What should I do if a business account or business email is hacked?

Business Tech & Tools

What should I do if a business account or business email is hacked?

The short answer

Use a trusted device to contact the provider, recover the account, change the password, replace multifactor and recovery methods, and end every other session. Then check what the intruder changed or sent, protect connected accounts, warn people who may be targeted, and document the timeline.

If customer information, payments, payroll, taxes, or regulated records may be involved, bring in qualified security, legal, insurance, and financial help promptly. A restored login does not prove the incident is over.

Contain the account first

Do not argue with the attacker or keep using a computer you suspect is infected. From a clean device:

  1. Start recovery through the provider's official website or app.
  2. Change the password to one never used before.
  3. Remove unfamiliar passkeys, security keys, authenticator devices, phone numbers, and recovery addresses.
  4. Revoke all sessions, app passwords, connected applications, and delegated access.
  5. Save new recovery codes somewhere separate and secure.
  6. Contact provider support if any setting cannot be reversed.

If your primary email was taken over, protect the domain registrar, password manager, cloud storage, financial accounts, website, social accounts, and payment platforms next. Email is often the recovery path for those services.

Look for quiet changes

An account can appear normal while an attacker keeps another door open. In email, inspect:

  • automatic forwarding.
  • mailbox and deletion rules.
  • delegates and shared inbox users.
  • sent, deleted, archived, and draft messages.
  • connected apps and OAuth permissions.
  • recovery details and trusted devices.
  • signatures containing changed payment instructions.

In other accounts, check new administrators, API keys, payout destinations, bank details, ad campaigns, scheduled posts, uploaded files, and recent exports.

Find the beginning and the reach

Write a timeline starting with the first suspicious event. Note login alerts, password resets, messages sent, files opened, payment changes, and people contacted. Preserve screenshots and provider logs. Avoid deleting possible evidence before a professional advises you when the incident is serious.

Ask which other accounts shared the old password, trusted the compromised email, or were open on the same device. Resetting one password will not fix a reused credential or infected computer.

The FTC's Data Breach Response guide recommends moving quickly to secure systems, determining what was taken, fixing vulnerabilities, and developing a communications plan.

Protect clients and money

If messages went out from your account, contact recipients through another channel. Say what time range was affected, what they should distrust, and how they can verify future requests. Do not include fresh login links in the warning.

Call banks, card issuers, payroll providers, or payment platforms using trusted contact information if financial changes are possible. Ask them to flag the account and explain their fraud process.

If personal information was exposed, notification duties may depend on the data, people, location, and industry. The FTC notes that breach-notification laws and other regulations may apply. Do not copy a generic internet notice and hope it fits. Check current state, federal, national, contractual, and professional requirements with qualified advisers.

Clean the device and close the cause

Update the operating system, browser, security software, and applications. Run appropriate scans. If the incident involved malware, remote-control software, or an administrator account, use a capable security professional to decide whether the device can be trusted or should be rebuilt.

Then address the entry point:

  • reused or weak password: move accounts into a password manager.
  • stolen code: switch to a phishing-resistant factor where available.
  • fake invoice: require second-channel payment verification.
  • old contractor access: create an offboarding checklist.
  • malicious file: tighten attachment handling and device protection.
  • missed alert: route security notices to a monitored backup contact.

Schedule follow-up reviews after twenty-four hours, one week, and one month. Watch for new forwarding rules, password resets, financial attempts, or messages that suggest the attacker is trying again.

Sources and further reading

A free next step

Not sure which business fits you yet?

The free Freedom Path Assessment can help you compare your strengths, schedule, income goals, and preferred way of working before you commit to a business direction.

Take the Freedom Path Assessment Free

Related Questions

← All questions