Someone Is Inside Your Business Email. Here’s the First Hour

OWNER BRIEF / COMPROMISED EMAIL

READ FIRST. A hacked mailbox is where the costliest business-email fraud begins. Respond in the order below and you keep what can be kept; respond in the wrong order and you hand the attacker your recovery plan.

A vendor calls and asks why an invoice your books show as paid is still unpaid. Accounts payable checks the wire. It went out days ago — to the bank the vendor's email said to use. Only later does someone look hard at that email. The change-of-bank notice came from a real employee's mailbox. A trusted employee appeared in the thread and confirmed it. Everyone followed the normal process, and the money is gone.

A September 2026 briefing written by cyber-insurance attorneys describes the shape of the attack this way: criminals took over the company's own mailbox, read genuine payment communications, waited for a legitimate payment the company was about to make, then announced the banking change from inside that mailbox. They inserted a nearly identical email address for the trusted employee and created mailbox rules that moved their messages — and the responses — into an RSS subscriptions folder, where nobody had any reason to look.[1]

I did not pick that story for the money. I picked it for the first sentence of the paragraph above — "read genuine payment communications." Nothing in it would have been fixed by changing a password. The takeover worked because of what the attacker did after getting in: reading your real conversations, concealing tracks with rules nobody checks, watching for the right payment. That is why order matters. A hacked mailbox is a crime scene, and you start there — not at the login screen.

THE 30-SECOND TAKEAWAY

A hacked mailbox is a crime scene, not a password problem. The order that holds up in every response playbook I trust: 1. If money moved — or payment instructions changed — call the bank first, before you touch anything else. 2. Lock the mailbox from a device you trust: reset the password, end all sessions, restart MFA enrollment. 3. Remove hidden rules, forwarding, connected apps, delegates, and unfamiliar recovery methods. 4. Save the evidence. 5. Warn the people who might receive fraudulent follow-ups. 6. Report the crime. And plan around this reality: while the mailbox is compromised, the attacker may be reading your response. Coordinate aloud or by phone, not by email.

How expensive a hacked inbox gets

■ Business email compromise is the expensive fraud. The FBI's 2025 Internet Crime Report logged 24,768 business email compromise complaints and $3.05 billion in reported losses, averaging above $123,000 per complaint. Those are reported losses; many incidents never become complaints.[5]

■ Mailbox takeovers are now industrial. In September 2026, Microsoft took down EvilTokens, an AI-powered criminal service tied to more than 12,000 compromised inboxes across more than 10,000 organizations — with victims in financial services, healthcare, construction, real estate, wholesale distribution, and higher education. Microsoft seized 50 websites and disabled more than 150 supporting domains; two men were arrested in the U.K.[4]

■ Stolen credentials remain the starting point. Verizon's 2026 Data Breach Investigations Report counted 7,152 confirmed breaches in its small- and medium-sized business dataset (organizations with fewer than 1,000 employees); credentials were compromised in 31%, and phishing appeared in 9% of recorded initial-access paths.[6]

■ Fast reporting keeps money recoverable. In September 2026, the U.S. Attorney's Office in Iowa announced roughly $375,000 recovered from a business email compromise scheme that had cost an Iowa company more than $800,000 in 2022. The U.S. Attorney's message was direct: "If you or your company are targeted by one of these scams, report it to your bank, to law enforcement, and to the FBI's Internet Crime Complaint Center."[7]

A customer once told me, after an incident, that he thought "cyberattack" meant a laptop with a ransom note. A hacked mailbox is cheaper for the criminal and more useful than any locked laptop. It comes with your real conversations, your real contacts, and your real authority. The response below assumes that starting position.

First, make sure it's your mailbox — not just your name

Not every weird email from your address means your mailbox was breached. Criminals can spoof a sender — forge the "from" line so a message looks like it came from you — without ever getting inside. Check where the evidence lives:

■ If your mailbox is clean — no sent items you didn't send, no rules or forwarding you didn't create, no password or recovery changes — spoofing is the likely answer. The fix is a domain problem: SPF, DKIM, and an enforced DMARC policy tell receiving servers to distrust mail that claims to be from your domain but isn't. That is a call to whoever manages your domain, not a response incident.

■ If you find any of the following, treat it as a takeover until proven otherwise: sent items you didn't send; inbox rules you didn't create; external forwarding you didn't turn on; messages missing or deleted without explanation; changed account contact details; repeated lockouts or forced password changes; a signature that appeared on its own; or the mailbox being blocked for sending spam. That is Microsoft's symptom list, substantially as published.[2]

Google's recovery guidance adds the other half of the check for Gmail and Google Workspace: review recent security events, review which devices are signed in, and verify that the recovery phone number and recovery email are yours.[3]

One honest caution: a rule can exist silently. Attackers create rules with innocent names and sometimes rules that don't even show where you look first. If you suspect a takeover but find nothing visible, that is a job for your IT provider's mailbox audit — not a verdict of "probably fine." Keep anything you do find; Microsoft session and audit logs are easiest to save while they're fresh.[11]

PHASE BY PHASE

The response, in the right order

Money first. Then lockout. Then the places attackers hide. Then evidence and reporting.

