Cyber security

We think someone has access to our email. What do we do now?

Revoke the active sessions, then change the password, then check the mailbox rules. That order matters: changing a password on its own does not sign somebody out of a session they already hold, and the mailbox rule is what has been hiding this from you.

Do these three things, in this order, before anything else.

  1. Revoke the account’s active sessions. In Microsoft 365 this is "sign out of all sessions" on the user, or disabling the account outright.
  2. Change the password, to something new, not a variation of the old one.
  3. Check the mailbox rules, on that account and on any shared mailbox it can reach.

The order is the part people get wrong. A password change on its own does not eject somebody who is already signed in, because the session they are holding was issued before you changed anything. Plenty of businesses have changed a password, felt relieved, and left the intruder exactly where they were.

Why do the mailbox rules matter so much?

Because they are how a compromise stays invisible.

Once somebody is in a mailbox, one of their first moves is to create a rule. Messages containing certain words get moved to a folder nobody opens, or marked as read, or forwarded outside the business. Then the account owner carries on as normal, seeing nothing unusual, while the interesting mail is filtered away before they reach it.

Look for rules that move things to RSS Feeds, Conversation History, Archive or a folder with a single character as a name. Look for anything forwarding externally. Delete them, and write down what they said first.

While you are in there, check the sent items and the deleted items. What has been sent from this account in the last month is the question that decides how bad this is.

What else needs checking?

  • Look at the sign in logs. Where has this account signed in from, and when. You are looking for locations and devices that make no sense.
  • Check whether multi-factor authentication was on. If it was not, switch it on now, for this account and every other one. If it was on and they got in anyway, somebody approved a prompt, which is a different conversation and a training one.
  • Check for new app registrations or consents granted from that account, because those survive a password change.
  • Check the other accounts. People reuse passwords. If this one leaked, assume others have.
  • Warn the people who deal with money. Anybody who could act on a payment instruction needs to know today that a mailbox has been compromised, and that no bank details change gets actioned this week without a phone call to a number they already held.
  • Tell your clients if the account has been emailing them. Awkward, and much less awkward than one of them paying an invoice that was not yours.

What was actually being aimed at?

Almost always money.

The pattern is consistent. Somebody gets into a mailbox, sets up the rule so nobody notices, and then reads. They are waiting for a transaction worth diverting: a completion, an invoice, a deposit, a payroll run. When it appears, an email arrives from a thread that is genuinely real, saying the bank details have changed.

That is why the payments warning above is not an afterthought. It is the thing you are actually trying to prevent.

Occasionally it is something else. Access to a mailbox is a route into whatever that address can reset a password on, which is usually more than anybody realises.

Do you have to report it?

Possibly, and this is worth taking advice on rather than deciding for yourself.

If personal data has been accessed, a notifiable breach has to be reported to the ICO within 72 hours of you becoming aware. If you are regulated, your regulator will have its own requirement. Your insurer almost certainly has a notification period, and leaving it late can affect a claim. And if client data is involved you may need to tell them.

Four clocks, all starting from the moment somebody realises. That is the argument for having decided in advance who makes those calls, rather than working it out on the day.

How do you stop it happening again?

Nobody enjoys this bit, and skipping it is how it happens twice.

Work out how they got in. It is usually a password entered on a convincing fake login page. Then fix the thing that made that enough: multi-factor authentication on every account with no exceptions, monitoring that would spot a mailbox rule being created, and email filtering ahead of the message arriving in the first place.

And say to your team, plainly, that whoever clicked it is not in trouble. I mean that. The most expensive version of this is the one where somebody realises at half past four on a Friday and decides to see whether it sorts itself out over the weekend. A team that owns up in five minutes is worth more to you than a team that never clicks anything, and the second one does not exist.

If you need somebody now

Ring us on the number at the top of the page. If you are not a client we will still tell you what to do first, because the first hour matters more than who you buy support from.

What we run for clients includes monitoring that flags exactly this, and what it costs is published. If you want somebody to check whether this could be happening right now and nobody has noticed, that is a short conversation.

Questions

The questions people ask us about this

Should we take the computer off the internet?

For a compromised mailbox, no. This is happening in the cloud rather than on a machine, so unplugging a laptop achieves nothing and gets in the way of fixing it.

If you also think malware is involved, isolate that machine from the network but leave it switched on, because turning it off destroys evidence in memory.

Do we have to tell anyone?

Possibly. If personal data has been accessed, UK GDPR gives you 72 hours to report a notifiable breach to the ICO from becoming aware of it. You may also have obligations to your regulator, your insurer and your clients, each on its own clock.

Take advice early rather than deciding on your own that it does not count.

How long do we have before it becomes expensive?

The costly outcome is almost always a diverted payment, so the clock is however long it is until your next significant invoice or transfer. That is why this gets dealt with today rather than at the end of the week.

Read next

Pricing

What does IT support cost per user per month?

Ours is £42, £55 or £72 per user per month excluding VAT, depending on how much security sits in it. Almost nobody in this industry publishes a figure, so any industry average you are quoted is a guess. Here is ours, and what moves it.

Read this

Cyber security

Will your cyber insurance actually pay out?

Only if the things you told the insurer you were doing were actually happening on the day you got hit. Your policy schedule lists them: multi-factor authentication, patching, endpoint protection, training, an incident response plan. If one of them was not true, a claim can be refused outright rather than reduced.

Read this

All posts

Next step

Talk to Tom, not a call queue

Ring the number below and you get Tom, the owner. No hold music, and no ticket reference before anyone has heard the problem. If we’re not the right fit, we’ll tell you that too.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.