News Details

Business Email Hacked? How Attackers Get In and What to Do Immediately

Business Email Hacked? How Attackers Get In and What to Do Immediately

A business email hacked or compromised by an attacker can become much more than an email problem. A criminal who gains access to a company mailbox may be able to read confidential conversations, impersonate employees, reset passwords for other services, create hidden forwarding rules or attempt to redirect payments.

One of the most dangerous aspects of an email account compromise is that the victim may still be able to use the mailbox normally. The attacker does not always change the password or lock the legitimate user out.

Instead, they may try to remain unnoticed while monitoring conversations or forwarding selected messages elsewhere.

If you suspect that a business email account has been compromised, speed matters. This guide explains the warning signs, common ways attackers get access, what you should check immediately and how businesses can reduce the risk of another incident.

How Do You Know If a Business Email Has Been Hacked?

An attacker does not always leave an obvious sign. In some cases, the first indication is a customer asking about a strange message or an employee noticing that emails are missing.

Warning signs can include:

  • Emails in Sent Items that the user did not send.
  • Messages unexpectedly disappearing from the Inbox.
  • Unknown forwarding addresses.
  • Unfamiliar inbox or filtering rules.
  • Unexpected password reset messages.
  • Login alerts from unfamiliar devices or locations.
  • Customers receiving unusual payment instructions.
  • Colleagues receiving phishing messages from the legitimate company address.
  • Changes to the email signature, recovery information or account settings.
  • Unexpected account lockouts or repeated password changes.
  • New applications or integrations connected to the account.

Microsoft lists suspicious inbox rules, newly added external forwarding, unexplained deleted messages and suspicious sent messages among the indicators administrators should investigate when responding to a compromised Microsoft 365 mailbox.

The Hidden Email Forwarding Attack

One particularly important warning sign is an email forwarding hack.

After gaining access to a mailbox, an attacker may create a rule that automatically forwards incoming messages to an external email address. The legitimate employee can continue receiving and sending email without realizing that someone else may also be receiving copies.

An attacker may also create more selective rules.

For example, a malicious rule could target messages containing terms related to invoices, payments or particular customers. Other rules may move selected messages to folders that the user rarely checks.

This can make the compromise difficult to notice.

Microsoft specifically warns that malicious inbox forwarding rules are commonly associated with phishing and business email compromise incidents.

What Is Business Email Compromise?

Business Email Compromise (BEC) is a type of fraud in which criminals abuse email accounts or impersonate trusted people and organizations to manipulate victims.

The attacker may pretend to be:

  • A company director.
  • An employee.
  • A supplier.
  • A customer.
  • An accountant.
  • A bank or financial contact.

The objective may be to steal information, obtain credentials or convince someone to transfer money.

A particularly dangerous situation occurs when the criminal has actually gained access to a real mailbox. They may be able to study genuine conversations, understand relationships between the parties and wait for an appropriate opportunity to intervene.

How Do Attackers Get Into Business Email Accounts?

There is no single method. Understanding the common entry points helps businesses improve their defenses.

1. Phishing

Phishing remains one of the most common methods of stealing credentials.

An employee may receive a message that appears to come from Microsoft, Google, a bank, courier, supplier or another trusted organization. The message directs the user to a fake login page designed to capture the email address and password.

Modern phishing messages can look convincing, so users should not rely only on spelling mistakes or poor design to identify them.

2. Password Reuse

If an employee uses the same password across multiple services, a breach of an unrelated website can create a risk for the company email account.

Attackers can test exposed username and password combinations against other services. This is one reason every important account should use a unique password.

3. Weak Passwords

Short, predictable or commonly used passwords are easier to attack.

Business email accounts should use strong, unique passwords and should not share credentials between employees.

4. Lack of Multi-Factor Authentication

A stolen password is much more dangerous when it is the only factor required to sign in.

Multi-factor authentication adds another layer of protection. Where available, businesses should consider stronger, phishing-resistant authentication methods for sensitive and administrative accounts.

5. Malicious or Compromised Applications

Not every attacker needs to keep using a stolen password.

A user may be tricked into authorizing a malicious application or granting permissions that allow access to account data. Businesses should therefore review connected applications and permissions when investigating suspicious activity.

6. Malware or an Infected Device

A compromised computer can expose credentials, browser sessions or other sensitive information.

If there is reason to believe the employee’s device is infected, changing the email password alone may not solve the underlying problem.

Business Email Hacked: What to Do Immediately

If you have reasonable evidence that an email account is compromised, treat it as a security incident rather than simply changing one setting.

