Blog
What to Do If Your Business Email Is Compromised

Key Takeaways
- Change your password and revoke all active sessions immediately — every minute counts.
- Enable two-factor authentication (2FA) before doing anything else with the account.
- Check email forwarding rules and filters — attackers often set silent redirects to maintain access.
- Review recent financial transactions and alert your bank if anything looks suspicious.
- Notify your contacts so they don’t fall for fraudulent messages sent from your account.
- Document everything and report financial losses to the FBI’s IC3 at ic3.gov.
- Bring in professional help to audit your entire web presence and infrastructure for additional vulnerabilities.
Step 1: Change Your Password Immediately
This is your first priority — not in five minutes, not after lunch. Right now. Choose a strong, unique password that is at least 16 characters long and includes a mix of uppercase letters, lowercase letters, numbers, and symbols. Do not reuse a password from any other account. If you use the same password (or a similar one) for other business accounts, change those too. Attackers frequently try compromised credentials across multiple platforms — a technique known as credential stuffing. Pro tip: Use a password manager like 1Password, Bitwarden, or LastPass to generate and store strong passwords. If your team doesn’t use one yet, this incident is your sign to start.Step 2: Revoke All Active Sessions
Changing your password doesn’t automatically kick out an attacker who’s already logged in. Most email platforms (Google Workspace, Microsoft 365, etc.) allow you to view and terminate active sessions. Here’s how:- Google Workspace: Go to your Google Account → Security → “Your devices” → Sign out of all other sessions.
- Microsoft 365: Go to My Account → Security info, and use the “Sign out everywhere” option. An admin can also do this from the Microsoft 365 Admin Center.
Step 3: Enable Two-Factor Authentication (2FA)
If you didn’t have 2FA enabled before, this is non-negotiable going forward. Two-factor authentication requires a second verification step — usually a code from an authenticator app or a physical security key — making it dramatically harder for attackers to access your account even if they steal your password. Use an authenticator app (Google Authenticator, Microsoft Authenticator, or Authy) rather than SMS-based 2FA. SIM-swapping attacks can intercept text message codes, while app-based codes are far more secure. For maximum protection, consider hardware security keys like YubiKey for your most critical accounts.Step 4: Check Email Forwarding Rules and Filters
This step is critical, and it’s the one most people miss. Sophisticated attackers don’t just read your email — they set up silent forwarding rules that send copies of incoming messages to an external address. This lets them monitor your communications even after you’ve changed your password. Check for:- Forwarding addresses you didn’t add (Settings → Forwarding in Gmail, or Mail Flow rules in Microsoft 365)
- Inbox rules or filters that automatically move, delete, or redirect messages
- Delegate access — unauthorized users who’ve been granted access to your mailbox
- Connected apps or third-party integrations with mail permissions
Step 5: Review Financial Transactions
BEC attacks are almost always financially motivated. Attackers frequently use compromised email to:- Send fake invoices to your clients or vendors
- Request wire transfers or changes to payment details
- Access linked financial accounts using password reset emails
- Intercept legitimate payment communications
- Review your business bank and credit card statements for unauthorized transactions.
- Contact your bank’s fraud department if you spot anything suspicious — the sooner you call, the higher the chance of recovering funds.
- If wire transfers were initiated, ask your bank to contact the receiving institution to freeze the funds. Time is critical — the FBI reports that recovery rates are significantly higher when reported within 24-48 hours.
- Check payroll systems to ensure no unauthorized changes were made to direct deposit information.
