The short answer: Act within the first hour. Get the account offline, change passwords from a device you know is clean, turn on multi-factor authentication, and check for hidden mailbox rules - then report it.
A hacked email account is rarely the end goal. It's the doorway attackers use to send fake invoices, harvest more credentials and impersonate you to your clients. The faster you move, the less damage they can do.
Signs your business email has been compromised
You often won't know until damage is done. Watch for:
- Suspicious sent items - Emails in your "Sent" folder you didn't write.
- Missing emails - Messages deleted from your inbox or folders without you touching them.
- New rules or forwards - Auto-forwarding to unknown addresses (check Outlook Rules or Gmail Filters).
- Password reset emails - Notices that your password changed when you didn't change it.
- Unusual login alerts - Microsoft or Google warning about sign-ins from unfamiliar places.
- Staff reports - Colleagues or clients getting odd emails "from you".
Immediate actions (first 60 minutes)
The first hour is critical. Do these in order:
Step 1: Disconnect the affected account
- Sign out of the account on all devices.
- If you can, disable the account in your admin portal (Microsoft 365 Admin Center or Google Admin Console).
- This blocks further access while you recover.
Step 2: Change passwords from a clean device
- Use a device you're confident hasn't been compromised.
- Set a strong, unique password for the email account.
- If that password was reused anywhere else, change those too.
Step 3: Enable or reset multi-factor authentication (MFA)
- Turn on MFA if it isn't already.
- Prefer an authenticator app over SMS.
- Review and remove any suspicious app passwords or connected apps that could bypass MFA.
Step 4: Check for mailbox rules and forwarding
- Outlook: Settings > Mail > Rules - look for forwarding rules you didn't set.
- Gmail: Settings > See all settings > Forwarding and POP/IMAP - remove unknown forwards.
- Delete any rule you didn't create. Hidden forwarding is the #1 way attackers keep reading your mail after you've reset the password.
Step 5: Audit recent activity
- Microsoft 365: Admin Center > Reports > Audit log search.
- Gmail: Google Admin Console > Reports > Audit - check login activity.
- Note any unfamiliar IPs, devices or actions for your report.
Australian-specific steps
When reporting a business email compromise in Australia:
- Report to the ACSC via ReportCyber - Lodge it at cyber.gov.au/report; this routes to the relevant police.
- If money moved - Call your bank immediately to try to recall the funds, and report the fraud through ReportCyber.
- Preserve evidence - Keep logs and email headers; investigators may ask for them.
- Notifiable Data Breaches scheme - If customer data may have been accessed, you generally must assess a suspected breach within 30 days and notify affected individuals and the OAIC as soon as practicable under the Privacy Act 1988.
How to prevent business email compromise (BEC)
Prevention is far cheaper than recovery. Put these controls in place:
For Microsoft 365 users
- Enable MFA for everyone - Blocks the vast majority of automated credential attacks.
- Configure anti-phishing policies - Use Exchange Online Protection to flag risky senders.
- Turn on mailbox intelligence - Microsoft Defender for Office 365 adds BEC detection.
- Restrict legacy authentication - Disable basic auth wherever you can.
For Google Workspace users
- Use the Advanced Protection Program - For your highest-risk accounts.
- Enable external-sender warnings - Helps staff spot spoofed emails.
- Enforce 2-Step Verification - Require MFA for all users.
For every business
- Never change payment details on email alone - Always verify by phone using a known number.
- Train staff on BEC red flags - Urgency, unusual requests, near-miss domain names.
- Use a verification protocol - Confirm sensitive requests in person or by phone.
The cost of email compromise
Australian small businesses hit by BEC typically face:
- ~$46,000 average loss per incident - ACSC estimate.
- 3-7 days of disruption - Lost productivity during investigation and recovery.
- Possible regulatory penalties - Under the Privacy Act if customer data was exposed.
When to get professional help
Call a specialist if:
- You suspect an attacker still has access.
- A payment has been made fraudulently.
- Customer or business data may have been accessed.
- You're not confident the account is fully secured.
<div class="cta-panel mt-lg"><h2>// Not sure if you've been hacked?</h2><h3>Get a plain-English security check</h3><p>The 2-minute Risk Check flags email and account vulnerabilities fast.</p><div class="cta-actions"><a class="btn btn-primary" href="/assessment.html">Start the Risk Check →</a></div></div>
If you need urgent help recovering from an email compromise, I'm based in Kingscliff and serve businesses across the Tweed Shire, Northern Rivers and Australia-wide. Get in touch for immediate assistance.
Key takeaways
1. Act fast - within hours, not days. 2. Use a clean device to change passwords and enable MFA. 3. Check mailbox rules and forwarding immediately. 4. Document everything for reporting. 5. Put prevention in place before the next incident.
Final thought
A compromised inbox is often just the opening move. Once inside, criminals can reach your network, steal data and impersonate staff for months undetected. My $150/month Enhance service includes ongoing Microsoft 365 hardening that cuts BEC risk significantly.