Step 1: Change the Password

Change the password immediately to a new, strong and unique password.

Do not reuse a password from another account.

If the same compromised password was used elsewhere, those accounts should also be changed.

Step 2: Sign Out Existing Sessions

Changing the password is important, but administrators should also review active sessions and revoke suspicious or existing sessions where the platform provides that capability.

The objective is to remove access that may already have been established.

Step 3: Enable or Review Multi-Factor Authentication

If MFA is not enabled, enable it.

If it was already enabled, investigate rather than assuming the account could not have been compromised. Review registered authentication methods and remove anything the legitimate user does not recognize.

Step 4: Check Email Forwarding

Inspect the mailbox for automatic forwarding to external addresses.

Do not assume that forwarding is legitimate simply because the user can still see their incoming mail. Forwarding can be configured while leaving a copy in the original mailbox.

Step 5: Check Inbox Rules and Filters

Review every mailbox rule and filter.

Look particularly for rules that:

  • Forward messages externally.
  • Delete messages automatically.
  • Mark messages as read.
  • Move messages to unusual folders.
  • Hide messages related to invoices or payments.
  • Target specific senders or customers.

Remove unauthorized rules, but document suspicious settings first if the incident may require a formal investigation.

Step 6: Check Delegates and Mailbox Permissions

Verify that only authorized people have access to the mailbox.

Depending on the email platform, this can include mailbox delegation, shared mailbox permissions, “send as” access and other forms of delegated access.

Step 7: Review Recent Sign-In Activity

Review available security and authentication logs for unfamiliar devices, IP addresses, locations and sign-in patterns.

Remember that location information is not always precise. Mobile networks, VPNs and internet providers can make legitimate logins appear to originate from unexpected locations.

Use login information as evidence to investigate rather than treating a different city or country as automatic proof by itself.

Step 8: Review Connected Apps and Permissions

Look for applications, integrations or authorization grants that the user does not recognize.

Remove suspicious access and investigate how it was granted.

Step 9: Check Sent, Deleted, Junk and Other Folders

Attackers may send messages and then attempt to hide them.

Check Sent Items, Deleted Items, Junk, Archive and less commonly used folders for suspicious activity.

Also ask colleagues or customers whether they received unusual messages from the account.

Step 10: Check the User’s Computer and Devices

If malware, credential theft or session theft is suspected, inspect the devices used to access the account.

Changing a password while leaving an infected computer untouched can allow the security problem to continue.

What If the Attacker Changed Payment Instructions?

This should be treated as an urgent financial and security incident.

If fraudulent bank details or payment instructions may have been sent from the compromised account, contact affected customers, suppliers or financial institutions using a separate trusted communication method.

Do not rely on replying to the potentially compromised email conversation to verify payment information.

If money has already been transferred, contact the relevant bank or payment provider immediately. Depending on the circumstances and jurisdiction, law enforcement or other authorities may also need to be notified.

Check Whether Other Company Accounts Are Affected

One compromised mailbox may not be the full extent of an incident.

Investigate whether:

  • The same password was used on other accounts.
  • Other employees received the same phishing message.
  • Similar forwarding rules exist in other mailboxes.
  • Administrative accounts show suspicious activity.
  • Other company services were accessed using the compromised identity.
  • Files or cloud storage associated with the account were accessed.

This is particularly important when email accounts are connected to broader cloud environments such as Microsoft 365 or Google Workspace.

Gmail or Google Workspace: What Should You Check?

For Gmail and Google Workspace accounts, review the account’s security activity and Gmail configuration.

Important areas include:

  • Automatic forwarding.
  • Filters and blocked addresses.
  • Mail delegation.
  • “Send mail as” addresses.
  • POP and IMAP access.
  • Recovery information.
  • Signed-in devices.
  • Connected applications.
  • Recent security events.

Google specifically advises users who see forwarding they did not configure to change their password immediately and disable the unauthorized forwarding.

Microsoft 365: What Should You Check?

For Microsoft 365 environments, administrators should investigate more than the mailbox password.

Depending on the organization’s configuration and licensing, the investigation may include:

  • Sign-in activity.
  • Inbox and forwarding rules.
  • Mailbox forwarding settings.
  • Sent and deleted messages.
  • Authentication methods.
  • Active sessions.
  • Application permissions.
  • Mailbox permissions.
  • Security alerts.

Microsoft’s guidance for compromised mailboxes specifically identifies suspicious inbox rules and external forwarding as important indicators to investigate.

