Home › Knowledgebase › KB-466

How to recognise and respond to a suspected compromised email account in Microsoft 365

Summary

This guide helps you troubleshoot and resolve: How to recognise and respond to a suspected compromised email account in Microsoft 365. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Microsoft 365 accounts are a common target for cybercriminals because they often contain sensitive business data and provide a gateway to other connected services. A compromised mailbox can lead to stolen data, fraudulent invoices, and unauthorised access to your wider organisation. Acting quickly is essential to limit damage and restore security. This guide explains how to recognise the warning signs of a hacked account and the immediate steps you should take to contain the breach before reporting it to 220 Internet Services for remediation.

Warning Signs of a Compromised Account

Before taking action, confirm that something is actually wrong. Common indicators include:

If you suspect an active breach, do not delete suspicious emails. They are valuable evidence for our support team and Microsoft's investigation.

Quick Fix Steps

  1. Change your Microsoft 365 password immediately.
  2. Sign out of all active sessions across every device.
  3. Enable multi-factor authentication (MFA) if it is not already active.
  4. Review and remove suspicious inbox rules and forwarding settings.
  5. Check your recent sign-in activity for anything unfamiliar.
  6. Open a support ticket with 220 Internet Services so we can complete a full remediation.

Detailed Instructions

Step 1: Change Your Password

Use a strong, unique password that you have not used elsewhere. Avoid simple variations of your old password.

  1. Sign in at https://myaccount.microsoft.com.
  2. Select Security from the left-hand menu.
  3. Choose Password security.
  4. Follow the prompts to create a new password. Aim for at least 14 characters, including a mix of upper and lower case letters, numbers, and symbols.
  5. Save the change and sign out of any browser session you currently have open.
If your password is rejected or you cannot access the password change page, the attacker may have already changed your recovery details. Skip to Open a Ticket immediately so we can assist.

Step 2: Revoke All Active Sessions

Signing out everywhere ensures the attacker loses access even if they still hold an old session token.

  1. Go to https://myaccount.microsoft.com and sign in with your new password.
  2. Select Security, then choose Sign out everywhere (or Revoke all sessions if available).
  3. Confirm the action when prompted.

You will need to sign back in on each of your own devices, including your phone, Outlook desktop, and any other apps that connect to your mailbox.

Step 3: Enable Multi-Factor Authentication

MFA is the single most effective control against account takeover. If it is not already turned on, enable it now.

  1. Navigate to https://myaccount.microsoft.com.
  2. Select Security, then Advanced security options.
  3. Under Two-step verification, choose Turn on.
  4. Follow the prompts to register an authenticator app (such as Microsoft Authenticator) or a phone number.
  5. Save the recovery code provided in a secure location.
Never approve an MFA prompt you did not initiate. Attackers sometimes trigger push notifications hoping you will tap Approve by mistake. If you receive an unexpected prompt, change your password and report it.

Step 4: Review and Remove Suspicious Inbox Rules

Attackers frequently create rules that hide their activity by automatically moving or deleting replies and forwarding your mail to an external address.

  1. Sign in to Outlook on the web at https://outlook.office.com.
  2. Click the gear icon (Settings), then choose Mail > Rules.
  3. Review every rule listed. Pay particular attention to rules that:
    • Forward mail to an address you do not recognise.
    • Move messages containing words like "invoice", "payment", or "bank" to a folder you did not create.
    • Delete or mark as read messages from specific senders.
  4. Select any suspicious rule and click the trash icon to delete it.
  5. Repeat the process under Forwarding and IMAP (within Mail settings) to confirm no external forwarding is configured.

Step 5: Check Recent Sign-In Activity

Reviewing your sign-in log helps confirm the scope of the breach and identify which sessions need to be revoked.

  1. Go to https://myaccount.microsoft.com.
  2. Select Security, then Sign-in activity.
  3. Look for entries from unfamiliar cities, countries, IP addresses, or devices.
  4. Select any entry that looks suspicious and choose Secure your account.

Step 6: Scan Your Devices for Malware

A compromised mailbox is sometimes the result of malware on your computer that captured your password. Run a full scan on any device you use to access email.

Step 7: Notify Contacts and Report the Incident

Once the immediate threat is contained, warn anyone who may have received fraudulent messages from your account. Then report the incident to 220 Internet Services so we can complete a full review of your tenant, including audit logs, mailbox forwarding, and any other accounts the attacker may have touched.

  1. Send a brief message to your regular contacts advising them to ignore any suspicious emails received recently from your address.
  2. Open a support ticket at app.220.com.au with the subject "Suspected compromised Microsoft 365 account".
  3. Include the approximate time you first noticed the issue and any actions you have already taken.

Troubleshooting

I cannot change my password

If the attacker has already changed your recovery details, the self-service password reset will fail. Open a ticket immediately and we will work with Microsoft to verify your identity and restore access.

MFA prompts keep appearing after I have secured the account

Revoke all sessions again and remove any unknown authenticator app registrations under Advanced security options in your Microsoft account. If prompts continue, contact us so we can review your tenant authentication policies.

Mail is still being forwarded externally

An attacker may have added forwarding at the tenant level rather than inside your individual mailbox. Our support team can audit and remove tenant-wide forwarding rules and review any connected apps or OAuth grants that may be silently exfiltrating your mail.

I am still receiving sign-in alerts after securing the account

Some legacy applications and mobile devices cache credentials and continue to retry sign-in attempts using the old password. Revoke all sessions again, remove any unknown app registrations under Apps and services that can access your data, and update the password on every device that connects to your mailbox.

How long does remediation take?

Initial containment steps can usually be completed within a few hours. A full tenant audit, including review of unified audit logs, mailbox forwarding, and connected applications, typically takes one to two business days once a ticket is opened.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket