Your Email Inbox Has Been Hacked. What now.
Business Email Compromise is the highest-cost cyber crime against UK businesses by value, according to the FBI and Action Fraud. The attacker isn't after your data — they're after a fraudulent payment or access to your customers. Stop the payment, then stop the access. Here's what to do in the first 4 hours.
We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.
YOU MAY HAVE SEARCHED
Do these 4 things in the next 10 minutes
- 1
If you've paid a fraudulent invoice — call your bank's fraud team NOW. UK Faster Payments can sometimes be reversed within the same working day if you act in time. Tell them you're a victim of APP fraud and ask for the Contingent Reimbursement Model (CRM) to be considered.
- 2
Block the compromised account from the Microsoft 365 / Entra admin console — disable sign-in. Don't reset the password yet — coming-in sessions and Inbox rules give us evidence. Just disable sign-in for now.
- 3
Check for malicious Inbox rules in the affected mailbox. The classic compromise hides these rules under names like '...' or 'RSS feeds'. Any rule that auto-forwards or auto-moves to a hidden folder is suspect — especially to a folder the user never uses.
- 4
Revoke any suspicious OAuth app grants via the Entra admin console — Enterprise Applications / User settings. An attacker-granted app (often imitating 'Microsoft' or 'Adobe') retains mailbox access after a password reset.
What we do — the Gridisys incident timeline
From the moment you engage, within fixed-price limits.
Containment (Hours 0-4)
- ▸Block the compromised mailbox sign-in.
- ▸Mailbox audit log search — look for items accessed, mail-items accessed, send-as events over the prior 30-90 days (Microsoft keeps extended audit logs if you have the right licensing).
- ▸Identify what the attacker did: read mail, set Inbox rules, granted OAuth app privileges, sent fraudulent mail, exported contacts/calendar.
- ▸Kill any active sessions from the Entra admin console.
- ▸Contact your bank if a payment has been made (this can run in parallel).
Scoping & ICO threshold (Hours 4-24)
- ▸Identify exactly what was in the mailbox — not just contact data, but invoices, contracts, special-category correspondence, employment references.
- ▸Identify any supplier bank-change requests the attacker may have sent pretending to be you — your business is now a phishing vector for your suppliers.
- ▸Make the ICO Article 33 decision. Mailbox compromise exposing personal data is typically 'risk to individuals' — notification is usually required.
- ▸Decide on Article 34 high-risk customer communication: if the attacker sent mail to your customers pretending to be you, you may need to advise customers directly.
Eradication & hardening (Days 2-7)
- ▸Reset password AND revoke active sessions (not just password reset).
- ▸Remove all malicious Inbox rules, OAuth grants, mailbox delegates, and forwarding addresses.
- ▸Reset ALL admin and privileged accounts — BEC attackers often move to admin mailboxes after their first foothold expires.
- ▸Enable Defender for Office 365 policies: Safe Links, Safe Attachments, anti-phishing, plus mailboxes in priority-account protection.
- ▸Conditional access: require MFA for all sign-ins, block legacy auth, restrict access by country / device state.
Recovery & supplier communication
- ▸Contact any supplier whose bank details were changed by the attacker — they may be sitting on a fraud in the other direction.
- ▸Notify customers who received attacker-controlled mail — they may have made payments they don't yet know are fraudulent.
- ▸Lodge Action Fraud report — UK cyber crime reporting (separate from the ICO).
- ▸Submit ICO 1-month update if new facts emerged.
- ▸Optional: ongoing Gridisys managed SOC monitoring of the affected mailbox and Entra ID signs.
What it costs
A Gridisys BEC triage + containment engagement is fixed-price — mailbox audit, malicious rule removal, OAuth grant review, and the ICO decision. Full incident response (incl. ICO submission, supplier/customer communications, supplier-side recovery coordination) is scoped to your situation. The initial 15-minute triage call is free — and if you've just made a fraudulent payment, please mention that on the form so we can advise on bank action immediately. Contact us for a tailored quote.
Full pricing breakdownWhat we cover
RELATED INCIDENT RESPONSE GUIDES
Frequently asked questions
Talk to us now
The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.