Category: Owner Briefs

  • Shadow AI Has Three Heads: What Small Businesses Should Do

    OWNER BRIEF / SHADOW AI

    Employee chatbots, third-party agents, and stealth coding.

    The 30-second takeaway

    Does this affect my business? Yes, if employees use AI for work, vendors add AI agents to your software, or AI-built scripts and apps touch company data.

    What should I do? Inventory all three paths, approve exact tools and account types, limit access, require review, and name an owner.

    How urgent is it? Start the inventory this week. If sensitive information or credentials have already been exposed, begin containment immediately.

    OWNER BRIEF / SHADOW AI

    Small businesses will not build most of the AI that changes their work. Employees and software vendors will bring it in — unless the owner controls all three doors.

    No hacker ever touched Community Bank of Pennsylvania. If you own a small business, that is the detail I want you to sit with.

    In May 2026, one of the bank's employees processed non-public customer information — names, Social Security numbers, and dates of birth — through an AI application the company had never approved. No ransomware. No outage. No evidence that the data had been misused. The bank's publicly traded parent, CB Financial Services, did not publicly identify the AI application.

    Days later, CB Financial filed an 8-K with the SEC — the first publicly disclosed shadow AI incident on record. Nobody had broken in. An employee had fed customer records into a tool the company could not see.

    Why would a small community bank tell the world? In practical terms, it had little choice. On May 7, CB Financial decided the incident was material because of “the volume and sensitive nature” of the customer information. For a public company, that decision triggered Item 1.05 of Form 8-K and a four-business-day disclosure clock. Banking and breach-notification rules separately required communication with regulators and affected customers. CB Financial filed with the U.S. Securities and Exchange Commission on May 11. The filing was not an admission that AI had caused financial damage — the company said it expected none. It was a compliance decision: once sensitive customer data had left the bank’s control at sufficient scale, keeping the incident private was no longer a safe option.[13]

    You will probably never file an 8-K. That does not make this a bank-only story. Picture the same click in a 20-person company: a bookkeeper pastes payroll into a chatbot, a salesperson uploads a customer list, or an office manager asks an AI tool to summarize tax forms. The owner now has the same first questions as the bank: What left our control? Who could see it? Can we get it back? Whom do we have to tell?

    All 50 states have breach-notification laws that apply to private businesses, although the definitions, triggers, and required notices vary. Client contracts and cyber-insurance policies may create additional reporting duties. CB Financial’s public-company status determined where the incident was disclosed; it did not create the underlying risk. A small-business owner can face the same data event with no security team, no in-house lawyer, and no reliable record of what the employee entered.[17]

    That is the trap: shadow AI does not break down the door. It is invited in. An employee opens a chatbot. A software vendor turns on an agent inside a product you already buy. Someone uses AI to build a quick internal app, then that “quick” tool starts touching live data. Each move looks useful and reasonable — until you have to explain who had access, what the AI did, and where the data went.

    The next three years will not mainly be about stopping careless employees. They will be about controlling implementation. Small businesses are unlikely to build their own agent platforms; they will inherit AI through vendor features, personal accounts, browser extensions, and code created outside a normal development process. If you do not decide which data, permissions, actions, and AI-built tools are acceptable, convenience and vendor defaults will decide for you.

    Shadow AI in the workday
    Finding Population / source
    48% reported using unapproved AI tools at work TrustedTech/Censuswide, 2026
    65% of senior decision-makers reported shadow-AI use TrustedTech/Censuswide, 2026
    41% reported lacking clear AI data guidance TrustedTech/Censuswide, 2026
    47% of workplace AI users used personal accounts Separate Netskope enterprise research, as reported

    The TrustedTech survey covered 2,001 U.S. and U.K. employees. The Netskope finding comes from a separate enterprise dataset; these percentages should not be combined. [2] [3]

    How widespread is shadow AI?

    • Unapproved use is already normal. In the TrustedTech/Censuswide survey, 48% of employees said they used unapproved AI tools at work.[2]
    • Leaders were more likely to do it. Sixty-five percent of senior decision-makers reported shadow-AI use, compared with 31% of employees below decision-maker level. The original report says 65%, not the 67% repeated in some coverage.
    • Many workplaces have not drawn the boundary. Forty-one percent said their organization lacked clear guidance about what information could be entered into AI tools. Only 23% learned to use AI through employer training; 54% learned by trial and error.
    • Personal accounts remain part of the problem. Netskope’s 2026 enterprise research was reported as finding that 47% of employees who used AI at work did so through personal, unmanaged accounts.[3]
    • Shadow AI incidents are getting more expensive. In IBM's 2026 Cost of a Data Breach Report, security incidents involving unapproved AI more than doubled to 43%, up from 20% the prior year, and averaged $5.39 million in breach costs, up from $4.63 million. About one in five of those incidents drew a regulatory fine.[14]

    The available research is weighted heavily toward large organizations. I did not find a publicly documented shadow-AI leak that names a small business, and I will not pretend the enterprise numbers are a small-business survey. What they show is the behavior produced by the same tools your staff can open in two minutes. A 20-person firm may have fewer users, but it also usually has fewer controls and less ability to investigate where information went.

