website security

Business Email Hacked? What to Do in the First Hour

Business email hacked? Lock the account from a clean device, remove forwarding rules, warn customers the right way, and call your bank fast if money moved.

A customer calls to ask about an invoice you never sent. Or you open your mailbox and find a forwarding rule you did not create, or replies to messages you never wrote. If your business email was hacked, the worry is not really the inbox. It is the customer who may be about to pay a stranger's bank account, and the supplier who may already have received "new" payment details in your name. The good news is that the first hour follows a clear order, and you can start it yourself right now, from a device you trust. Lock the account first, then deal with the money, then warn the people who may act on a fake message. Every step below comes from Microsoft's and Google's own guidance and from the FBI and FTC. Start with the section that matches where you are, and keep going in order.

Key Takeaways

Lock the account, not just the password

Change the password from a clean device, sign out every session, remove unknown apps and app passwords, and turn on two-step verification. A new password alone can leave the attacker's forwarding rule running.

Call the bank first if money moved

The FBI says "time is of the essence." Ask your bank's fraud department for a recall, then file at ic3.gov. A recall is a request, not a guarantee.

Warn people from a separate channel

Tell customers and suppliers by phone or a fresh message, never by replying inside the hacked thread, and leave links out of the warning.

Stop the repeat with two habits

Two-step verification on every account, and a phone call to a known number before anyone changes payment details.

My business email was hacked. What do I do first?

Do these in order, from a computer or phone you trust. If you think the device you normally use may be infected, use a different one. Microsoft's own compromised account guidance starts with a malware scan before the password change for exactly this reason: a new password typed on an infected machine can be stolen again.

  1. Change or reset the password: Use a new password you have never used anywhere else. If you reused the old one on other accounts, change those too.
  2. Sign out every session: Force every device and app off the account, so an attacker who is already logged in gets thrown out.
  3. Turn on two-step verification: An authenticator app or a security key, not just a text message, where you can.
  4. Remove what keeps the attacker in: Forwarding rules, inbox filters, automatic replies, app passwords, connected apps you do not recognize, and any recovery phone number or email that is not yours.
  5. Check what was sent and what went missing: Look through Sent, Deleted, Archive, Spam and any folder you did not create.
  6. Call your bank now if any payment may have gone out: Do not wait until the account is clean.
  7. Warn the people at risk: Customers, suppliers and staff who may get or act on a fake message.
  8. Keep the evidence: Screenshots of rules, suspicious messages and sign-in records, before you delete anything.

If you do only one thing in the next ten minutes, make it steps 1 and 2 together. Changing the password without signing out the sessions leaves the door open for anyone who is already inside.

A closed laptop on a clean wooden desk beside a small brass padlock and a folded paper notepad with blank pages.
Lock the account from a device you trust before you do anything else.

How do I lock down Microsoft 365 or Google Workspace?

The steps are the same idea on both platforms, but the buttons live in different places. If you are the only person on the account, you can do nearly all of this from your own settings. If your business has an administrator, or you are the administrator, there are extra checks only an admin can run. The table puts the two side by side, and the sections under it add what matters for each.

First-hour steps, Microsoft 365 and Google Workspace
StepMicrosoft (Outlook, Microsoft 365)Google (Gmail, Google Workspace)
Before the passwordRun a full antivirus scan on the deviceUse a device you trust
PasswordChange or reset itChange it immediately
Sessions"Sign out everywhere" (can take up to 24 hours); admins revoke sessions and tokensRemove unfamiliar devices; run Security Checkup
Forwarding and rulesCheck forwarding, automatic replies and inbox rules, including hidden rulesCheck automatic forwarding and filters
Apps and accessCheck connected accountsRemove unfamiliar connected apps and app passwords
Two-step verificationTurn it onTurn it on; admins can enforce it
Admin reviewInspect inbox rules and sign-ins across usersReview Email Log Search and user activity
StepBefore the password
Microsoft (Outlook, Microsoft 365)Run a full antivirus scan on the device
Google (Gmail, Google Workspace)Use a device you trust
StepPassword
Microsoft (Outlook, Microsoft 365)Change or reset it
Google (Gmail, Google Workspace)Change it immediately
StepSessions
Microsoft (Outlook, Microsoft 365)"Sign out everywhere" (can take up to 24 hours); admins revoke sessions and tokens
Google (Gmail, Google Workspace)Remove unfamiliar devices; run Security Checkup
StepForwarding and rules
Microsoft (Outlook, Microsoft 365)Check forwarding, automatic replies and inbox rules, including hidden rules
Google (Gmail, Google Workspace)Check automatic forwarding and filters
StepApps and access
Microsoft (Outlook, Microsoft 365)Check connected accounts
Google (Gmail, Google Workspace)Remove unfamiliar connected apps and app passwords
StepTwo-step verification
Microsoft (Outlook, Microsoft 365)Turn it on
Google (Gmail, Google Workspace)Turn it on; admins can enforce it
StepAdmin review
Microsoft (Outlook, Microsoft 365)Inspect inbox rules and sign-ins across users
Google (Gmail, Google Workspace)Review Email Log Search and user activity

