Start Here
Business Technology

What to Do If Your Business Email or Account Gets Hacked

Last Updated: July 20, 2026 6 min read By Leo Baquiran

If you think your business email or an account has been hacked, take a breath — then move fast. The first hour matters most, because the damage attackers do usually comes after they get in: reading your email, messaging your customers, redirecting invoices, and quietly setting themselves up to keep access. Here’s exactly what to do, in order.

Signs your account has been hacked

  • You’re suddenly signed out, or your password no longer works.
  • Contacts say they got strange emails or messages from you.
  • Emails you never sent appear in Sent — or messages are vanishing from your inbox.
  • Login alerts from unfamiliar locations or devices.
  • Password-reset emails you didn’t request.
  • New forwarding rules, filters, or a changed signature you didn’t create.

Do these first (the first hour)

  1. Change the password — from a device you trust. If you suspect the computer itself is compromised, use a different, clean device. Make the new password long, unique, and stored in a password manager.
  2. Turn on MFA immediately. This is what actually locks the attacker out, even if they know the new password. If you don’t have it, set it up now — see how to set up MFA.
  3. Sign out all other sessions. Most services have a “sign out everywhere” or “active sessions/devices” option. Do this after changing the password, or the attacker stays logged in.
  4. Check what they changed (see the next section — this is the step people miss).
  5. Change the password anywhere else you reused it. If that password was used on other accounts, those are compromised too.
  6. Scan the device for malware with your antivirus, in case credentials were stolen by something on the machine.

Check what the attacker changed (don’t skip this)

Attackers usually leave themselves a way back in — and it’s easy to miss. Go through your account settings and check for:

  • Email forwarding rules — a hidden rule quietly copying your mail to them. This is the most common one.
  • Filters/rules that delete or move messages (often used to hide their activity from you).
  • Recovery email and phone number — if they changed these, they can reset your password again.
  • Connected/third-party apps with access to your account — revoke anything unfamiliar.
  • Your signature and auto-replies — sometimes altered to include scam links or fake payment details.
  • New users or admins, if it’s a business account with an admin console.

Contain the damage

  • Warn your contacts and customers. Attackers often email your contacts pretending to be you — sometimes with fake invoices or “updated bank details.” A quick heads-up (“if you got an odd message from me, ignore it”) prevents someone else losing money.
  • Check for financial fraud. Review your Sent folder for invoices or payment requests you didn’t send, and check whether any bank details in your recent emails were altered.
  • Check linked accounts. Your email is the reset key for everything else — review your bank, payment, domain, and social accounts for unauthorized changes.
  • Alert your team so they don’t act on any instructions that came from the compromised account.

If you’re locked out completely

If the attacker changed your password and recovery details, use the provider’s account-recovery process — Microsoft, Google, and the major platforms all have one, and they’ll ask questions to verify you’re the real owner. If it’s a business account (Microsoft 365 or Google Workspace) and you have an admin, the admin can reset the user’s password directly — much faster. Being the admin of your own business accounts is exactly why that access matters.

Who to notify

  • Your bank or payment provider, immediately, if any financial details were exposed or money was moved.
  • Customers or clients whose data may have been accessed — depending on where you operate, notifying affected people may be a legal obligation, so check your local data-protection rules.
  • The platform provider, so they can help secure the account and investigate.
  • Local authorities/cybercrime reporting, particularly if there’s been financial loss.

Stop it happening again

Once things are secure, close the door properly:

  • MFA on every account that offers it — this alone stops the vast majority of repeat attacks.
  • A password manager, with a unique password everywhere (no reuse, ever).
  • Train your team to spot phishing — it’s how most compromises start. See how to protect your business from phishing.
  • Keep real backups so you can recover data if an attack goes further — see how to back up your business data.
  • Remove access for anyone who’s left the business.

Work through our small business cybersecurity checklist to cover the rest of the basics.

The bottom line

Being hacked feels awful, but it’s recoverable — and most businesses get through it fine when they act quickly. Lock the attacker out (password + MFA + sign out everywhere), undo the changes they made, warn the people who could be affected, then fix the weakness that let them in. The businesses that get hit twice are the ones that skip that last step.

Frequently asked questions

What should I do first if my business email is hacked?

Change your password from a device you trust, turn on multi-factor authentication, then sign out all other sessions. That locks the attacker out. Next, check for forwarding rules or recovery-detail changes they may have made to keep access.

How do I know if my account was really hacked?

Common signs include being signed out unexpectedly, contacts receiving strange messages from you, emails in your Sent folder you didn’t send, login alerts from unfamiliar locations, password-reset emails you didn’t request, or new forwarding rules and filters you didn’t create.

What if I can’t get back into my account?

Use the provider’s account-recovery process, which verifies you’re the real owner. If it’s a Microsoft 365 or Google Workspace business account, an admin can reset the password directly — usually much faster than recovery.

Do I need to tell my customers?

If their data may have been accessed, yes — and depending on where you operate it may be a legal requirement, so check your local data-protection rules. At minimum, warn contacts if the attacker may have messaged them pretending to be you.

About the Author

Leo Baquiran

IT Professional & Technology Reviewer

Leo Baquiran is an IT professional with experience in IT operations, infrastructure management, cybersecurity, Microsoft technologies, enterprise applications, and business productivity solutions. He writes practical technology reviews, AI tool comparisons, software guides, and buying guides for professionals, students, and business users.

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like

Hand-picked reads based on this page.

Get Smarter Tech Picks Weekly

Receive reviews, buying guides, comparisons, and deals directly in your inbox.

No spam. Unsubscribe anytime.

Jump into another corner of the Oleohub research hub.