Discovering that someone else may have access to your business email is one of the more stressful situations a business owner can face. Acting quickly makes a significant difference to the outcome. Here is what to do first.
Change your password immediately
Do not wait. Log into your email account and change your password to something long and unique that you have never used anywhere else. If you need help choosing a secure password, see our guide on creating a strong password. If you cannot log in because the attacker has already changed your password, contact your IT support straight away. Every minute counts.
Check for forwarding rules
One of the first things attackers do is set up a rule that silently forwards copies of all your incoming emails to an address they control. This allows them to monitor your business communications for weeks without you knowing.
In Outlook, go to Settings, then Mail, then check Rules and Forwarding. Remove anything you did not set up yourself.
Look at your sent folder
Check whether any emails were sent from your account that you did not send. Attackers often use compromised accounts to send phishing emails or fake invoices to your contacts. If you find anything suspicious, let your key clients and suppliers know immediately.
Enable two-factor authentication
Once you have secured the account, enable two-factor authentication if it is not already active. This adds a second layer that stops an attacker from getting back in even if they somehow get your password again.
Call for help
A compromised email account is not always straightforward to clean up fully. Forwarding rules, delegated access and login history all need to be checked and this is not the time to miss something. If you are not confident handling it yourself, get professional help involved quickly.