Microsoft 365 and Outlook

Microsoft's guidance is to scan the device, then change or reset the password, then check connected accounts, forwarding and automatic replies. Its sign out everywhere option logs the account out of other devices, and Microsoft notes it can take up to 24 hours to take full effect, so do not treat a quiet inbox in the first hour as proof the attacker is gone. If you have an admin, ask them to inspect inbox rules for every affected user, including hidden ones, and to revoke suspicious sessions or tokens. Microsoft's admin response steps cover this for business accounts.

Gmail and Google Workspace

Google's advice for suspicious activity on your account is to change the password right away, remove devices you do not recognize and complete Security Checkup. Then check automatic forwarding, filters, recovery options, connected apps and app passwords. For Workspace admins, Google's page on how to identify and secure compromised accounts says to review Email Log Search, remove app passwords the user created, check filters and forwarding, and turn on two-step verification. Once the account is contained, go back through sent, deleted and missing messages.

Why is the attacker still in after I changed the password?

Because the password was only one of the ways in. An attacker who got into your mailbox can leave things behind that keep working after the password changes: a signed-in session on their own device, an app you approved without realizing it, an app password, a recovery email they added, or a rule that quietly forwards your mail to them.

The forwarding rule is the one to hunt for. Microsoft's security team describes inbox manipulation rules that forward, delete or hide messages as a common sign of business email compromise. A rule that sends every message containing "invoice" or "payment" to an outside address, or moves a customer's replies straight to a folder you never open, lets the attacker watch your deals and keeps you from seeing the customer asking "is this new bank account right?"

So, after the password change, open your rules and filters and read every one. Delete anything you did not create, but take a screenshot first. Then remove connected apps and app passwords you do not recognize, and check that the recovery phone and email are yours.

Did money already go out? Call the bank now

If a customer paid an invoice that came from your hacked mailbox, or you paid a supplier after a "change of bank details" email, stop reading and call the bank that sent the money. Use the fraud number on the back of the card or on the bank's own website, not one from any email.

The FBI's Internet Crime Complaint Center puts it plainly: "time is of the essence." Its business email compromise warning tells victims to contact their financial institution immediately and request a recall. When you call, have ready:

  • The amount and date: Exactly what was sent and when.
  • The receiving bank and account: The details from the fake instructions.
  • The transaction reference: The wire or payment confirmation number.
  • The fake message: Keep it, with its headers, so the bank and investigators can see it.

Then file a complaint at ic3.gov, whatever the amount, with the full transaction details. The FBI says its Recovery Asset Team can work with banks and law enforcement to try to freeze funds. Contact local police as well when it fits your situation.

Be ready for a hard truth: a recall is a request, not a promise. The FBI's 2025 IC3 Annual Report says its recovery team handled 3,900 incidents in 2025 involving $1,163,919,846 in attempted theft, and froze $679,013,183 of it, a 58% success rate across all fraud types. That is money frozen, not a guarantee for any single case, and the report notes that banks have different policies. The one thing that clearly helps is speed.

A plain desk telephone with its handset resting on a blank legal pad next to a closed checkbook on a gray countertop.
If money moved, the call to your bank comes before anything else.

How does the fake invoice scam actually work?

Business email compromise is fraud that uses a hacked mailbox, a lookalike address or a spoofed sender to get a trusted person to send money or share information. With a hacked mailbox, the attacker does not need to guess. They read your real invoices and conversations, learn who pays whom and when, and wait.

