A Microsoft Entra account compromise can expose those connected services.

Record a timeline, suspicious changes, messages and recipients, and findings about data access. Keep the records available to the people handling the incident rather than trying to erase evidence as a cleanup step.

Rank #2
Thetis PRO-C for Business - USB C FIDO2 Security Key L1 MFA & Passkey Access for School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesfore - 2 Pack
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C & NFC): The Thetis PRO-A features integrated USB Type C and NFC for a near-instant account unlock. Simply unfold the key and hold it to your smartphone’s NFC antenna to authenticate on the go.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

How do you limit harm to customers, employees, and business partners?

Use the investigation to identify suspicious messages and everyone who received them. Notify those people through a separate, trusted channel—especially if a message asked them to send money, disclose credentials, or share sensitive information. Tell recipients not to act on the suspicious request and to verify any new payment or account-change instructions independently.

If a wire transfer, invoice, payroll change, or other payment may be involved, contact the bank and business counterparty quickly using verified contact information. Preserve the messages and transaction records for responders and, where appropriate, relevant authorities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Thetis PRO-A for Business - USB A FIDO2 Security Key L1 MFA & Passkey Access for School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesfore - 2 Pack
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-A & NFC): The Thetis PRO-A features integrated USB Type A and NFC for a near-instant account unlock. Simply unfold the key and hold it to your smartphone’s NFC antenna to authenticate on the go.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

There is no single reporting or breach-notification deadline that applies to every business. Determine obligations from the facts and the rules that apply to your organization, including relevant local law, regulators, contracts, and insurer requirements. Involve appropriate legal, compliance, or incident-response advisers where needed.

When is it safe to restore the account?

Restore service only when responders have a basis to believe the account is under your organization’s control and unauthorized access paths have been addressed. Before normal use resumes, verify that the account owner can authenticate safely, remove remaining unauthorized changes, and require MFA. Then monitor sign-ins and mail activity for further suspicious behavior.

Rank #4
Thetis Pro For Business - FIDO2 Security Key L1 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

Microsoft 365 is the specific provider workflow described here, not a universal set of steps. For another service, ask the provider or administrator how to block the account, revoke active sessions or tokens, inspect forwarding and rules, review and retain logs, trace outbound mail, and check access to connected storage. Log availability and retention vary by platform.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should you harden email after recovery?

CISA’s business MFA guidance states, “Strong passwords help, but they are no longer enough.” Require MFA for business email and, where supported, other important systems such as file storage, remote access, and privileged accounts. CISA recommends phishing-resistant MFA and ranks a physical security key as its strongest option in the methods it lists. Check that any method fits your identity provider and employees’ devices, and plan how people can recover access if a factor is lost.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Thetis Pro For Business - FIDO2 Security Key L2 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L2 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Fully compatible with ID Austria, this hardware key meets the mandatory FIDO2 Level 2 (L2) security standard. Check FIDO2 compatibility before purchase - Known limitations: Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
MFA method CISA’s relative guidance Practical consideration
Physical security key Strongest option among those listed by CISA Check compatibility with the organization’s identity provider and employee devices; define a lost-key recovery process.
Authenticator app with number matching Listed after a physical security key Requires compatible employee devices and a recovery process for a lost or replaced device.
App-generated one-time code Listed after authenticator app with number matching Confirm compatibility and make account recovery part of deployment planning.
Biometrics Listed as usually used with another method Availability depends on the employee’s device and the organization’s authentication setup.
Text or email code Weakest of the listed options; CISA says to use it only when stronger methods are unavailable Use a stronger compatible option when possible.

A physical FIDO security key is an option for hardening after access is secured; it does not remove an attacker or investigate a compromise. Choose any key only after checking compatibility with the organization’s identity provider and devices.

CISA also recommends enabling useful logs across servers, firewalls, endpoints, and cloud services; monitoring for high-risk events; and protecting logs from unauthorized access or deletion. Organizations should designate incident-response roles that cover technology, communications, legal matters, and business continuity so staff know who coordinates decisions during an incident.

What changes if the business does not use Microsoft 365?

The containment goals remain similar, but do not assume another provider has the same controls, labels, or log retention as Microsoft 365. Ask the provider or your IT/security team to confirm these capabilities:

  • Can the affected account be blocked while it is investigated?
  • Can active sessions or tokens be revoked?
  • Are sign-in and audit logs available for the relevant period, and can they be preserved?
  • Can administrators inspect mailbox forwarding and rules, including hidden or less-visible rules?
  • Can outbound messages and recipients be traced?
  • Could the account provide access to connected file storage or other services that also need review?

Microsoft’s account response guidance applies to Microsoft 365. CISA’s 2024 Emergency Directive 24-02 addressed a specific Microsoft corporate email exfiltration incident and its reset and exfiltrated-content analysis requirements apply to federal civilian executive branch agencies, not businesses generally. CISA said other organizations potentially affected by that campaign should contact Microsoft with questions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.