    Shadow AI is becoming a three-headed monster

    Shadow AI is any artificial-intelligence use the business has not approved, configured, or made visible. The first wave was easy to picture: an employee pasted work into a public chatbot. The next wave is broader. Agents arrive inside third-party software, while AI coding tools let people create working software without a normal development process.

    Most small businesses will not build an agent platform from scratch. They will inherit AI through products they already buy and through tools their staff adopt. That shifts the owner’s question from “Who is using ChatGPT?” to “Which AI can see our data, take actions in our systems, or create software we now depend on?”

    Three ways AI enters the business
    AI entry point Exposure Owner control
    Employee chatbots Prompts and uploads Control inputs and accounts
    Third-party agents Access and actions Control permissions and logs
    Stealth coding Ownership and upkeep Require review and inventory

    Head one: employee chatbots move data across the boundary

    This is the familiar head. An employee uses a personal chatbot, meeting assistant, browser extension, image generator, transcription service, or coding assistant because it produces a useful answer quickly. The risk begins when customer, employee, financial, legal, or technical information crosses into an account the business does not manage.

    A personal paid account is still a personal account. A familiar product name does not tell you which contract applies, whether workspace data is used for training, how long it is retained, whether shared links exist, or who can administer the account when an employee leaves.

    Control the input: Name the approved product and the approved account type. “ChatGPT is allowed” is not a policy. “ChatGPT Business through our company workspace is allowed for the uses listed below” is a policy.

    Head two: third-party agents turn access into action

    A chatbot waits for a person to paste something. An agent may read email, search files, update customer records, send messages, schedule work, or trigger another system. For a small business, that capability is more likely to arrive as a feature inside accounting, customer-relationship, support, productivity, or security software than as an agent the company builds itself.

    Agents in business software
    Period Gartner enterprise-application forecast
    2025 Less than 5% include task-specific agents
    End of 2026 Up to 40% include task-specific agents
    By 2028 Agent ecosystems begin working across applications

    This is an enterprise forecast, not a measured small-business adoption rate. [15]

    The control problem is no longer only what someone pastes. It is what the agent can reach and what it can do without a second approval.

    Control the access: Before enabling an agent, document its data sources, permissions, actions, logs, human-approval points, and off switch. Treat a vendor’s new AI feature as a new access decision, not a harmless software update.

    Head three: stealth coding creates software nobody owns

    AI coding tools let developers and non-developers create scripts, automations, dashboards, and internal apps quickly. The danger is not that every AI-built tool is bad. It is that a useful prototype can become a production dependency before anyone reviews its data access, authentication, logging, backup, error handling, or maintenance owner.

    Retool-sponsored survey of 307 technology and security leaders
    Finding Reported response
    Concern 93% were worried about AI-coded tools running in production
    Priority 38% called it one of their biggest operational risks
    Visibility 95% could not say they knew every AI-coded tool in production

    Enterprise leadership sample; vendor-sponsored research, not a small-business prevalence study. [16]

    This vendor-sponsored enterprise survey is not a small-business prevalence study, but its warning is blunt: AI-built software can reach production before a business even knows it exists—let alone reviews it or assigns an owner.[16]

    Control the code: Require registration and review before an AI-built script, workflow, or app touches live company data. Record who owns it, where it runs, which credentials it uses, how changes are tested, and how it will be retired.

    Employee chatbot incidents show what happens when data leaves your control

    Prompt-based chatbot use arrived first and is easiest to observe. Its documented incidents reveal the many forms an exposure can take; agents and AI-built tools add permissions, actions, and software dependencies to the same loss of visibility.

    Examples of information leaving the owner’s control
    Example from the source document Exposure Safer practice
    CISA official [4] At least four sensitive, unclassified government documents uploaded to public ChatGPT Approved tools and a never-paste list
    Shared chats, 2025 [5] About 4,500 conversations indexed after users enabled discoverability Avoid public work-chat links and review existing links
    Heppner case, 2026 [6] Consumer-Claude documents found not privileged under the account terms and case facts Keep legal strategy and client confidences out
    Samsung, 2023 [1] Proprietary code, equipment-test code and a meeting recording entered into ChatGPT Provide an approved route before convenience wins

    Owner-facing forums confirm the pattern—not a breach count

    Public forums are anecdotal and self-selected. They cannot prove that a specific organization suffered a leak, and anonymous posters cannot be independently verified. Their value is narrower: they show what owners and managed-service providers are actually finding.

