Home › Guides

What to do if a Microsoft 365 account is hacked

By Greg Mitchell · Squared Away Tech · October 11, 2026

It usually starts with a phone call. A client asks why you sent them a strange invoice, or a vendor wants to confirm the “new bank details” you emailed. Someone in your office typed their password into a fake sign-in page, and now a stranger is reading and sending mail as them.

This is one of the most common problems small offices face, and it is fixable. What matters is doing the right things in the right order. Here is the plan I follow.

Step 1: If you have cyber insurance, call your carrier first

Many cyber-insurance policies require you to report an incident quickly and to use their approved response team. If you start cleaning things up on your own, you may make it harder to file a claim. Find your policy, call the claims number, and ask what they want you to do before anything else. If you don’t have a policy, move on to Step 2.

Step 2: Lock the account out

The goal is to stop the attacker right now. In the Microsoft 365 admin center, an administrator should:

If you can’t tell how bad it is, it is reasonable to block sign-in for the account entirely until you’ve finished the next steps.

Step 3: Look for hidden mailbox rules and forwarding

This is the step most people miss. Attackers often create inbox rules that quietly forward copies of mail to an outside address, or that move replies from certain people straight into a folder like RSS Feeds or Archive so the real owner never sees them. That way, when a client replies “did you really send this?”, the employee never knows.

Check the mailbox for:

Delete anything suspicious, but write down what you found first. You will want that record later.

Step 4: Find out what was sent

Look in the Sent Items and Deleted Items folders, and use message tracing in the admin tools, to see what went out while the attacker had access. Pay close attention to anything involving invoices, payment instructions, wire transfers or W-2s. Those are what attackers are usually after.

Step 5: Warn the people who need to know

If fake messages went to clients or vendors, tell them, by phone if money is involved. A short, honest note works best: “An email account in our office was compromised. If you received a message from us asking you to change payment details or open an attachment, please ignore it and call us to confirm.” If a payment was already sent, call your bank right away. Speed makes a real difference in whether money can be recovered.

Depending on what was in the mailbox, you may have legal duties to notify people whose information was exposed. Florida has its own data-breach notification law, and some industries have extra rules. Talk to your attorney if personal or financial information was involved.

Step 6: Check the rest of the office

One phished account is often the first of several. Attackers use a hacked mailbox to send convincing phishing emails to coworkers. Look at recent sign-ins across all users for unfamiliar locations, check other mailboxes for the same kinds of rules, and ask staff whether anyone else clicked a similar link.

Step 7: Make sure it doesn’t happen again

Once the dust settles, close the gaps that let it happen:

Keep a written record. Note the date you noticed the problem, what you found, and every step you took. Your insurer, your attorney or your accountant may ask for it, and it helps if anything comes up later.

When to get help

If you aren’t sure what an attacker could have touched, or you don’t have someone comfortable in the Microsoft 365 admin tools, get help sooner rather than later. A mailbox that looks clean can still have a rule or app connection left behind. I clean up compromised accounts for small offices, check the rest of the tenant for the same signs, and give you a written summary of what happened and what was fixed. That is not the same as the forensic investigation an insurer may require, so if you’re insured, start with your carrier.

Want a second set of eyes? Greg offers a free 15-minute quick look at your Microsoft 365 sign-in and email forwarding settings. No cost, no obligation. Call or text (941) 479-1075 or email greg@squaredawaytechfl.com.

Book a quick look

Squared Away Tech serves offices of 5 to 100 people in Ellenton, Bradenton, Sarasota and Tampa Bay, with remote service anywhere in the U.S. Mon–Fri 5–9 PM and Sat 9 AM–5 PM (Eastern Time). Daytime and Sunday appointments available on request; daytime calls get a same-evening callback. Back to the home page · More guides

This guide is general information, not legal or insurance advice. Every office’s setup is different.