ACTIVE INCIDENT RIGHT NOW? Gridisys 24/7 emergency triage — £0 first 15 minutes.
24/7 EMERGENCY INCIDENT RESPONSE · UK

Office 365 Hacked? — UK Mailbox + Email Compromise Response

If your Office 365 or Microsoft 365 mailbox has been hacked — emails sent to your contact list, attackers reading your mail, suspicious autoforwarding, BEC fraud against your finance team — we contain it within hours, not days. UK-based 24/7 incident response: mailbox recovery, attacker-rules cleanup, conditional access re-secure, ICO notification if needed.

We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.

YOU MAY HAVE SEARCHED

"office 365 email hacked UK""microsoft 365 mailbox compromised""o365 account hacked help""outlook email hacked what do I do""office 365 abnormal sign-in""m365 auto-forward rule to external""mailbox sending spam contacts""CFO email compromised supplier bank change""office 365 suspicious inbox rules"

Do these 4 things in the next 10 minutes

  1. 1

    Force password reset on every suspected compromised account (admin → Entra ID → Users → select user → Reset password). Use a strong fresh password — not a variant of the old one.

  2. 2

    Revoke all active sessions: Entra ID → Users → Sign-in sessions → Revoke all refresh tokens & session tokens. This kicks the attacker out immediately.

  3. 3

    Check mailbox rules — this is the highest-value attacker-persistence fix. Outlook admin → mailbox → Inbox rules + Sweep rules. Look for: unknown rules forwarding to external addresses, mail moving to 'RSS Feeds' or 'Archive' folders, mail auto-deleted on keywords like 'invoice', 'bank', 'payment'. Delete any attacker rules.

  4. 4

    Enable MFA on the account if not already (Microsoft 365 admin → Entra ID → Users → Authentication methods → Require MFA). Break-glass admin account: ensure none exists with simple password — reset it.

Most UK SMEs hit by Office 365 mailbox compromise don't discover it for 7-21 days. Acting now compresses the breach window, limits ICO exposure, and reduces the fraud window for BEC payment diversion. We've handled 200+ Microsoft 365 compromise incidents for UK SMEs.

What we do — the Gridisys incident timeline

From the moment you engage, within fixed-price limits.

First 60-120 minutes

Triage + scoping (Hour 0-2)

  • Free 15-min triage call — confirm incident type, suspected accounts, business impact
  • Pull last 30 days of unified audit log (UAL) for affected mailbox: sign-ins, mailbox rules,MailboxLogin operations, OAuth grants
  • Identify attacker persistence: inbox rules, autoforward, OAuth grants, delegated access, sent-folder cleanup
  • Containment authorisation from client — we lead the response
Within 4 hours of engagement

Containment (Hour 2-4)

  • Force password reset all suspected accounts + all admin accounts
  • Revoke all sessions + refresh tokens
  • Remove attacker inbox rules + auto-forwarding
  • Revoke all suspicious OAuth grants (Mail.ReadWrite, Mail.Send)
  • Block suspicious external IPs at conditional access (geo + threat intelligence)
  • Enable MFA for all accounts + enforce conditional access baseline
Days 1-2

Investigation (Hour 4-48)

  • Full unified audit log analysis (30-90 days) — what data the attacker accessed, sent, downloaded, exfiltrated
  • Mailbox forensics: identify any sent/received messages to assess ICO notification (personal data accessed or exfiltrated)
  • BEC pattern investigation: were supplier emails intercepted? Was supplier bank account change fraud attempted or successful? Were any wire transfers diverted?
  • Identify persistence: OAuth grants, mailbox delegation, signed-in mobile devices, app passwords, legacy auth protocols still enabled
1-7 days

Recovery + secure baseline (Day 2-7)

  • Reset all suspected account credentials + admin accounts + break-glass
  • Disable legacy auth (IMAP / POP / SMTP basic auth) at tenant level
  • Configure Defender for Office 365 anti-phishing policy + safe links/attachments
  • Implement conditional access baseline (MFA everywhere, geo-block, device compliance for admins)
  • Configure mail-flow rules to alert on external autoforwarding + supplier-bank-change keyword monitoring
72-hour ICO clock

ICO + regulator + customer notifications (Day 1-7)

  • Assess whether personal data was likely accessed / exfiltrated — triggers ICO 72-hour clock under UK GDPR / DPA 2018
  • Draft ICO notification submission (ICO guidance — confirm threshold met, risk tier, breach description, mitigation actions)
  • Draft supplier/customer notification packets if financial fraud attempted — particularly if customer bank details intercepted
  • If FCA-regulated: SUP 15.3.20 / PS21/3 notification assessment (operationally significant regulatory incident)
  • Document breach register entry + I've Been Hacked timeline evidence pack

What it costs

Triage + first 4 hours: free. All incident response engagements are fixed-price, scoped to the scope of compromise. Includes audit-log forensics, containment, recovery, ICO / customer notification pack. Optional ongoing M365 managed SOC monitoring available after the incident. Contact us for a tailored quote.

Full pricing breakdown

What we cover

Mailbox compromise forensics — unified audit log, mailbox audit, sign-in logs (90 days)
Attacker persistence removal — hidden inbox rules, autoforwarding, OAuth grant abuse, app passwords, delegated access
BEC (Business Email Compromise) investigation — what finance/supplier emails were intercepted, what wires were attempted/diverted
Conditional access re-secure — MFA enforcement, geo-block, legacy auth disabled, break-glass account hardened
Defender for Office 365 hardening — anti-phishing policy, safe links, safe attachments, ZAP enabled
ICO 72-hour notification assessment + drafting (UK GDPR / DPA 2018)
FCA SUP 15.3.20 operational resilience notification assessment (if FCA-regulated)
Customer + supplier notification packets (with BEC fraud specifically — bank-change fraud acknowledgement)
Incident report — board-ready timeline, root-cause finding, remediation log, evidence of breach

Frequently asked questions

Talk to us now

The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.