    Practitioner discussions
    Forum discussion Reported pattern Owner lesson
    r/msp, December 2025 [7] An IT-provider audit reportedly found six different AI note-takers, extensions and an unknown operations tool Inventory extensions, accounts and retention settings
    r/ChatGPT, January 2024 [8] An employee asked whether a personal paid account was safer for work data A paid consumer account is not a company-managed workspace
    r/sysadmin, 2023 [9] Office network blocks did not address home devices and phones Use controls and training alongside filtering

    Anecdotal, self-selected forum posts; these are not verified breach counts.

    Those posts do not establish loss. They reinforce the same operating pattern the survey data shows: people use what helps, personal accounts blur the boundary, and network blocks do not create governance. The note-taker, extension, and quick automation are also the bridge from the first head to the other two: a tool begins as an assistant, gains access, and quietly becomes part of the workflow.

    PART TWO

    Take back control: empower with policy—not a ban

    You've seen how control is lost. What follows is how to take it back.

    A ban feels decisive. It is also easy to evade with a personal phone, home computer, browser extension, or consumer account. TrustedTech found that 29% of workers would continue using AI even if a ban put them at risk of discipline; among decision-makers, the figure was 37%.[2]

    Even a perfectly enforced chatbot ban would not govern an agent activated inside approved software or an AI-built app running on company data. The control has to match all three ways AI enters the work. If a useful tool saves an hour and the approved alternative is “do not,” someone will eventually create a workaround.

    Start with a two-week amnesty inventory. Tell employees: “List the AI tools and accounts you use for work, and tell us what kinds of information have gone into them. During this inventory, disclosure will not be punished.” The purpose is to find the real environment before writing a rule for an imaginary one.

    Ask about all three heads:

    • Employee chatbots: personal accounts, meeting assistants, transcription services, browser extensions, and company information already entered.
    • Third-party agents: AI features inside accounting, customer-relationship, design, hiring, support, productivity, and security tools — especially features with permission to read, write, send, or approve.
    • Stealth coding: scripts, automations, dashboards, integrations, and internal apps created or substantially modified with AI, including where they run and who owns them.

    Do not ask only, “Who uses ChatGPT?” That misses the agent attached to an approved subscription and the quick app that became a business process.

    AMNESTY LANGUAGE

    Tell us now so we can make the safe path work. For the next two weeks, report every AI chatbot, agent, coding tool, automation, or AI-built app used for company work. Include the account type, data or systems involved, actions it can take, and who owns it. This is an inventory, not a disciplinary exercise. After the inventory closes, the approved-tool, access, and review rules take effect.

    One page governs all three heads

    A 20-person company does not need a 40-page AI standard. It needs a rule an employee can use before opening a chatbot, enabling an agent, or putting an AI-built tool into service.

    The one-page AI rule
    Question Requirement
    Which path? Approve the chatbot, agent or AI-built app
    What access? Limit data, systems, permissions and actions
    Who reviews? Check high-stakes output, actions and code
    Who owns it? Name a person accountable for access, logs and upkeep

    1. Which tool, account, agent, or app may I use?

    Name the exact product, account type, approved use, and owner. A company-managed business workspace gives the owner contractual terms and administrative control that a personal account does not. An embedded agent also needs an approved permission scope, and an AI-built app needs a named maintainer. OpenAI says it does not train on ChatGPT Business workspace data by default; its published price was $25 per user monthly or $20 per user monthly with annual billing when this article was prepared.[10]

    Do not assume every business product has identical terms. Read the current data-use, retention, administrator, permission, and logging settings before approval.

    2. What must never go in — or be granted?

    The short list should include:

    • Customer personal information, payment details, or authentication data.
    • Passwords, recovery codes, private keys, or application programming interface keys.
    • Employee records, payroll, health information, or performance details.
    • Material covered by a client contract or nondisclosure agreement.
    • Unpublished financials, legal strategy, source code, trade secrets, or acquisition plans.

    If a task requires real data, use a sanitized version with names, identifiers, secrets, and unique business details removed. “Anonymized” should mean the information cannot be tied back to a person or client — not simply that the name was deleted. Apply the same logic to access: an agent should not receive an entire mailbox, drive, or customer database when one folder, queue, or read-only view will do.

    3. Who checks the output, action, and code?

    Require human review before AI output reaches a customer or affects money, contracts, legal advice, health, hiring, discipline, production code, or security settings. Require approval before an agent sends, changes, deletes, or purchases. Require testing and code review before an AI-built tool touches live data. Input exposure, confident errors, unauthorized actions, and weak software are separate risks; the policy should address each one.