Then they step into a genuine thread. A customer who has been emailing you for weeks gets a reply from your real address saying the bank details have changed. A supplier gets a note asking for an urgent wire, a payroll change, gift cards or cryptocurrency. Because the message sits inside a real conversation, it looks normal. The forwarding rule hides the customer's reply asking to confirm.

The scale is large. The FBI's 2025 IC3 Annual Report, released in April 2026, recorded 24,768 business email compromise complaints and $3,046,598,558 in reported losses for 2025, second only to investment fraud. The 2024 report recorded $2,770,151,146 the year before. These are losses people reported to the FBI, not a count of every loss, so the real total is unknown.

Reported business email compromise losses, FBI IC3
YearReported BEC lossesSource
2022$2,742,354,0492024 IC3 Annual Report
2023$2,946,830,2702024 IC3 Annual Report
2024$2,770,151,1462024 IC3 Annual Report
2025$3,046,598,558 (24,768 complaints)2025 IC3 Annual Report
Year2022
Reported BEC losses$2,742,354,049
Source2024 IC3 Annual Report
Year2023
Reported BEC losses$2,946,830,270
Source2024 IC3 Annual Report
Year2024
Reported BEC losses$2,770,151,146
Source2024 IC3 Annual Report
Year2025
Reported BEC losses$3,046,598,558 (24,768 complaints)
Source2025 IC3 Annual Report

Is my account hacked, or is someone faking my address?

It matters which one you have, because the fix is different. A spoofed message only looks like it came from you. The attacker forged the sender line, and the message may never have touched your mailbox. A hacked mailbox means someone actually logged in.

A hacked mailbox usually leaves marks you can find: sign-ins you do not recognize, sent messages you did not write, rules or filters you did not create, apps you did not approve, or missing mail. If you find none of that, and the fake messages come from an address that is one letter off from yours, you may be dealing with spoofing or a lookalike domain instead.

Spoofing is fixed mainly on your domain's email settings, with SPF, DKIM and DMARC, which the next section covers. A hacked mailbox is fixed by locking the account as described above. If you cannot tell which you have, treat it as a hacked mailbox until the sign-in records say otherwise.

Who do I need to tell, and how fast?

Tell your email provider or administrator right away, so they can check other accounts and lock things down on their side. Keep copies of the suspicious messages, their headers, sign-in records, the rules you found and any payment instructions before you delete anything.

Customers, suppliers and staff

Warn anyone who may get a fake message from you, as soon as there is a real chance it happened. Do it by phone or a brand-new message from a clean account, never by replying in the thread the attacker used. The FTC's advice on business email imposters is to tell customers quickly when scammers are using your name, and to leave hyperlinks out of the warning. Keep it short: your email was compromised, do not act on any payment change that came by email, and call a number they already have for you to confirm.

Bank, FBI and police

If any payment moved, the bank call and the IC3 complaint from the section above come first. If you have cyber insurance, let your insurer know as well.

State breach notice

Whether you have a legal duty to notify goes beyond the email itself. It depends on your state, what kind of personal information was in the mailbox, where the affected people live, and whether that information was actually accessed. The sources behind this post give no single deadline that covers every state. If customer personal information may have been exposed, talk to a lawyer before you decide.

A manila folder holding a neat stack of blank printed pages, with a paper clip and a pencil resting on top, on a light oak table.
Save the messages, rules and sign-in records before you delete anything.

What stops this from happening again?

Two habits close the gaps this attack depends on, and neither needs to cost much. The first is two-step verification on every mailbox, every admin account and every bank and payment account. Authenticator apps are often free, and they are stronger than text messages. Security keys are stronger still and cost the price of the device. Two-step verification raises the bar a long way, though it does not make a break-in impossible, which is why the second habit matters.

The second is a payment rule that everyone follows: no change to bank details, and no urgent wire, goes through on the strength of an email. Someone calls the customer or supplier at a number already on file, never one from the message, and confirms it out loud. That single call breaks the fake invoice scam even when the mailbox itself has been compromised.

Then fix the domain side. Google's help on how to set up SPF and its recommended DMARC rollout walk through the order: publish SPF, turn on DKIM for every service that sends mail as you, then add DMARC in monitoring mode before moving slowly toward quarantine or reject. That makes it harder for someone to fake your address. It does not stop an attacker who has your real password, so treat it as the fix for spoofing, not a replacement for the lock-down steps.

