Guide · Scams & security
Your business email has been hacked: what to do in the first hour
Business email hacked? The first-hour steps for Australian small businesses: lock the attacker out, check rules, warn your bank and customers, report.

A customer rings to ask why you changed your bank details. Emails you never wrote are sitting in Sent Items. Or you have been logged out and your password no longer works. However you find out, the first hour matters, because a hacked mailbox is used for more than reading mail. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) notes that email accounts can be used “to impersonate the account owner, to spread scams, and to perform password resets” on your other accounts.
This guide is the order we would work in, drawn from ACSC, Microsoft and Google guidance. If you want someone on the phone while you do it, the ACSC runs a 24/7 hotline on 1300 CYBER1 (1300 292 371).
The first hour, step by step
1. Call your bank. The ACSC’s first step is securing your money: ask your bank to check for suspicious activity and follow its advice on freezing accounts or cards. If money has gone to a fraudster, say so; the ACSC says banks may be able to stop a transaction. Use the bank’s official number.
2. Change the password from a clean device. Log in to your provider’s site or app directly and change the password. The ACSC warns against reset links sent by email or message, as fake ones are common. On our reading, if the computer itself may be infected, use a different device you trust.
3. Sign out every session. The ACSC says a password change should log out other devices, but use the sign-out-everywhere option in security settings anyway.
4. Turn on multi-factor authentication (MFA), and remove anything you don’t recognise. The ACSC calls MFA “the most important defence against cybercriminals”. It also warns the attacker may have added their own MFA methods and recovery options; delete any you don’t recognise.
5. Check forwarding rules, inbox rules, auto-replies, delegates and connected apps. The ACSC says criminals “will often set up rules to forward incoming emails to other accounts”, which keep working after a password change. Remove forwarding, rules, automatic replies and linked third-party apps you don’t recognise. Check who else has mailbox access too; Google lists mail delegation among settings to review.
6. Look at what was sent. Check Sent and Deleted items. The ACSC notes attackers may permanently delete emails or mark opened ones unread. This tells you who to warn.
7. Warn contacts. Tell customers, colleagues and suppliers (see “Warn your customers” in this guide).
8. Report it. Lodge a report through ReportCyber, choosing the option for a business or organisation. The ACSC says the report goes to the relevant police jurisdiction; note the reference number beginning “CIRS-”, which you can give to your bank or insurer. If a scam was involved, also report to Scamwatch.
If you use Microsoft 365
Microsoft says disabling the account while you investigate is “preferred and highly recommended”, with a password reset as the next step. An admin can do most of this from the Microsoft 365 admin center. Go to Users > Active users, select the person, and choose Reset password. Then select the user again and, on the Account tab, choose Sign out of all sessions. Microsoft says the user is prompted to sign in again within an hour, as an access token lasts an hour, and that Block sign-in can take up to 24 hours, so reset the password for immediate effect.
Microsoft’s guide for compromised accounts adds several checks:
- Don’t email the new password to the user, “because the attacker could have access to the mailbox”.
- App passwords are not revoked by a password reset; delete them and create new ones.
- Remove MFA methods and devices you don’t recognise, and review applications the user has consented to.
- Check any admin roles the account holds.
- Review mailbox forwarding and inbox rules, including hidden rules.
- Use the audit log in the Microsoft Defender portal, starting from just before the suspicious activity.
To check delegates, open the user in Active users, expand Mail Settings and select Edit next to Mailbox permissions, which lists Read and manage, Send as and Send on behalf. If the account sent a lot of spam, Microsoft says it may be blocked from sending until it is removed from the Restricted entities page.
If you use Google Workspace
Google’s admin guidance starts by suspending the user, which it says “resets the user’s sign-in cookies and OAuth tokens”. To reset a password, go to Menu > Directory > Users, find the user and choose Reset password, then reset sign-in cookies under Security > Sign-in cookies > Reset. Google says that after both, the user is signed out of all active sessions.
Google also recommends revoking the user’s OAuth 2.0 tokens, removing app passwords the user created and turning on 2-Step Verification. User log events show sign-ins for up to six months.