    4. Who owns it?

    Name one accountable person for every approved chatbot workspace, agent, and AI-built tool. An employee facing an unusual task needs a fast yes, no, or safer alternative. A workflow also needs someone responsible for permissions, logs, failures, updates, and retirement. A policy without ownership becomes wallpaper.

    A free, adaptable AI-use-policy template is available from Safe AI Australia under an MIT license. It is more detailed than many small firms need, but its approved, conditional, and prohibited-use structure is a useful starting point.[11]

    A 45-minute owner plan is enough to start

    The first version does not need to be perfect. It needs to make responsibility visible.

    1. Minutes 0–10: announce the three-part inventory. Set the two-week amnesty window. Ask for chatbots and personal accounts, agent features and connected systems, and AI-built scripts, automations, or apps.
    2. Minutes 10–20: publish the never-paste and never-grant list. Include client data, employee records, credentials, payment information, legal material, source code, and trade secrets. Add broad mailbox, file-drive, customer-database, payment, and administrator access unless specifically approved.
    3. Minutes 20–30: choose approved paths. Use a company-managed chatbot workspace where the vendor’s terms and settings match your needs. Require a documented permission and approval model for agents. Require registration and review before AI-built tools touch live systems.
    4. Minutes 30–40: remove the easiest shadow routes. Review browser extensions, meeting assistants, connected applications, OAuth grants, automation platforms, and scripts running under employee accounts. Use filtering as a backstop, not as the whole program; it cannot govern every vendor feature or home-built workflow.
    5. Minutes 40–45: teach one ten-minute lesson. Show one safe and unsafe example for each head, where to ask, and how to report a mistake quickly. Repeat it for new employees.

    COPY INTO YOUR POLICY

    Use approved AI only. Protect the input. Limit the access. Review the action and the code. Company work may be performed only through approved accounts, agents, and AI-built tools. Never enter restricted information or grant broad system access without approval. A person must review high-stakes output and approve consequential actions. AI-built software must be registered, tested, and assigned an owner before it touches live data. Report mistakes immediately; early reporting will be treated as help, not concealment.

    Prepare for an Incident

    Do not begin by demanding a perfect explanation. Begin by containing what you can and learning exactly what happened. The event may be a pasted prompt, an over-permissioned agent, an unauthorized action, or an AI-built tool connected to live data.

    • Record the facts. Note the tool, account type, date, data entered, files uploaded, systems connected, permissions granted, actions taken, code or automation deployed, people involved, output created, and whether a share link exists.
    • Delete the chat or file from the service. OpenAI documents how users can delete chats.[12] Deletion is a necessary containment step, not proof that every copy or prior processing vanished.
    • Review and remove shared links. In ChatGPT, shared links are managed under Settings, Data Controls, Shared Links. Do not assume deleting a local chat removed a previously shared public version.[5]
    • Rotate exposed secrets now. Replace passwords, API keys, tokens, recovery codes, or payment credentials that appeared in a prompt, upload, output, or AI-built tool. Revoking the old secret matters more than deleting the sentence that contained it.
    • Revoke agent access and stop unsafe automation. Disable the agent or AI-built workflow, remove its connected-app grants and service credentials, preserve relevant logs, and confirm whether it sent, changed, or deleted anything before restoring service.
    • Check contracts and notification duties. If customer or employee information was involved, review the relevant agreement and state breach-notification law. Many small firms fall below comprehensive privacy-law thresholds; breach-notification duties may still apply regardless of company size.
    • Call the right people before making promises. Notify your insurer or broker under the policy terms. Use qualified legal counsel when regulated data, client confidences, or notification duties may be involved.

    Turning off a training setting is useful going forward, but it is not a time machine. Temporary-chat features can also reduce retention for appropriate low-risk work; they do not make it acceptable to paste client personal information into a consumer account.

    Break the chain: Make accidental disclosure easy to report. The employee who tells you in five minutes gives you options. The employee who hides it for five weeks takes them away.

    Your IT provider should be able to account for all three heads

    An owner should not have to accept “we have security” as an answer. Ask for evidence about chatbot use, agent permissions, and AI-built software in ordinary language.

    CONTROL

    ASK FOR PROOF

    Chatbot inventory

    Which AI tools, accounts, bots, and extensions are known?

    Agent access

    Which systems can agents read, change, send from, or delete?

    AI-built tools

    Which scripts, apps, and automations run, and who owns them?

    Data terms

    Are training, retention, sharing, and deletion settings documented?

    Review and logs

    Which outputs, actions, and code require approval or logging?

    Incident response

    Who records, contains, escalates, and assesses notification duties?

    The provider does not need to promise that no employee will ever use an unapproved tool. It should be able to show which controls exist for each head, who receives alerts, what the limitations are, and what happens after a report.

