What to Do When Your Email Account Is Compromised
Managed Cybersecurity • Incident Response • Threat Remediation • Human Firewall Security
Strategic Summary: An Email Account Compromise (EAC) is one of the quietest and most costly cybersecurity breaches a business can face. Security Specialist Jacques van der Merwe outlines a real-world case study revealing how threat actors maintain persistent access—and details the 6-step incident response framework required to fully secure corporate mailboxes.
The initial indicator of compromise was subtle: the attacker hijacked a corporate subscription service, switching the notification address to their own while leaving the client’s corporate card attached. The charges continued, but all receipt alerts were quietly redirected. It was a stealthy theft designed to fly under the radar for months.
Our incident response team intervened immediately. We secured the account, forced credential resets, and enforced Multi-Factor Authentication (MFA). But simply changing a password is never enough.
The Anatomy of a Business Email Compromise
Once a threat actor gains access to a corporate inbox, the critical question is not merely “How did they get in?” The more urgent question is: “What secondary footholds did they establish while inside?”
Adversaries routinely configure malicious inbox forwarding rules, register unauthorized OAuth applications, and add rogue authentication methods to maintain persistent access after a password reset occurs.
Beyond the mailbox itself, our investigation uncovered a critical external threat vector: the attacker had registered a lookalike domain (typosquatting) mimicking our client’s brand. This domain was prepared for follow-up spear-phishing and payment invoice fraud against their clients and suppliers.
What began as a single compromised subscription was, in reality, the staging phase of a coordinated financial fraud operation.
6-Step Incident Response Playbook for Email Breaches
When an email compromise is detected, organizations must execute a structured remediation process:
- 1. Secure the Account & Enforce MFA: Change credentials immediately from an uncompromised, clean device. Enforce Multi-Factor Authentication (MFA) across the entire identity tenant.
- 2. Revoke Persistent Active Sessions: A password reset does not invalidate existing OAuth tokens or active browser sessions. Force a complete session revocation across all devices to kick the attacker out.
- 3. Audit Inbox Rules & Delegation: Inspect mailbox settings for hidden forwarding rules, sweep rules, delegate permissions, and connected third-party applications created to exfiltrate mail silently.
- 4. Conduct Application & Exposure Forensics: Review connected SaaS platforms, cloud infrastructure, and financial subscriptions associated with the address. Alert banking partners if card data or payment approval flows were exposed.
- 5. Scan for External Threat Vectors: Check for lookalike domain registrations, unauthorized password reset attempts on external portals, and outbound phishing emails dispatched from the compromised account.
- 6. Implement Post-Incident Monitoring: Maintain elevated logging and active monitoring for 30–60 days. Attackers often attempt a secondary breach using data harvested during the initial intrusion.
“Resetting a password without auditing persistent session tokens, inbox forwarding rules, and lookalike domain registrations leaves the door open. True incident response addresses the entire attack chain.”
Building Resilience Before an Intrusion Occurs
No organization can guarantee that an email address will never face a phishing attempt. However, disciplined security controls prevent a single compromised mailbox from escalating into a catastrophic business event.
Strong identity management, strict conditional access policies, continuous log auditing, and professional oversight significantly reduce breach impact. Equally vital is cultivating user security awareness. Through structured Human Firewall Security Training, employees learn to recognize suspicious mailbox behaviors and report anomalies before financial loss occurs.
Our specialized Managed Cybersecurity team builds this rigorous investigation methodology into every incident we manage.
Is Your Corporate Identity Tenant Protected?
Ensure your Microsoft 365 or Google Workspace environment is resilient against advanced account takeover attempts:
- Conditional Access Rules: Enforce strict location, device health, and risk-based authentication policies for every login attempt.
- Automated Inbox Rule Auditing: Implement continuous monitoring to detect and alert on auto-forwarding rules created across tenant mailboxes.
- Domain Protection Services: Monitor global domain registries for typosquatting registrations targeting your brand identity.
