Email Hacked? — UK Email Account Compromise Response
If your email account has been hacked — emails sent to your contacts, suspicious autoforwarding, attackers reading your inbox, password no longer works, fraudsters trying to reset your bank login — we recover it within hours, not days. UK-based 24/7 incident response for Microsoft 365, Gmail, Outlook.com, Virgin Media, BT Internet and other UK email providers.
We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.
YOU MAY HAVE SEARCHED
Do these 4 things in the next 10 minutes
- 1
Try to log in. If the password no longer works, attacker has changed it — go to the provider's recovery flow (Google: myaccount.google.com / Microsoft: account.live.com / Virgin/BT: their help portal) and choose ' Forgotten password / account recovery'. Use a recovery email or phone you still control.
- 2
From a separate clean device, change the password on every account that uses this email address for password resets — bank, PayPal, credit card, HMRC, Companies House, AWS, social media, online shopping. Assume the attacker has read your inbox and knows what services you use.
- 3
If you can still log into the email account: check Inbox Rules / Filters / Forwarding (Gmail: Settings → Forwarding and POP/IMAP + Filters; Outlook: Rules; BT/Virgin/Yahoo: Settings → Filters). Look for unknown rules that autoforward to external addresses or auto-delete incoming mail on keywords like 'invoice', 'bank', 'password'. Delete any attacker rules.
- 4
Turn on 2-step verification / 2FA as soon as you regain access — Google: myaccount.google.com/security; Microsoft: account.microsoft.com/security; BT/Virgin via their help portal. SMS is OK short-term; an authenticator app is safer.
What we do — the Gridisys incident timeline
From the moment you engage, within fixed-price limits.
Triage + scoping (Hour 0-2)
- ▸Free 15-min triage call — which provider, how access was lost, what's already been tried
- ▸Identify likely attack vector — phishing link, password reuse, SIM-swap, malicious OAuth grant, reused password from a breached site
- ▸Check HaveIBeenPwned for the email address — find what password leaks it's already in
- ▸Walk the client through provider-level account recovery if they haven't done it yet
Recovery + attacker purge (Hour 2-6)
- ▸Regain access to the email account via provider recovery flow, with verification
- ▸Change password to a fresh random password (don't reuse a pattern from your other accounts)
- ▸Force-end all other active sessions (Gmail: Manage devices; Outlook: Recent activity; BT/Virgin: equivalents)
- ▸Purge every attacker rule and autoforward — check both Inbox rules and sweep rules, plus any connected third-party apps with mail read/send permission (OAuth grants)
- ▸Enable 2-step verification / 2FA — authenticator-app based, not SMS if possible
Blast-radius investigation (Hour 6-48)
- ▸Audit every password-reset email received in the last 30–90 days (sent folder + deleted items + spam) — identify which other accounts the attacker likely targeted
- ▸Identify which services used this email address for recovery: bank, HMRC, Companies House, AWS, PayPal, social media, online banking, share-trading platforms
- ▸Identify any BEC (Business Email Compromise) sent from the account — fraudulent supplier bank-change requests, fake invoices, executive impersonation
- ▸Identify any personal data exposed — clients, employees, suppliers whose personal data sat in the inbox (triggers UK GDPR / DPA 2018 ICO notification)
Re-secure + rollback (Day 2-7)
- ▸Change passwords on every account that used this email for recovery — bank, HMRC, pension, share-trading — using a password manager with random unique passwords
- ▸Replace recovery-email address + recovery-phone where possible (a fresh SIM is safer if a SIM-swap was likely)
- ▸Document what was sent/received during the breach window for the breach register / ICO submission
- ▸Set up a clean account alias / forwarding architecture if account reputation is contaminated (sender blacklist, spoofed domain, bounce-back loop)
ICO + Action Fraud + bank notifications (Day 1-7)
- ▸Assess whether personal data was likely accessed / exfiltrated — triggers UK GDPR / DPA 2018 ICO 72-hour notification
- ▸Draft ICO notification submission (threshold assessment, breach description, mitigation actions, risk tier)
- ▸File Action Fraud UK report if financial fraud was attempted or succeeded — faster Action Fraud notification significantly improves bank reimbursement odds
- ▸Coordinated bank notification protocol if any payment-account password resets were received during the breach window (suspicious-bank-login prevention)
- ▸Cyber insurance notification — most UK policies require insurer notification within 24-72h of becoming aware
What it costs
Triage + first 4 hours: free. All email compromise investigations are fixed-price — personal account recovery, business mailbox compromise with BEC investigation + ICO + customer-notification pack, or multi-account / tenant-wide compromise. Optional ongoing managed SOC monitoring available after the incident. Contact us for a tailored quote.
Full pricing breakdownWhat we cover
RELATED INCIDENT RESPONSE GUIDES
Frequently asked questions
Talk to us now
The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.