ACTIVE INCIDENT RIGHT NOW? Gridisys 24/7 emergency triage — £0 first 15 minutes.
24/7 EMERGENCY INCIDENT RESPONSE · UK

Your Email Inbox Has Been Hacked. What now.

Business Email Compromise is the highest-cost cyber crime against UK businesses by value, according to the FBI and Action Fraud. The attacker isn't after your data — they're after a fraudulent payment or access to your customers. Stop the payment, then stop the access. Here's what to do in the first 4 hours.

We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.

YOU MAY HAVE SEARCHED

"my Outlook has been hacked business""my email has been compromised UK""supplier says they didn't send the invoice""we paid an invoice to the wrong bank""malicious Inbox rule detected""OAuth app granted to attacker""someone is reading my mailbox"

Do these 4 things in the next 10 minutes

  1. 1

    If you've paid a fraudulent invoice — call your bank's fraud team NOW. UK Faster Payments can sometimes be reversed within the same working day if you act in time. Tell them you're a victim of APP fraud and ask for the Contingent Reimbursement Model (CRM) to be considered.

  2. 2

    Block the compromised account from the Microsoft 365 / Entra admin console — disable sign-in. Don't reset the password yet — coming-in sessions and Inbox rules give us evidence. Just disable sign-in for now.

  3. 3

    Check for malicious Inbox rules in the affected mailbox. The classic compromise hides these rules under names like '...' or 'RSS feeds'. Any rule that auto-forwards or auto-moves to a hidden folder is suspect — especially to a folder the user never uses.

  4. 4

    Revoke any suspicious OAuth app grants via the Entra admin console — Enterprise Applications / User settings. An attacker-granted app (often imitating 'Microsoft' or 'Adobe') retains mailbox access after a password reset.

BEC cost UK businesses over £350m in 2024 alone — more than ransomware by total value. Mailbox takeovers usually begin with a phishing link, then a hidden Inbox rule that hides the attacker's activity. The fix path is well-trodden.

What we do — the Gridisys incident timeline

From the moment you engage, within fixed-price limits.

First 4 hours

Containment (Hours 0-4)

  • Block the compromised mailbox sign-in.
  • Mailbox audit log search — look for items accessed, mail-items accessed, send-as events over the prior 30-90 days (Microsoft keeps extended audit logs if you have the right licensing).
  • Identify what the attacker did: read mail, set Inbox rules, granted OAuth app privileges, sent fraudulent mail, exported contacts/calendar.
  • Kill any active sessions from the Entra admin console.
  • Contact your bank if a payment has been made (this can run in parallel).
Day 1

Scoping & ICO threshold (Hours 4-24)

  • Identify exactly what was in the mailbox — not just contact data, but invoices, contracts, special-category correspondence, employment references.
  • Identify any supplier bank-change requests the attacker may have sent pretending to be you — your business is now a phishing vector for your suppliers.
  • Make the ICO Article 33 decision. Mailbox compromise exposing personal data is typically 'risk to individuals' — notification is usually required.
  • Decide on Article 34 high-risk customer communication: if the attacker sent mail to your customers pretending to be you, you may need to advise customers directly.
First week

Eradication & hardening (Days 2-7)

  • Reset password AND revoke active sessions (not just password reset).
  • Remove all malicious Inbox rules, OAuth grants, mailbox delegates, and forwarding addresses.
  • Reset ALL admin and privileged accounts — BEC attackers often move to admin mailboxes after their first foothold expires.
  • Enable Defender for Office 365 policies: Safe Links, Safe Attachments, anti-phishing, plus mailboxes in priority-account protection.
  • Conditional access: require MFA for all sign-ins, block legacy auth, restrict access by country / device state.
Weeks 1-4

Recovery & supplier communication

  • Contact any supplier whose bank details were changed by the attacker — they may be sitting on a fraud in the other direction.
  • Notify customers who received attacker-controlled mail — they may have made payments they don't yet know are fraudulent.
  • Lodge Action Fraud report — UK cyber crime reporting (separate from the ICO).
  • Submit ICO 1-month update if new facts emerged.
  • Optional: ongoing Gridisys managed SOC monitoring of the affected mailbox and Entra ID signs.

What it costs

A Gridisys BEC triage + containment engagement is fixed-price — mailbox audit, malicious rule removal, OAuth grant review, and the ICO decision. Full incident response (incl. ICO submission, supplier/customer communications, supplier-side recovery coordination) is scoped to your situation. The initial 15-minute triage call is free — and if you've just made a fraudulent payment, please mention that on the form so we can advise on bank action immediately. Contact us for a tailored quote.

Full pricing breakdown

What we cover

Microsoft 365 / Entra ID mailbox takeover (Exchange Online, Outlook)
Google Workspace Gmail compromise — Workspace admin, OAuth app abuse
Malicious Inbox rules — hidden folders, auto-forward, auto-delete
OAuth application abuse — fake 'Microsoft' / 'Adobe' / 'Reader' apps granted consent
Supplier invoice fraud — attacker used your mailbox to send bank detail changes to a supplier
Director impersonation / CEO fraud — fake 'CEO' email to finance team requesting urgent payment
ICO Article 33 decision (mailbox compromise is typically reportable)
Action Fraud / National Cyber Crime Unit reporting
Bank-fraud coordination — APP fraud recovery under the Contingent Reimbursement Model

Frequently asked questions

Talk to us now

The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.