Office 365 Hacked? — UK Mailbox + Email Compromise Response
If your Office 365 or Microsoft 365 mailbox has been hacked — emails sent to your contact list, attackers reading your mail, suspicious autoforwarding, BEC fraud against your finance team — we contain it within hours, not days. UK-based 24/7 incident response: mailbox recovery, attacker-rules cleanup, conditional access re-secure, ICO notification if needed.
We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.
YOU MAY HAVE SEARCHED
Do these 4 things in the next 10 minutes
- 1
Force password reset on every suspected compromised account (admin → Entra ID → Users → select user → Reset password). Use a strong fresh password — not a variant of the old one.
- 2
Revoke all active sessions: Entra ID → Users → Sign-in sessions → Revoke all refresh tokens & session tokens. This kicks the attacker out immediately.
- 3
Check mailbox rules — this is the highest-value attacker-persistence fix. Outlook admin → mailbox → Inbox rules + Sweep rules. Look for: unknown rules forwarding to external addresses, mail moving to 'RSS Feeds' or 'Archive' folders, mail auto-deleted on keywords like 'invoice', 'bank', 'payment'. Delete any attacker rules.
- 4
Enable MFA on the account if not already (Microsoft 365 admin → Entra ID → Users → Authentication methods → Require MFA). Break-glass admin account: ensure none exists with simple password — reset it.
What we do — the Gridisys incident timeline
From the moment you engage, within fixed-price limits.
Triage + scoping (Hour 0-2)
- ▸Free 15-min triage call — confirm incident type, suspected accounts, business impact
- ▸Pull last 30 days of unified audit log (UAL) for affected mailbox: sign-ins, mailbox rules,MailboxLogin operations, OAuth grants
- ▸Identify attacker persistence: inbox rules, autoforward, OAuth grants, delegated access, sent-folder cleanup
- ▸Containment authorisation from client — we lead the response
Containment (Hour 2-4)
- ▸Force password reset all suspected accounts + all admin accounts
- ▸Revoke all sessions + refresh tokens
- ▸Remove attacker inbox rules + auto-forwarding
- ▸Revoke all suspicious OAuth grants (Mail.ReadWrite, Mail.Send)
- ▸Block suspicious external IPs at conditional access (geo + threat intelligence)
- ▸Enable MFA for all accounts + enforce conditional access baseline
Investigation (Hour 4-48)
- ▸Full unified audit log analysis (30-90 days) — what data the attacker accessed, sent, downloaded, exfiltrated
- ▸Mailbox forensics: identify any sent/received messages to assess ICO notification (personal data accessed or exfiltrated)
- ▸BEC pattern investigation: were supplier emails intercepted? Was supplier bank account change fraud attempted or successful? Were any wire transfers diverted?
- ▸Identify persistence: OAuth grants, mailbox delegation, signed-in mobile devices, app passwords, legacy auth protocols still enabled
Recovery + secure baseline (Day 2-7)
- ▸Reset all suspected account credentials + admin accounts + break-glass
- ▸Disable legacy auth (IMAP / POP / SMTP basic auth) at tenant level
- ▸Configure Defender for Office 365 anti-phishing policy + safe links/attachments
- ▸Implement conditional access baseline (MFA everywhere, geo-block, device compliance for admins)
- ▸Configure mail-flow rules to alert on external autoforwarding + supplier-bank-change keyword monitoring
ICO + regulator + customer notifications (Day 1-7)
- ▸Assess whether personal data was likely accessed / exfiltrated — triggers ICO 72-hour clock under UK GDPR / DPA 2018
- ▸Draft ICO notification submission (ICO guidance — confirm threshold met, risk tier, breach description, mitigation actions)
- ▸Draft supplier/customer notification packets if financial fraud attempted — particularly if customer bank details intercepted
- ▸If FCA-regulated: SUP 15.3.20 / PS21/3 notification assessment (operationally significant regulatory incident)
- ▸Document breach register entry + I've Been Hacked timeline evidence pack
What it costs
Triage + first 4 hours: free. All incident response engagements are fixed-price, scoped to the scope of compromise. Includes audit-log forensics, containment, recovery, ICO / customer notification pack. Optional ongoing M365 managed SOC monitoring available after the incident. Contact us for a tailored quote.
Full pricing breakdownWhat we cover
RELATED INCIDENT RESPONSE GUIDES
Frequently asked questions
Talk to us now
The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.