The first hour: stop the bleeding

This is the order I would execute if this were my mailbox.

☐ STEP 1 Call the bank first — before everything — if money moved or payment instructions changed.

Call the wire or fraud desk (use the number in your own records, not one from the email), ask to recall or freeze the transfer, and ask about notifying the receiving bank. The FBI's business email compromise guidance and Google's hacked-account guidance both name bank contact as an immediate step, and a federal court in Pennsylvania held in August 2026 that a business that lost $1.4 million was in the best position to prevent its own loss — a phone call verifying the new account would have done it.[10] Reach the bank in minutes, and some of the loss may still be recoverable.

☐ STEP 2 Lock the account from a device you trust.

Reset the password — Microsoft recommends disabling the account during the investigation and explicitly warns not to send the new password by email, since the attacker may still read the mailbox. Update app passwords too, which Microsoft says are not automatically revoked by a password reset.[2] Resetting the password alone is not enough: end all active sessions, since a password change does not always sign the attacker out. For Google, sign out every device you don't recognize in the security panel.[3]

☐ STEP 3 Restart MFA rather than trusting what is there.

Review the registered MFA devices and methods, remove anything unfamiliar — the attacker may have enrolled something of theirs — and re-enroll the user's method. Where available, prefer an authenticator app, passkey, or hardware key over one-time codes. If the account is reused across services, change every one of those passwords; attackers use breached credentials like spare keys.[2]

☐ STEP 4 Sweep the places attackers hide.

This is the step most likely to be skipped, and it is the one that decides whether the mailbox is clean or merely quiet. Clear every hidden inbox rule and external forwarder, revoke connected applications (attackers grant malicious apps persistent access that survives a password change), remove mailbox delegates you don't recognize, check recovery email and phone, and review the administrative roles on the account.[2] Coordinate by phone or in person — assume the mailbox is reading your response emails.[11]

The sweep is the difference between "we changed the password" and "they're out." I would not declare the first hour finished until someone can tell me — in writing — what the sweep found and what was removed. "We looked" is not a report.

The first day: preserve evidence before retention deletes it

Once the attacker is out, resist the urge to clean everything up. What you preserve in the next 24 hours is what proves — to law enforcement, to the bank, to the insurer — that this was an unauthorized takeover of a legitimate account, not an employee mistake.

☐ STEP 1 Export the evidence that proves the takeover.

Save the original fraudulent messages with full headers when available, the complete email chain, any substituted bank instructions alongside the originals, and screenshots of the malicious rules and forwarding settings before you delete or disable them. Attorneys who handle cyber-insurance claims say the evidence worth preserving is what proves four points: criminals entered a real company account, they manipulated data inside the payment process, the company intended to make a legitimate payment, and employees were following a normal process the criminals exploited.[1] Keep a simple timeline — what happened, when, and who acted — in the same file.

☐ STEP 2 Save the logs that show the attacker's footprint.

Microsoft's response playbook points to the sign-in logs, audit logs, and recent activity — the IP addresses, locations, times, and new mailbox activity covering the compromise window — plus a message trace of what the attacker actually sent from the mailbox.[2] Log retention is finite. Export before it rotates.

☐ STEP 3 List everyone who received fraudulent mail.

The message trace is also how you find the blast radius: who got invoices, "payment change" notices, or reply-to redirects from your address. You will need that recipient list when you warn them — and that warning should go through a different channel than the compromised mailbox.

☐ STEP 4 Learn how the attacker came in, and close that door.

The usual doors are a stolen or reused password or a malware-infected device. If the email password was reused anywhere else — banking, accounting, payroll, suppliers — Google's own guidance says to change every one of those accounts immediately, including sites reached through the email address and saved passwords tied to it.[3] If a device looks infected, disconnect it from the network and get qualified help before reconnecting it. Guessing the door and acting are better than a perfect diagnosis that arrives next week — but you still want the diagnosis.

☐ STEP 5 Brief your staff in person.

One message: payments, bank-detail changes, and anything financial from the affected account are frozen until cleared. No one forwards the fraudulent messages "to investigate" and nobody tries a creative fix of their own.

Small businesses do post about this publicly, and the pattern above shows up in those warnings. One real example: Affordable Plumbing Solutions posted on September 16, 2026 that a hacked email account had sent false invoices in its name. Owner reports are anecdotal, not breach statistics — but they confirm that the published guidance and the lived failure match.[8]

The first week: warn, report, close the door

☐ STEP 1 Warn everyone in the blast radius.

Contact the customers, vendors, and partners who received or could receive fraudulent mail — through a trusted channel different from the compromised mailbox. The message is simple: our mailbox was taken over during this window; treat any payment-instruction change from us in that window as fraudulent; call us at a known number to confirm anything outstanding.

☐ STEP 2 File the reports.