    The bottom line

    Shadow AI is a three-headed visibility problem created by useful tools. Employee chatbots expose inputs. Third-party agents add permissions and actions. Stealth coding creates software dependencies the business may not know it owns. Punishing people for wanting to work faster will not solve any of them.

    After years in security, my advice is to make the safe route easier than the shadow route: one approved business account, explicit limits on agent access, a register of AI-built tools, one page of rules, a named owner, and a response plan that rewards fast reporting.

    You do not need to monitor every thought or stop every experiment. You need to control which data leaves the business, which systems AI can reach, what actions it can take, which software it creates, and who remains accountable. That is small-business AI governance in practical form.

    Sources

    Accessed September 29, 2026. Statistics describe the cited source’s sample or reported dataset and should not be generalized beyond that scope. No publicly named small-business shadow-AI leak was found in the research for this article.

    1. Samsung employee ChatGPT incidents. DarkReading, “Samsung Engineers Fed Sensitive Data to ChatGPT, Sparking Workplace AI Warnings” (2023). Open source

    2. Workplace shadow-AI survey. TrustedTech/Censuswide, “Shadow AI in the Workplace” (March 2026; 2,001 U.S. and U.K. employees). Open source

    3. Personal-account use. Newsworthy summary of Netskope’s Cloud and Threat Report 2026. Open source

    4. CISA document uploads. TechRepublic, “Former CISA Chief Admits Uploading Sensitive Documents to ChatGPT” (September 10, 2026). Open source

    5. Indexed shared chats and deletion steps. Bitdefender, “Your Shared ChatGPT Chats May Be Publicly Searchable” (2025). Open source

    6. Consumer AI and privilege. Ogletree Deakins, analysis of United States v. Heppner (2026). Open source

    7. MSP shadow-AI inventory discussion. Reddit r/msp (December 10, 2025; anecdotal). Open source

    8. Personal ChatGPT Plus workplace-data discussion. Reddit r/ChatGPT (January 25, 2024; anecdotal). Open source

    9. Blocking-versus-governance discussion. Reddit r/sysadmin (June 7, 2023; anecdotal). Open source

    10. ChatGPT Business data terms and pricing. OpenAI Help Center, “ChatGPT Business FAQ.” Open source

    11. Adaptable AI-use-policy template. Safe AI Australia, MIT-licensed governance template. Open source

    12. Chat deletion instructions. OpenAI Help Center, “How to Delete and Archive Chats in ChatGPT.” Open source

    13. Community Bank shadow-AI SEC filing and disclosure context. American Banker, “A bank breaks its silence on its shadow-AI breach” (June 11, 2026). Open source

    14. Shadow-AI breach costs. IBM, Cost of a Data Breach Report 2026 (602 breached organizations, March 2025–February 2026; non-statistical, enterprise-weighted sample). Open source

    15. Agents embedded in enterprise applications. Gartner, “Gartner Predicts 40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026” (August 26, 2025; forecast, not a small-business adoption count). Open source

    16. Governance of AI-coded internal tools. Retool press release reporting a Wynter survey of 307 CTOs, CISOs, and CIOs (June 17, 2026; enterprise leadership sample and vendor-sponsored). Open source

    17. State breach-notification laws. National Conference of State Legislatures, “Security Breach Notification Laws” (all 50 states and listed U.S. territories; requirements and definitions vary). Open source

  • Someone Is Inside Your Business Email. Here’s the First Hour

    OWNER BRIEF / COMPROMISED EMAIL

    READ FIRST. A hacked mailbox is where the costliest business-email fraud begins. Respond in the order below and you keep what can be kept; respond in the wrong order and you hand the attacker your recovery plan.

    A vendor calls and asks why an invoice your books show as paid is still unpaid. Accounts payable checks the wire. It went out days ago — to the bank the vendor's email said to use. Only later does someone look hard at that email. The change-of-bank notice came from a real employee's mailbox. A trusted employee appeared in the thread and confirmed it. Everyone followed the normal process, and the money is gone.

    A September 2026 briefing written by cyber-insurance attorneys describes the shape of the attack this way: criminals took over the company's own mailbox, read genuine payment communications, waited for a legitimate payment the company was about to make, then announced the banking change from inside that mailbox. They inserted a nearly identical email address for the trusted employee and created mailbox rules that moved their messages — and the responses — into an RSS subscriptions folder, where nobody had any reason to look.[1]

    I did not pick that story for the money. I picked it for the first sentence of the paragraph above — "read genuine payment communications." Nothing in it would have been fixed by changing a password. The takeover worked because of what the attacker did after getting in: reading your real conversations, concealing tracks with rules nobody checks, watching for the right payment. That is why order matters. A hacked mailbox is a crime scene, and you start there — not at the login screen.

