My Business Email Has Been Compromised
The signs an inbox is hacked, what to do in the first hour, and how SecDesk recovers a compromised account. Two-hour response. Senior Dutch responders on every case.
We have closed inbox-takeover cases for a 400-person logistics operator, a Noord-Brabant healthcare provider, and several Dutch mid-market firms.
Signs your business email is actually compromised
- 01
Mailbox rules you did not create
Attackers almost always add forwarding rules that send copies of incoming mail to an external address, or auto-delete rules that hide their replies to your contacts. Check the rules list in Outlook web and in the Exchange admin center. If there is a rule that forwards to a Gmail address, or a rule that moves anything mentioning invoice or wire to RSS Feeds, you are compromised.
- 02
Sign-ins from places the user has never been
Azure AD sign-in logs show country, IP, and device. A login from Lagos or Moscow on an account that only ever logs in from Utrecht is a strong signal. Impossible travel, two successful sign-ins from different countries within a span that no flight could cover, is a stronger one.
- 03
Password reset or MFA device messages the user did not trigger
If your user got an email about a new MFA device they did not register, or a password reset they did not request, treat it as an active attempt in progress. A successful MFA enrollment by the attacker means they can keep signing in even after the password is changed.
Seeing these signs? Call 088 SECDESK.
088 SECDESK (7323375)What to do in the first hour, and how SecDesk recovers the inbox
First hour, your side
Disable the account or sign it out of all sessions in the Microsoft 365 admin center. Do not reset the password yet: a plain reset leaves refresh tokens valid. Do not delete the suspicious mail. Screenshot any strange rules or sign-in events, then call us.
Containment, SecDesk
We revoke refresh tokens and session cookies so the attacker loses access even if they held a stolen token. We remove mailbox forwarding rules, auto-delete rules, and any Power Automate flows the attacker set up. We unregister attacker-added MFA devices and tighten conditional access so re-entry is blocked.
Investigation
We trace the root cause: phishing (AiTM or OAuth consent), credential stuffing from a prior leak, or session token theft through a malicious OAuth app. We pull the Unified Audit Log, Exchange mailbox audit log, and Azure AD sign-in logs. We check what the attacker read, downloaded, or forwarded, and whether they pivoted to SharePoint, OneDrive, or Teams.
Recovery and hardening
Credentials reset with session revocation, MFA re-registered on a clean device, conditional access rules tightened, OAuth application consents reviewed. If the compromise touched personal data, the AVG gives you 72 hours to notify the Autoriteit Persoonsgegevens. Our report is structured for that submission.
Common root causes we see
Phishing (AiTM and OAuth consent)
Most compromises start with phishing. AiTM (adversary-in-the-middle) phishing kits capture the session token after a real MFA approval, so MFA alone does not stop them. OAuth consent phishing tricks the user into granting a malicious app permanent mailbox access.
Credential stuffing
A password reused on a breached third-party site shows up in a credential dump, and an attacker tries it against your Microsoft 365 login. Without MFA, this works on the first try. With weak MFA, it still works often.
Session token theft
Infostealer malware on a personal device exports browser cookies and session tokens. The attacker imports them and is signed in as the user, past the MFA prompt, because the prompt already happened on the victim's machine.
When it is more than one inbox
Phishing waves rarely hit one person. Once we contain the obvious victim, we check every account in the tenant for the same patterns, suspicious sign-ins, matching mailbox rules, or OAuth grants to the same malicious app.
Frequently asked questions
What are the first signs an email account is compromised?
Mailbox rules you did not create, sign-ins from countries the user has never visited, password reset or MFA registration messages the user did not trigger, contacts reporting strange replies, and sent items the user does not recognise. Any one of these is worth investigating. Two at once is a confirmed incident.
Is resetting the password enough?
No. A password reset does not invalidate existing refresh tokens or session cookies. If the attacker has a stolen token, they remain signed in. You need to revoke sessions, remove attacker-added MFA devices, and remove any OAuth grants. Only then is the password reset meaningful.
Can the attacker still read email after we change the password?
Yes, if you did not revoke sessions, or if the attacker set up a forwarding rule, or if they consented to an OAuth app that has mailbox read permission. That is why recovery is not just a password reset.
Do we have to notify customers?
It depends on what data was exposed. If the attacker read or exfiltrated personal data, the AVG requires you to assess risk to the data subjects and, in many cases, to notify them. We help with that assessment and with the written notification to the Autoriteit Persoonsgegevens.
How long does recovery take?
A single compromised inbox with no lateral movement typically closes within one to two business days of billable work. If the compromise spread to other accounts, to SharePoint, or to finance workflows, it takes longer. We scope this on the first call.
What if we do not know how the attacker got in?
We work it out. Sign-in logs, device logs, email headers, OAuth audit trails, and the user's own browser history point to the root cause. If we cannot determine it with certainty, we say so and explain the probable vector.
Related reading
- Most compromises start with phishing
- On Microsoft 365? See the O365 response page
- If the attacker is sending invoices from your CEO, this is BEC
- How credential stuffing works
- Phishing attack example, step by step
- Reporting a data breach in the Netherlands
- Our full incident response service
- Prevent the next one with Threat Exposure Management
Call 088 SECDESK
Seeing the signs? Call now. A senior responder picks up, and begins containment within two hours.
- Two-hour SLA
- Dutch senior responders