Do Not Delete the Evidence Too Quickly

There is a natural temptation to delete every suspicious message, rule and setting immediately.

Containment is important, but businesses should also preserve enough information to understand what happened.

Where appropriate, record:

  • Suspicious forwarding addresses.
  • Inbox rules.
  • Relevant login activity.
  • Approximate times of suspicious events.
  • Messages sent by the attacker.
  • Changes to account settings.
  • Potentially affected customers or suppliers.

This information can help determine the scope of the incident and may be important if financial fraud, data exposure or a formal investigation is involved.

How to Protect Business Email from Future Attacks

Once the immediate incident has been contained, address the weaknesses that allowed or increased the impact of the compromise.

Require Multi-Factor Authentication

MFA should be required for business email wherever possible, particularly for administrators and users with access to sensitive information.

Use Unique Passwords

Employees should not reuse their business email passwords on unrelated websites or personal services.

Protect Administrator Accounts

Administrative accounts deserve additional protection because compromising one privileged account may expose multiple users or systems.

Train Employees to Recognize Phishing

Technical controls are important, but employees should also know how to identify suspicious login pages, unexpected attachments, unusual payment requests and attempts to create urgency.

Monitor Forwarding and Inbox Rules

Unexpected external forwarding deserves attention. Organizations with appropriate administrative tools should monitor suspicious mailbox changes rather than waiting for users to notice them.

Keep Devices Secure

Operating systems, browsers and applications should be maintained and updated. Endpoint security should be appropriate for the organization’s risk and environment.

Use Email Authentication for Your Domain

Domain owners should correctly configure technologies such as SPF, DKIM and DMARC as part of their email security strategy.

These controls address domain authentication and spoofing risks. They do not replace strong account security, MFA or incident monitoring.

Business Email Security Is More Than Spam Filtering

Spam filtering is useful, but modern email security requires several layers.

A sensible business approach combines account protection, authentication, filtering, monitoring, endpoint security, user awareness and a documented response process.

The goal is not to assume that every attack can be prevented. Businesses should also be able to identify suspicious activity quickly and respond before a compromised account becomes a larger incident.

Frequently Asked Questions About Hacked Business Email

How can I tell if my business email has been hacked?

Possible signs include unfamiliar sent messages, unexpected forwarding rules, missing emails, unknown login activity, password changes, suspicious filters and customers receiving messages you did not send. No single sign proves compromise, so suspicious activity should be investigated systematically.

Can hackers forward my emails without me knowing?

Yes. If an attacker gains sufficient access to a mailbox, they may be able to configure forwarding or inbox rules. Depending on the configuration, the original user may continue receiving messages while copies are sent elsewhere.

Is changing my email password enough after a hack?

Not necessarily. You should also review active sessions, MFA methods, forwarding, inbox rules, connected applications, account permissions and the devices used to access the mailbox. The appropriate response depends on how the compromise occurred.

Can an email account still be compromised if MFA is enabled?

Yes. MFA significantly improves account security, but no single control eliminates every possible attack. Organizations should combine MFA with secure devices, monitoring, phishing awareness and appropriate account controls.

Should I contact customers after an email compromise?

If the attacker may have sent messages, changed payment instructions or accessed information affecting customers, suppliers or other parties, communication may be necessary. The appropriate response depends on what happened and any legal or contractual obligations that apply.

What should I do if money was sent because of a hacked email?

Contact the relevant bank or payment provider immediately using trusted contact information. Preserve evidence and consider reporting the incident to the appropriate authorities. Speed can be important in attempted payment fraud.

Suspect Your Business Email Has Been Compromised?

A compromised mailbox should not be treated as a simple password problem. Hidden forwarding rules, active sessions, malicious applications and other account changes can allow unauthorized access to continue or make it difficult to understand what information was exposed.

A proper investigation should identify how far the incident extends, remove unauthorized access and strengthen the account against another compromise.

Aekpani Networks provides information security services, IT support and infrastructure services for businesses in Pakistan, the UAE and international markets.

If you suspect unauthorized access to a company mailbox, unexpected email forwarding or other suspicious account activity, contact Aekpani Networks for technical assistance.

Published by Aekpani Networks.

Leave a comment

Your email address will not be published. Required fields are marked *

Aekpani Networks – Powering Your Digital Presence

Contact Info

Mon - Frd : 9:00 -18:00
+92 333 2223624
info@aekpani.net

Office Address

Karachi, Pakistan