    THE 30-SECOND TAKEAWAY

    A hacked mailbox is a crime scene, not a password problem. The order that holds up in every response playbook I trust: 1. If money moved — or payment instructions changed — call the bank first, before you touch anything else. 2. Lock the mailbox from a device you trust: reset the password, end all sessions, restart MFA enrollment. 3. Remove hidden rules, forwarding, connected apps, delegates, and unfamiliar recovery methods. 4. Save the evidence. 5. Warn the people who might receive fraudulent follow-ups. 6. Report the crime. And plan around this reality: while the mailbox is compromised, the attacker may be reading your response. Coordinate aloud or by phone, not by email.

    How expensive a hacked inbox gets

    ■ Business email compromise is the expensive fraud. The FBI's 2025 Internet Crime Report logged 24,768 business email compromise complaints and $3.05 billion in reported losses, averaging above $123,000 per complaint. Those are reported losses; many incidents never become complaints.[5]

    ■ Mailbox takeovers are now industrial. In September 2026, Microsoft took down EvilTokens, an AI-powered criminal service tied to more than 12,000 compromised inboxes across more than 10,000 organizations — with victims in financial services, healthcare, construction, real estate, wholesale distribution, and higher education. Microsoft seized 50 websites and disabled more than 150 supporting domains; two men were arrested in the U.K.[4]

    ■ Stolen credentials remain the starting point. Verizon's 2026 Data Breach Investigations Report counted 7,152 confirmed breaches in its small- and medium-sized business dataset (organizations with fewer than 1,000 employees); credentials were compromised in 31%, and phishing appeared in 9% of recorded initial-access paths.[6]

    ■ Fast reporting keeps money recoverable. In September 2026, the U.S. Attorney's Office in Iowa announced roughly $375,000 recovered from a business email compromise scheme that had cost an Iowa company more than $800,000 in 2022. The U.S. Attorney's message was direct: "If you or your company are targeted by one of these scams, report it to your bank, to law enforcement, and to the FBI's Internet Crime Complaint Center."[7]

    A customer once told me, after an incident, that he thought "cyberattack" meant a laptop with a ransom note. A hacked mailbox is cheaper for the criminal and more useful than any locked laptop. It comes with your real conversations, your real contacts, and your real authority. The response below assumes that starting position.

    First, make sure it's your mailbox — not just your name

    Not every weird email from your address means your mailbox was breached. Criminals can spoof a sender — forge the "from" line so a message looks like it came from you — without ever getting inside. Check where the evidence lives:

    ■ If your mailbox is clean — no sent items you didn't send, no rules or forwarding you didn't create, no password or recovery changes — spoofing is the likely answer. The fix is a domain problem: SPF, DKIM, and an enforced DMARC policy tell receiving servers to distrust mail that claims to be from your domain but isn't. That is a call to whoever manages your domain, not a response incident.

    ■ If you find any of the following, treat it as a takeover until proven otherwise: sent items you didn't send; inbox rules you didn't create; external forwarding you didn't turn on; messages missing or deleted without explanation; changed account contact details; repeated lockouts or forced password changes; a signature that appeared on its own; or the mailbox being blocked for sending spam. That is Microsoft's symptom list, substantially as published.[2]

    Google's recovery guidance adds the other half of the check for Gmail and Google Workspace: review recent security events, review which devices are signed in, and verify that the recovery phone number and recovery email are yours.[3]

    One honest caution: a rule can exist silently. Attackers create rules with innocent names and sometimes rules that don't even show where you look first. If you suspect a takeover but find nothing visible, that is a job for your IT provider's mailbox audit — not a verdict of "probably fine." Keep anything you do find; Microsoft session and audit logs are easiest to save while they're fresh.[11]

    PHASE BY PHASE

    The response, in the right order

    Money first. Then lockout. Then the places attackers hide. Then evidence and reporting.

    The first hour: stop the bleeding

    This is the order I would execute if this were my mailbox.

    ☐ STEP 1 Call the bank first — before everything — if money moved or payment instructions changed.

    Call the wire or fraud desk (use the number in your own records, not one from the email), ask to recall or freeze the transfer, and ask about notifying the receiving bank. The FBI's business email compromise guidance and Google's hacked-account guidance both name bank contact as an immediate step, and a federal court in Pennsylvania held in August 2026 that a business that lost $1.4 million was in the best position to prevent its own loss — a phone call verifying the new account would have done it.[10] Reach the bank in minutes, and some of the loss may still be recoverable.

    ☐ STEP 2 Lock the account from a device you trust.

