What to do if a Microsoft 365 account is hacked
It usually starts with a phone call. A client asks why you sent them a strange invoice, or a vendor wants to confirm the “new bank details” you emailed. Someone in your office typed their password into a fake sign-in page, and now a stranger is reading and sending mail as them.
This is one of the most common problems small offices face, and it is fixable. What matters is doing the right things in the right order. Here is the plan I follow.
Step 1: If you have cyber insurance, call your carrier first
Many cyber-insurance policies require you to report an incident quickly and to use their approved response team. If you start cleaning things up on your own, you may make it harder to file a claim. Find your policy, call the claims number, and ask what they want you to do before anything else. If you don’t have a policy, move on to Step 2.
Step 2: Lock the account out
The goal is to stop the attacker right now. In the Microsoft 365 admin center, an administrator should:
- Reset the user’s password to something long and new. Don’t send the new password by email.
- Sign the user out of all sessions. Resetting the password alone does not always kick out someone who is already signed in.
- Check the user’s multi-factor authentication methods. Attackers sometimes add their own phone or authenticator app so they can get back in. Remove anything the employee doesn’t recognize.
If you can’t tell how bad it is, it is reasonable to block sign-in for the account entirely until you’ve finished the next steps.
Step 3: Look for hidden mailbox rules and forwarding
This is the step most people miss. Attackers often create inbox rules that quietly forward copies of mail to an outside address, or that move replies from certain people straight into a folder like RSS Feeds or Archive so the real owner never sees them. That way, when a client replies “did you really send this?”, the employee never knows.
Check the mailbox for:
- Inbox rules the employee didn’t create, especially ones that delete, move or forward messages.
- Forwarding set on the mailbox itself to any outside address.
- Changes to the signature, auto-reply, or “send on behalf” permissions.
- Apps the user granted access to that they don’t recognize.
Delete anything suspicious, but write down what you found first. You will want that record later.
Step 4: Find out what was sent
Look in the Sent Items and Deleted Items folders, and use message tracing in the admin tools, to see what went out while the attacker had access. Pay close attention to anything involving invoices, payment instructions, wire transfers or W-2s. Those are what attackers are usually after.
Step 5: Warn the people who need to know
If fake messages went to clients or vendors, tell them, by phone if money is involved. A short, honest note works best: “An email account in our office was compromised. If you received a message from us asking you to change payment details or open an attachment, please ignore it and call us to confirm.” If a payment was already sent, call your bank right away. Speed makes a real difference in whether money can be recovered.
Depending on what was in the mailbox, you may have legal duties to notify people whose information was exposed. Florida has its own data-breach notification law, and some industries have extra rules. Talk to your attorney if personal or financial information was involved.
Step 6: Check the rest of the office
One phished account is often the first of several. Attackers use a hacked mailbox to send convincing phishing emails to coworkers. Look at recent sign-ins across all users for unfamiliar locations, check other mailboxes for the same kinds of rules, and ask staff whether anyone else clicked a similar link.
Step 7: Make sure it doesn’t happen again
Once the dust settles, close the gaps that let it happen:
- Turn on multi-factor authentication for everyone, not just administrators.
- Block older sign-in methods that skip multi-factor checks.
- Block automatic forwarding of mail to outside addresses unless there’s a business reason.
- Turn on alerts for suspicious sign-ins and new forwarding rules, and make sure someone actually reads them.
- Train staff to spot fake sign-in pages and to verify payment changes by phone.
When to get help
If you aren’t sure what an attacker could have touched, or you don’t have someone comfortable in the Microsoft 365 admin tools, get help sooner rather than later. A mailbox that looks clean can still have a rule or app connection left behind. I clean up compromised accounts for small offices, check the rest of the tenant for the same signs, and give you a written summary of what happened and what was fixed. That is not the same as the forensic investigation an insurer may require, so if you’re insured, start with your carrier.
Want a second set of eyes? Greg offers a free 15-minute quick look at your Microsoft 365 sign-in and email forwarding settings. No cost, no obligation. Call or text (941) 479-1075 or email greg@squaredawaytechfl.com.
Book a quick lookSquared Away Tech serves offices of 5 to 100 people in Ellenton, Bradenton, Sarasota and Tampa Bay, with remote service anywhere in the U.S. Mon–Fri 5–9 PM and Sat 9 AM–5 PM (Eastern Time). Daytime and Sunday appointments available on request; daytime calls get a same-evening callback. Back to the home page · More guides
This guide is general information, not legal or insurance advice. Every office’s setup is different.