If you would rather hand this part off, it is fair to know what you are paying for. Two-step verification is commonly included in business email plans, though features vary by plan, and SPF, DKIM and DMARC are settings in your domain and provider accounts. What costs money is someone's time to set it up, read the DMARC reports and check every account, and no one has published a standard price for that.

A small metal security key and a door key on a ring, lying beside a closed notebook on a dark slate surface.
Two-step verification and a phone check on payment changes stop the repeat.

When should I get outside help?

You can handle the first hour yourself, and you should start it now rather than wait for anyone. Outside help makes sense when you cannot tell whether the mailbox was actually hacked, when more than one account is involved, when payment or personal information may have been exposed, when the sign-in logs do not make sense to you, when something keeps coming back after you remove it, or when a device may be infected.

A good helper will tell you to call the bank and your provider first, then offer a review scoped to what the evidence shows. That review might cover every mailbox and admin account, connected apps, two-step verification for the whole team, SPF, DKIM and DMARC, and a written record for your bank or insurer. It will not get your money back, and it cannot promise that no one will ever try again.

Business email hacked: check your next move

Pick an answer to begin.

1. You changed your email password. Is the attacker definitely locked out?

2. A customer paid a fake invoice sent from your hacked mailbox an hour ago. What should happen first?

3. What is the safest way to warn customers?

Frequently Asked Questions About business email hacked

What should I do first if my business email was hacked?

From a device you trust, change the password, sign out every session, turn on two-step verification, and remove any forwarding rules, filters, app passwords and connected apps you do not recognize. If money may have moved, call the bank right away and ask for a recall.

Does changing the password get rid of the hacker?

Not always. Signed-in sessions, app passwords, connected apps, forwarding rules, filters and recovery settings can all keep working. Check each one after the password change.

Can my bank get back money sent to a scammer?

Ask for a recall immediately and file at ic3.gov. The FBI says time is of the essence and its team can work with banks to freeze funds, but recovery is not guaranteed.

Should I tell my customers my email was hacked?

Yes, as soon as there is a real chance they received a fake message. Use a phone call or a new message from a clean account, leave links out, and ask them to confirm any payment change by phone.

How do I know if my email was hacked or just spoofed?

A hacked mailbox usually shows unfamiliar sign-ins, sent messages you did not write, new rules or filters, or missing mail. If none of that appears, someone may be forging your address instead.

Will DMARC stop someone who hacked my mailbox?

No. DMARC helps other mail servers spot messages that fake your domain. It does not stop an attacker who logs in with your real password, so two-step verification is still needed.

Wrapping Up

When your business email is hacked, the order matters more than the tools. Lock the account from a clean device and sign out every session. Remove the rules and apps that keep an attacker inside. Call the bank the moment you think money moved, and file with the FBI. Then warn the people who might act on a fake message, from a channel the attacker cannot see.

After the first hour, the goal is making the next attempt fail. Two-step verification on every account, a phone check before any payment change, and SPF, DKIM and DMARC on your domain close the doors this kind of attack walks through.

If you want a second set of eyes once the urgent steps are done, Web Leveling can help. Our website security audit looks at the accounts, domain settings and access around your business, and we will tell you what we find and what we would fix first, even when that is something you can fix yourself. We work with small and medium businesses across the country and overseas. Tell us what happened to your email, and we will help you work out what to check next.

Terms

Email security words in this post

Tap a term to see what it means.

Business email compromise (BEC). Fraud that uses a hacked, faked or lookalike business email identity to trick someone into sending money or information.

Forwarding rule. A mailbox setting that sends copies of certain messages to another address, which attackers use to watch conversations.

Two-step verification. A second check, such as an app code or a security key, needed after the password to sign in.

App password. A separate password that lets an older app reach your mailbox, and can keep working after the main password changes.

Spoofing. Faking the sender line so a message looks like it came from your address without anyone logging in to your mailbox.

DMARC. A domain setting that tells other mail servers what to do with messages that fail your SPF and DKIM checks.

Recall. A request from your bank to the receiving bank to return or freeze a payment, which is not guaranteed to succeed.