    Reset the password — Microsoft recommends disabling the account during the investigation and explicitly warns not to send the new password by email, since the attacker may still read the mailbox. Update app passwords too, which Microsoft says are not automatically revoked by a password reset.[2] Resetting the password alone is not enough: end all active sessions, since a password change does not always sign the attacker out. For Google, sign out every device you don't recognize in the security panel.[3]

    ☐ STEP 3 Restart MFA rather than trusting what is there.

    Review the registered MFA devices and methods, remove anything unfamiliar — the attacker may have enrolled something of theirs — and re-enroll the user's method. Where available, prefer an authenticator app, passkey, or hardware key over one-time codes. If the account is reused across services, change every one of those passwords; attackers use breached credentials like spare keys.[2]

    ☐ STEP 4 Sweep the places attackers hide.

    This is the step most likely to be skipped, and it is the one that decides whether the mailbox is clean or merely quiet. Clear every hidden inbox rule and external forwarder, revoke connected applications (attackers grant malicious apps persistent access that survives a password change), remove mailbox delegates you don't recognize, check recovery email and phone, and review the administrative roles on the account.[2] Coordinate by phone or in person — assume the mailbox is reading your response emails.[11]

    The sweep is the difference between "we changed the password" and "they're out." I would not declare the first hour finished until someone can tell me — in writing — what the sweep found and what was removed. "We looked" is not a report.

    The first day: preserve evidence before retention deletes it

    Once the attacker is out, resist the urge to clean everything up. What you preserve in the next 24 hours is what proves — to law enforcement, to the bank, to the insurer — that this was an unauthorized takeover of a legitimate account, not an employee mistake.

    ☐ STEP 1 Export the evidence that proves the takeover.

    Save the original fraudulent messages with full headers when available, the complete email chain, any substituted bank instructions alongside the originals, and screenshots of the malicious rules and forwarding settings before you delete or disable them. Attorneys who handle cyber-insurance claims say the evidence worth preserving is what proves four points: criminals entered a real company account, they manipulated data inside the payment process, the company intended to make a legitimate payment, and employees were following a normal process the criminals exploited.[1] Keep a simple timeline — what happened, when, and who acted — in the same file.

    ☐ STEP 2 Save the logs that show the attacker's footprint.

    Microsoft's response playbook points to the sign-in logs, audit logs, and recent activity — the IP addresses, locations, times, and new mailbox activity covering the compromise window — plus a message trace of what the attacker actually sent from the mailbox.[2] Log retention is finite. Export before it rotates.

    ☐ STEP 3 List everyone who received fraudulent mail.

    The message trace is also how you find the blast radius: who got invoices, "payment change" notices, or reply-to redirects from your address. You will need that recipient list when you warn them — and that warning should go through a different channel than the compromised mailbox.

    ☐ STEP 4 Learn how the attacker came in, and close that door.

    The usual doors are a stolen or reused password or a malware-infected device. If the email password was reused anywhere else — banking, accounting, payroll, suppliers — Google's own guidance says to change every one of those accounts immediately, including sites reached through the email address and saved passwords tied to it.[3] If a device looks infected, disconnect it from the network and get qualified help before reconnecting it. Guessing the door and acting are better than a perfect diagnosis that arrives next week — but you still want the diagnosis.

    ☐ STEP 5 Brief your staff in person.

    One message: payments, bank-detail changes, and anything financial from the affected account are frozen until cleared. No one forwards the fraudulent messages "to investigate" and nobody tries a creative fix of their own.

    Small businesses do post about this publicly, and the pattern above shows up in those warnings. One real example: Affordable Plumbing Solutions posted on September 16, 2026 that a hacked email account had sent false invoices in its name. Owner reports are anecdotal, not breach statistics — but they confirm that the published guidance and the lived failure match.[8]

    The first week: warn, report, close the door

    ☐ STEP 1 Warn everyone in the blast radius.

    Contact the customers, vendors, and partners who received or could receive fraudulent mail — through a trusted channel different from the compromised mailbox. The message is simple: our mailbox was taken over during this window; treat any payment-instruction change from us in that window as fraudulent; call us at a known number to confirm anything outstanding.

    ☐ STEP 2 File the reports.

    Submit a complaint to the FBI's Internet Crime Complaint Center at IC3.gov — it's the federal clearinghouse for business email compromise and the reason money is sometimes recoverable later.[7] [9] Report to local law enforcement with your evidence file. And notify your cyber insurer promptly under every potentially responsive policy — cyber, crime, fraud — with the same file. Here is the hard part: insurers sometimes dispute integrated attacks (mailbox takeover + payment redirection) by labeling them both "not computer fraud" and "not social engineering." Legal counsel who handle these claims say your best counterweight is the documented attack record: unauthorized access, manipulated data, a legitimate obligation, a normal process.[1] That's what your evidence file is for.

