← IncidentReady

Company email account hacked? Do this in the next 30 minutes

For companies whose entire IT department is one person. No SOC, no SIEM assumed. Works for Microsoft 365 and Google Workspace. Print this.

The first 15 minutes

  1. Disable sign-in first, don't just reset the password. A live session survives a password change until you revoke tokens — disable the account, then reset, then revoke, in that order.
  2. Revoke all active sessions and refresh tokens the moment the account is disabled — this is the step that actually kicks an attacker out in real time, not the password reset.
    • M365 / Entra ID: Entra admin center → Identity → Users → [user] → Revoke sessions (or Block sign-in to stop password-based re-auth too).
    • Google Workspace: Admin console → Directory → Users → [user] → Sign out user, then Security → Suspend user if you need a full lockout while you work.
  3. Reset the password to a strong, unique value. Deliver it out-of-band — phone call or in person, never by email to the compromised account.
  4. Sweep inbox rules and forwarding. This is the fastest-deployed persistence mechanism, so do it now, not after the wipe-your-hands moment. Check both admin-level mail flow rules and the mailbox's own rules — an attacker with even a few minutes of access commonly adds a rule that forwards or hides mail matching payment or password keywords.
  5. Check MFA methods registered on the account. Remove any phone number, authenticator app, or security key the user doesn't recognize, then require re-registration.
  6. Check OAuth/app grants. A malicious app grant survives a password reset — this is the step people skip and the reason accounts get "re-hacked" a day later.
  7. Check for new devices or sessions registered on the account in your identity provider. Remove/revoke anything unrecognized.
  8. Start an incident log — timestamps for every action above. You'll want them later to correlate against audit logs.

Microsoft 365 / Entra ID: exact paths

Google Workspace: exact paths

If it's an admin/privileged account

Treat it as a full-tenant incident, not a single-account issue:

The mistakes that make it worse

This checklist is 1 of 10 runbooks.

The full IncidentReady pack covers compromised accounts end-to-end (admin-account special handling, persistence hunting, breach-notification thresholds, copy-paste user and vendor notices) plus ransomware, phishing/BEC, lost devices, and a tabletop kit to rehearse it — written for businesses of 5–50 people. Editable, $29.

Get the pack — $29   Read the free phishing runbook →

Preparedness templates, not legal advice. © 2026 IncidentReady