What to do first after a business account hack
If you need to know how to recover business account after hack, speed matters more than perfection.
The first few minutes are about stopping damage, preserving evidence, and regaining control without making the breach worse.
Start by identifying which account was compromised: email, Microsoft 365, Google Workspace, social media, banking, cloud storage, or a CRM.
Then notify your internal team so no one unknowingly follows attacker instructions, resets passwords on the wrong device, or approves fraudulent transfers.
- Freeze affected accounts or sessions if the platform allows it.
- Disconnect compromised devices from the network.
- Do not delete emails, logs, or messages yet; they may be evidence.
- Warn staff about phishing messages sent from the compromised account.
How to recover business account after hack?
Recovery starts with identity verification.
Most major platforms require ownership confirmation through backup email, SMS, authenticator apps, security keys, admin consoles, billing records, or support tickets.
If an attacker changed recovery details, you may need to prove business control using invoices, domain records, government ID, or registered payment information.
For Google Workspace and Microsoft 365, use the admin recovery and tenant support pathways if you still have any admin access.
For social platforms and ad accounts, use the official compromised-account forms and business verification flows.
For financial accounts, call the bank or payment processor immediately and request a fraud hold, new credentials, and transaction review.
When an account is restored, confirm the attacker did not create hidden access points.
Revoke all active sessions, remove unknown devices, reset passwords, and reissue recovery methods.
If possible, rotate API keys, app passwords, OAuth tokens, and connected app permissions at the same time.
Preserve evidence before making changes
Good incident response balances recovery with investigation.
Save screenshots of suspicious login alerts, password reset notices, inbox rules, forwarded messages, deleted items, admin changes, and unusual payment activity.
Keep timestamps and, if your tools allow it, export audit logs.
Evidence matters because many business account hacks involve more than stolen credentials.
Attackers may use phishing, session hijacking, token theft, malware, SIM swapping, or business email compromise to move laterally across systems.
A clear record helps with support escalation, cyber insurance claims, and law enforcement reports.
- Capture the first alert and the last known legitimate access time.
- Save IP addresses, device names, and geolocation clues.
- Record the names of all support agents and case numbers.
- Archive suspicious emails with full headers, not just screenshots.
Secure the account so the attacker cannot return
After access is restored, assume the attacker may still have persistence.
Many intruders create forwarding rules, delegated mailbox access, backup admins, or third-party integrations that survive a password change.
The recovery process should therefore include a full security review of the account and related systems.
Change credentials in the right order
Start with the most privileged credentials first, especially administrator accounts and email accounts used for resets.
Use strong, unique passwords stored in a reputable password manager.
Enable multi-factor authentication with an authenticator app or hardware security key rather than SMS when possible.
Audit sessions, devices, and trusted locations
Review active sessions across all devices and sign out everywhere.
Remove unknown devices from the account settings and disable legacy authentication methods that bypass MFA.
Check whether trusted IP ranges, conditional access rules, or login exemptions were altered during the compromise.
Check inbox rules, forwarding, and delegation
Business email accounts are often used to redirect invoices or steal sensitive correspondence.
Search for auto-forwarding, hidden inbox rules, mailbox delegation, and rules that mark messages as read or delete security alerts.
In collaboration tools, inspect guest access and shared drives for unauthorized sharing.
Investigate the scope of the breach
Once the account is under control, determine what the attacker accessed and whether they touched other systems.
For many organizations, a hacked business account is the entry point to payroll, cloud storage, customer data, accounting software, or vendor portals.
Review sign-in logs, file access history, admin actions, sent messages, deleted items, and permission changes.
If the account is tied to Single Sign-On, check whether the same credentials unlocked other applications such as Salesforce, QuickBooks, Slack, Dropbox, or AWS.
Look for signs of data exfiltration, including large downloads, unusual file sharing, exports, or external email forwarding.
If regulated data may be involved, assess reporting obligations under laws or contracts relevant to your business.
Notify the right people quickly
Communication should be fast, accurate, and limited to people who need to act.
Internal leadership, IT, legal, finance, and security teams should know what happened, what is confirmed, and what remains under investigation.
If customer data, payment data, or employee records were exposed, notification requirements may apply.
External notifications may include banks, payment processors, hosting providers, cyber insurance carriers, and affected vendors.
For business email compromise, tell customers and partners not to trust recent payment instruction changes or urgent requests sent from the compromised account.
- Inform staff not to reuse old passwords.
- Alert finance about suspicious invoice changes.
- Tell support teams how to handle incoming complaints.
- Document all notifications for compliance and insurance.
Common attack methods that cause business account compromise
Understanding the attacker’s method helps prevent repeat incidents.
Phishing remains the most common entry point, especially when attackers imitate Microsoft, Google, DocuSign, payroll systems, or executives.
Credential stuffing also succeeds when employees reuse passwords from earlier data breaches.
Other frequent causes include malware on a remote work device, stolen browser cookies, weak MFA configured with SMS, and social engineering directed at help desks.
In some cases, attackers exploit third-party apps with overbroad permissions rather than attacking the main account directly.
Signs the compromise is still active
- Password reset emails keep arriving after cleanup.
- New forwarding rules or filters reappear.
- Unknown logins continue from unfamiliar locations.
- Finance receives changed banking instructions.
- Users report receiving phishing emails from the account.
How to harden business accounts after recovery
Recovery should end with stronger controls than before the hack.
Use phishing-resistant MFA wherever possible, especially for administrators and finance staff.
Separate daily-use accounts from privileged accounts so one stolen login cannot expose every system.
Adopt least-privilege access for email, cloud storage, and SaaS apps.
Regularly review sharing permissions, vendor access, and dormant accounts.
Maintain device security with endpoint protection, patching, and disk encryption on laptops and mobile devices that access company systems.
Set up alerting for impossible travel, new mailbox rules, privilege escalation, risky sign-ins, and payment-detail changes.
For smaller businesses, even basic monitoring can shorten attacker dwell time and reduce fraud losses.
When to bring in outside experts
Bring in a managed security provider, incident response firm, or digital forensics specialist if the compromise affects multiple accounts, involves customer data, or includes evidence of persistence.
Outside experts can preserve logs, identify root cause, and help with recovery sequencing that minimizes additional loss.
You should also seek outside help if the attacker changed admin settings, deleted backups, encrypted files, or used the account to impersonate the business in a way that may create legal or reputational exposure.
Faster expert involvement often means cleaner restoration and better documentation for insurers and regulators.