    ☐ STEP 3 Finish the credential cleanup.

    Every reused password, every app tied to the email address, every session you didn't end in the first hour. Microsoft's playbook also recommends reviewing administrative roles and connected applications as part of the takeover response — a compromised account with admin rights is a second incident hiding inside the first.[2]

    ☐ STEP 4 Make this the last time.

    Enforce MFA on every mailbox, payroll, banking, and domain account; block or alert external auto-forwarding; enforce DMARC on the domain; document how sign-ins, new rules, delegates, and recovery changes get reviewed. A hacked mailbox teaches the same lesson every prevention plan promises: block the cheap paths and write down who watches them.

    If the attacker viewed or copied customer or employee data — not just money — your notification duties depend on what was touched and where those people live. That's a conversation with qualified counsel or your insurer's breach-response team, not a guess.[1]

    THREE LINES FOR YOUR TEAM

    Put this in the onboarding packet, not the incident file. 1. If something looks wrong with the company email, say so immediately — "I clicked" is information, not a confession. 2. If money moved, the next call is the bank, and the call after that is the one that secures the mailbox. 3. The new password for a compromised account never travels through that mailbox — not in an email, not as a reply thread, not ever.

    Your IT provider should be able to prove they did all of this

    Articles on this site keep the same standard: managed does not mean verified. After an email compromise, "we handled it" should come with paperwork.

    What your IT provider should verify

    CONTROL

    ASK FOR PROOF

    Lockout proof

    When the account was disabled/blocked; sessions revoked; MFA re-enrolled

    Persistence sweep

    Hidden rules, forwarding, apps, delegates, recovery: list of found + removed

    Changed watch

    Sign-in logs and recovery-change alerts saved for the whole window

    Recipient tracking

    Message-trace output: fraudulent mail that went out and who got it

    Entry point

    How the attacker came in: verdict or verdict pending with evidence

    Reporting readiness

    Evidence archive and timeline ready for IC3, police, and insurer

    I am not asking you to run a security operations center. I am asking you to make the response visible after the fact. A lockout, a sweep, a recipient list, and a timeline are the evidence that a "we think it's clean now" never becomes.

    The bottom line

    A hacked inbox is where the costliest business email fraud usually starts. Not with a dramatic hack, but with a legitimate account, real conversations, and a quiet rule nobody checks.

    The order decides how much of the damage is recoverable. Call the bank before you fix the mailbox. Lock and uproot the persistence before you tidy up. Save the evidence before retention deletes it. Warn and report before the trail goes cold. After years of watching incidents, that order is the one part of the response I would never rearrange.

    Sources

    Accessed September 30, 2026. Statistics describe the cited source's dataset or reported complaints and should not be generalized beyond that scope.

    1. Hacked-mailbox payment-diversion scenario and insurance-coverage analysis. Cyber-insurance law briefing, "When Your Cyber Insurer Sends You in Circles: A Hacked CFO Email, a Stolen Vendor Payment, and the Coverage Maze That Can Follow" (September 3, 2026). Open source

    2. Official compromised-email-account response playbook. Microsoft Learn, "Responding to a Compromised Email Account" (Microsoft Defender for Office 365). Open source

    3. Official hacked-Google-Account recovery steps. Google Support, "Secure a hacked or compromised Google Account." Open source

    4. EvilTokens cybercrime-service takedown. Redmond magazine, "Microsoft Disrupts AI Platform Behind 12,000 Email Breaches" (September 23, 2026), reporting Microsoft's milestone post. Open source

    5. 2025 Internet Crime Report. FBI Internet Crime Complaint Center, 2025 Internet Crime Report (published April 2026). Open source

    6. Small-business breach data. Verizon, 2026 Data Breach Investigations Report, pp. 97-98. Open source

    7. Iowa BEC fraud-proceeds recovery. U.S. Attorney's Office for the Northern District of Iowa, "United States Recovers $375,000 in Fraud Proceeds from a Business Email Compromise Scam" (September 24, 2026). Open source

    8. Small-business owner warning. Affordable Plumbing Solutions public warning that a hacked email account sent false invoices (September 16, 2026; archived page). Open source

    9. Business-email-compromise guidance. FBI Internet Crime Complaint Center, "Business Email Compromise: The $26 Billion Scam" (April 6, 2020). Open source

    10. Bank duty-of-care and verification-rationale decision. LexBlog, "Banks Do Not Owe a Duty of Care to Non-customers in Business Email Compromise and Wire Fraud Cases" (September 23, 2026), reporting Frontline Fabrics, Inc., E.D. Pa. (August 2026). Open source

    11. Email-recovery guide for businesses. Guardian Digital, "Email Recovery Guide — What to Do After Your Account is Compromised." Open source

    Independent guidance for practical small-business defense.