Submit a complaint to the FBI's Internet Crime Complaint Center at IC3.gov — it's the federal clearinghouse for business email compromise and the reason money is sometimes recoverable later.[7] [9] Report to local law enforcement with your evidence file. And notify your cyber insurer promptly under every potentially responsive policy — cyber, crime, fraud — with the same file. Here is the hard part: insurers sometimes dispute integrated attacks (mailbox takeover + payment redirection) by labeling them both "not computer fraud" and "not social engineering." Legal counsel who handle these claims say your best counterweight is the documented attack record: unauthorized access, manipulated data, a legitimate obligation, a normal process.[1] That's what your evidence file is for.

☐ STEP 3 Finish the credential cleanup.

Every reused password, every app tied to the email address, every session you didn't end in the first hour. Microsoft's playbook also recommends reviewing administrative roles and connected applications as part of the takeover response — a compromised account with admin rights is a second incident hiding inside the first.[2]

☐ STEP 4 Make this the last time.

Enforce MFA on every mailbox, payroll, banking, and domain account; block or alert external auto-forwarding; enforce DMARC on the domain; document how sign-ins, new rules, delegates, and recovery changes get reviewed. A hacked mailbox teaches the same lesson every prevention plan promises: block the cheap paths and write down who watches them.

If the attacker viewed or copied customer or employee data — not just money — your notification duties depend on what was touched and where those people live. That's a conversation with qualified counsel or your insurer's breach-response team, not a guess.[1]

THREE LINES FOR YOUR TEAM

Put this in the onboarding packet, not the incident file. 1. If something looks wrong with the company email, say so immediately — "I clicked" is information, not a confession. 2. If money moved, the next call is the bank, and the call after that is the one that secures the mailbox. 3. The new password for a compromised account never travels through that mailbox — not in an email, not as a reply thread, not ever.

Your IT provider should be able to prove they did all of this

Articles on this site keep the same standard: managed does not mean verified. After an email compromise, "we handled it" should come with paperwork.

What your IT provider should verify

CONTROL

ASK FOR PROOF

Lockout proof

When the account was disabled/blocked; sessions revoked; MFA re-enrolled

Persistence sweep

Hidden rules, forwarding, apps, delegates, recovery: list of found + removed

Changed watch

Sign-in logs and recovery-change alerts saved for the whole window

Recipient tracking

Message-trace output: fraudulent mail that went out and who got it

Entry point

How the attacker came in: verdict or verdict pending with evidence

Reporting readiness

Evidence archive and timeline ready for IC3, police, and insurer

I am not asking you to run a security operations center. I am asking you to make the response visible after the fact. A lockout, a sweep, a recipient list, and a timeline are the evidence that a "we think it's clean now" never becomes.

The bottom line

A hacked inbox is where the costliest business email fraud usually starts. Not with a dramatic hack, but with a legitimate account, real conversations, and a quiet rule nobody checks.

The order decides how much of the damage is recoverable. Call the bank before you fix the mailbox. Lock and uproot the persistence before you tidy up. Save the evidence before retention deletes it. Warn and report before the trail goes cold. After years of watching incidents, that order is the one part of the response I would never rearrange.

Sources

Accessed September 30, 2026. Statistics describe the cited source's dataset or reported complaints and should not be generalized beyond that scope.

1. Hacked-mailbox payment-diversion scenario and insurance-coverage analysis. Cyber-insurance law briefing, "When Your Cyber Insurer Sends You in Circles: A Hacked CFO Email, a Stolen Vendor Payment, and the Coverage Maze That Can Follow" (September 3, 2026). Open source

2. Official compromised-email-account response playbook. Microsoft Learn, "Responding to a Compromised Email Account" (Microsoft Defender for Office 365). Open source

3. Official hacked-Google-Account recovery steps. Google Support, "Secure a hacked or compromised Google Account." Open source

4. EvilTokens cybercrime-service takedown. Redmond magazine, "Microsoft Disrupts AI Platform Behind 12,000 Email Breaches" (September 23, 2026), reporting Microsoft's milestone post. Open source

5. 2025 Internet Crime Report. FBI Internet Crime Complaint Center, 2025 Internet Crime Report (published April 2026). Open source

6. Small-business breach data. Verizon, 2026 Data Breach Investigations Report, pp. 97-98. Open source

7. Iowa BEC fraud-proceeds recovery. U.S. Attorney's Office for the Northern District of Iowa, "United States Recovers $375,000 in Fraud Proceeds from a Business Email Compromise Scam" (September 24, 2026). Open source

8. Small-business owner warning. Affordable Plumbing Solutions public warning that a hacked email account sent false invoices (September 16, 2026; archived page). Open source

9. Business-email-compromise guidance. FBI Internet Crime Complaint Center, "Business Email Compromise: The $26 Billion Scam" (April 6, 2020). Open source

10. Bank duty-of-care and verification-rationale decision. LexBlog, "Banks Do Not Owe a Duty of Care to Non-customers in Business Email Compromise and Wire Fraud Cases" (September 23, 2026), reporting Frontline Fabrics, Inc., E.D. Pa. (August 2026). Open source

11. Email-recovery guide for businesses. Guardian Digital, "Email Recovery Guide — What to Do After Your Account is Compromised." Open source

Independent guidance for practical small-business defense.