In Gmail, Google’s hacked-account checklist includes delegation, automatic forwarding, filters, IMAP and POP access, the vacation responder, addresses used on outgoing mail and blocked addresses. Also check Apps with access to your account.
Then, in the next few days
- Secure connected accounts. The ACSC says to prioritise accounts that share the email password, use this address for password recovery, or use sign in with Google or similar.
- Find out how they got in. If you don’t know, the ACSC suggests malware may have stolen the password. Our recent report on an ATO-themed scam email that installs remote-access software is one example of how that happens.
- Look for lookalike domains. The ACSC says to check whether fake emails came from your exact address; for .au lookalikes you can complain to auDA or ask the registrar for a takedown.
- Get free help. IDCARE’s Small Business Cyber Resilience Service offers free one-on-one support to businesses with 19 or fewer full-time equivalent employees, on 1800 595 170 (Monday to Friday, 8am to 6pm AEST, according to business.gov.au). For a live incident, business.gov.au says to call 1300 CYBER1 first. The ACSC lists IDCARE’s 1800 595 160 line for identity theft.
- Check your privacy obligations. If customer personal information may have been accessed, the OAIC’s Notifiable Data Breaches scheme requires businesses covered by the Privacy Act to notify affected people and the OAIC when a breach is likely to cause serious harm. The OAIC says most businesses with annual turnover of $3 million or less are not covered, but some are regardless of turnover, including health service providers and, generally, businesses that trade in personal information. See our story on Privacy Act changes for small business.
Warn your customers
On our reading, the bigger risk is often your customers’ money: an attacker who has read your invoices can send a convincing “our bank details have changed” email from your real address. The ACSC says to alert contacts about fake emails involving “changing of bank details, requests for large payments or unusual links or attachments”.
Work from the Sent items list, and use the ACSC’s template notice. On our reading, phone key customers rather than relying on email from the affected account, and ask them to confirm any change in bank details by phone. If a customer has already paid a fake account, the ACSC says to encourage them to report it to their financial institution.
Checklist
- Call your bank now. Ask it to check for suspicious activity and try to stop any payment sent to a fraudster.
- Change the password from a trusted device. Log in to the provider directly, not through an emailed reset link.
- Sign out all sessions. Use Sign out of all sessions in Microsoft 365, or in Google Workspace reset the password and then the sign-in cookies.
- Turn on MFA and remove unknown methods. Attackers may have added their own MFA methods and recovery details.
- Delete unknown forwarding and inbox rules. They keep sending your mail to the attacker after a password change.
- Remove unknown delegates and connected apps. Check mailbox permissions, OAuth apps and app passwords (in Microsoft 365 a password reset does not revoke app passwords).
- Phone customers and suppliers. Warn them about fake bank-detail changes and ask them to verify any change by phone.
- Report through ReportCyber. Keep the CIRS- reference number for your bank and insurer.
- Call IDCARE if you qualify. Businesses with 19 or fewer full-time equivalent staff get free recovery support on 1800 595 170 (weekdays); for a live incident call 1300 CYBER1 first.
- Check whether the Privacy Act covers you. If it does and personal information was exposed, you may need to notify the OAIC.
Tick items as you go. Your ticks stay in this browser.
Sources 15 sources
- Recovering a compromised email account (ASD's ACSC)
- Report and recover from business email compromise (ASD's ACSC)
- ReportCyber (ASD's ACSC)
- Respond to a compromised cloud email account (Microsoft Learn)
- Step 1 - Prevent user sign-in and block access to Microsoft 365 (Microsoft Learn)
- Give mailbox permissions to another Microsoft 365 user (Microsoft Learn)
- Identify and secure compromised accounts (Google Workspace Help)
- Reset a user's password (Google Workspace Help)
- Sign a user out of a managed Google Account (Google Workspace Help)
- Secure a hacked or compromised Google Account (Google Account Help)
- Small Business Cyber Resilience Service (IDCARE)
- Small Business Cyber Resilience Service (business.gov.au)
- Report a scam (Scamwatch)
- About the Notifiable Data Breaches scheme (OAIC)
- Small business (OAIC)

