How to recognise and respond to a suspected compromised email account in Microsoft 365
Summary
This guide helps you troubleshoot and resolve: How to recognise and respond to a suspected compromised email account in Microsoft 365. Follow the steps below to fix the issue.
Common Causes
Microsoft 365 accounts are a common target for cybercriminals because they often contain sensitive business data and provide a gateway to other connected services. A compromised mailbox can lead to stolen data, fraudulent invoices, and unauthorised access to your wider organisation. Acting quickly is essential to limit damage and restore security. This guide explains how to recognise the warning signs of a hacked account and the immediate steps you should take to contain the breach before reporting it to 220 Internet Services for remediation.
Warning Signs of a Compromised Account
Before taking action, confirm that something is actually wrong. Common indicators include:
- Recipients informing you that they have received suspicious or unexpected emails from your address.
- Emails in your Sent Items folder that you did not send.
- Login alerts from Microsoft about sign-ins from unfamiliar locations or devices.
- Rules you did not create appearing in your mailbox, especially rules that automatically forward, delete, or move messages.
- Inability to sign in, or your password suddenly not working.
- Unexpected changes to your recovery email or phone number.
- Outbound bounce-back messages (NDRs) for emails you never sent.
Quick Fix Steps
- Change your Microsoft 365 password immediately.
- Sign out of all active sessions across every device.
- Enable multi-factor authentication (MFA) if it is not already active.
- Review and remove suspicious inbox rules and forwarding settings.
- Check your recent sign-in activity for anything unfamiliar.
- Open a support ticket with 220 Internet Services so we can complete a full remediation.
Detailed Instructions
Step 1: Change Your Password
Use a strong, unique password that you have not used elsewhere. Avoid simple variations of your old password.
- Sign in at
https://myaccount.microsoft.com. - Select Security from the left-hand menu.
- Choose Password security.
- Follow the prompts to create a new password. Aim for at least 14 characters, including a mix of upper and lower case letters, numbers, and symbols.
- Save the change and sign out of any browser session you currently have open.
Step 2: Revoke All Active Sessions
Signing out everywhere ensures the attacker loses access even if they still hold an old session token.
- Go to
https://myaccount.microsoft.comand sign in with your new password. - Select Security, then choose Sign out everywhere (or Revoke all sessions if available).
- Confirm the action when prompted.
You will need to sign back in on each of your own devices, including your phone, Outlook desktop, and any other apps that connect to your mailbox.
Step 3: Enable Multi-Factor Authentication
MFA is the single most effective control against account takeover. If it is not already turned on, enable it now.
- Navigate to
https://myaccount.microsoft.com. - Select Security, then Advanced security options.
- Under Two-step verification, choose Turn on.
- Follow the prompts to register an authenticator app (such as Microsoft Authenticator) or a phone number.
- Save the recovery code provided in a secure location.
Step 4: Review and Remove Suspicious Inbox Rules
Attackers frequently create rules that hide their activity by automatically moving or deleting replies and forwarding your mail to an external address.
- Sign in to Outlook on the web at
https://outlook.office.com. - Click the gear icon (Settings), then choose Mail > Rules.
- Review every rule listed. Pay particular attention to rules that:
- Forward mail to an address you do not recognise.
- Move messages containing words like "invoice", "payment", or "bank" to a folder you did not create.
- Delete or mark as read messages from specific senders.
- Select any suspicious rule and click the trash icon to delete it.
- Repeat the process under Forwarding and IMAP (within Mail settings) to confirm no external forwarding is configured.
Step 5: Check Recent Sign-In Activity
Reviewing your sign-in log helps confirm the scope of the breach and identify which sessions need to be revoked.
- Go to
https://myaccount.microsoft.com. - Select Security, then Sign-in activity.
- Look for entries from unfamiliar cities, countries, IP addresses, or devices.
- Select any entry that looks suspicious and choose Secure your account.
Step 6: Scan Your Devices for Malware
A compromised mailbox is sometimes the result of malware on your computer that captured your password. Run a full scan on any device you use to access email.
- Windows: Open Windows Security, select Virus & threat protection, then choose Full scan.
- macOS: Use a reputable antivirus product and ensure your operating system is fully updated.
- Mobile: Confirm no unknown device management profiles or apps have been installed.
Step 7: Notify Contacts and Report the Incident
Once the immediate threat is contained, warn anyone who may have received fraudulent messages from your account. Then report the incident to 220 Internet Services so we can complete a full review of your tenant, including audit logs, mailbox forwarding, and any other accounts the attacker may have touched.
- Send a brief message to your regular contacts advising them to ignore any suspicious emails received recently from your address.
- Open a support ticket at app.220.com.au with the subject "Suspected compromised Microsoft 365 account".
- Include the approximate time you first noticed the issue and any actions you have already taken.
Troubleshooting
I cannot change my password
If the attacker has already changed your recovery details, the self-service password reset will fail. Open a ticket immediately and we will work with Microsoft to verify your identity and restore access.
MFA prompts keep appearing after I have secured the account
Revoke all sessions again and remove any unknown authenticator app registrations under Advanced security options in your Microsoft account. If prompts continue, contact us so we can review your tenant authentication policies.
Mail is still being forwarded externally
An attacker may have added forwarding at the tenant level rather than inside your individual mailbox. Our support team can audit and remove tenant-wide forwarding rules and review any connected apps or OAuth grants that may be silently exfiltrating your mail.
I am still receiving sign-in alerts after securing the account
Some legacy applications and mobile devices cache credentials and continue to retry sign-in attempts using the old password. Revoke all sessions again, remove any unknown app registrations under Apps and services that can access your data, and update the password on every device that connects to your mailbox.
How long does remediation take?
Initial containment steps can usually be completed within a few hours. A full tenant audit, including review of unified audit logs, mailbox forwarding, and connected applications, typically takes one to two business days once a ticket is opened.
Still Having Issues?
💻 Open a Ticket