Step 6: Notify Your Contacts
This feels uncomfortable, but it’s essential. If an attacker had access to your email, they may have sent messages to your clients, vendors, or partners — and those messages could contain malware links, fake invoices, or fraudulent payment instructions. Send a clear, honest notification to:- Clients and customers who may have received messages from your account
- Vendors and suppliers — especially those you exchange payment information with
- Internal team members who may have received instructions from the compromised account
Step 7: Document Everything
Thorough documentation protects you legally, supports insurance claims, and helps investigators track down the attackers. Record the following:- When you first noticed the compromise (date and time)
- What unauthorized activity occurred (emails sent, data accessed, financial transactions)
- Screenshots of suspicious forwarding rules, login activity, and sent messages
- IP addresses and locations from the login history (most email providers show this)
- A list of everyone who was notified and when
Step 8: Report to the FBI’s IC3
If your business suffered financial loss from a BEC attack, report it to the FBI’s Internet Crime Complaint Center at ic3.gov. This is the primary federal resource for reporting cybercrime. When filing your IC3 complaint, include:- Details of the fraudulent transaction (amount, date, recipient account)
- Any email headers or IP addresses associated with the attack
- Communication records related to the fraud
BEC Recovery Timeline: What to Expect
Recovery doesn’t happen overnight. Here’s a realistic timeline:| Timeframe | Action |
| First 30 minutes | Change password, revoke sessions, enable 2FA |
| First 2 hours | Check forwarding rules, review financial activity, contact your bank |
| First 24 hours | Notify contacts, document the incident, report to IC3 |
| Days 2-7 | Full audit of all connected accounts, review access logs, assess data exposure |
| Weeks 2-4 | Implement long-term security improvements (email authentication, team training, security policies) |
| Ongoing | Regular monitoring, periodic security reviews, phishing awareness training |
Get a FREE Audit
We'll perform a comprehensive SEO, AEO, GEO & CRO audit of your website — completely free — and show you exactly how to outrank your competitors.
Don't have a site yet? Get in touch →
When to Bring in Professional Help
Not every business has an in-house IT team — and even those that do may not have incident response expertise. Consider bringing in professionals if:- You’re unsure whether the attacker still has access to your systems
- Financial losses have occurred and you need forensic evidence
- Your website or other digital assets may also be compromised
- You need to implement proper email authentication protocols like DMARC, SPF, and DKIM to prevent spoofing
- You want a thorough security audit of your entire web presence
How to Prevent Future BEC Attacks
Once you’ve recovered, don’t just go back to business as usual. Implement these protections to avoid a repeat:- Set up email authentication protocols. DMARC, SPF, and DKIM verify that emails sent from your domain are legitimate and help prevent attackers from spoofing your address. These are essential for any business — learn how they work in our guide to DMARC, SPF, and DKIM.
- Train your team. Human error is the number one attack vector. Regular phishing protection training helps your team recognize suspicious emails before they click.
- Use a password manager. Eliminate password reuse across your organization.
- Enable 2FA on every business account. Email, banking, social media, hosting — all of it.
- Establish verification procedures. Require phone call confirmation for any wire transfer or payment change request, no matter who it appears to come from.
- Monitor your accounts. Set up login alerts and review access logs regularly.
Frequently Asked Questions
How do I know if my business email has been compromised?
Can I recover money lost in a business email compromise attack?
How long does it take to fully recover from a BEC attack?
Should I notify my customers if my business email was hacked?
Put this into action with eSEOspace
We help businesses grow with maintenance & support that actually performs. Explore the services behind this guide:
Get a FREE GEO/AEO/SEO Audit
We'll analyze your site's SEO, GEO, AEO & CRO — completely free — and show you exactly how to get found across Google and AI answers.
Don't have a site yet? Get in touch →
Great — your audit is on the way!
We'll send your free SEO/GEO/AEO/CRO audit within the next few hours. Where should we send it?
You're all set! ✓
Your free audit is being prepared — check your inbox in the next few hours. Talk soon!
On this page
- Key Takeaways
- Step 1: Change Your Password Immediately
- Step 2: Revoke All Active Sessions
- Step 3: Enable Two-Factor Authentication (2FA)
- Step 4: Check Email Forwarding Rules and Filters
- Step 5: Review Financial Transactions
- Step 6: Notify Your Contacts
- Step 7: Document Everything
- Step 8: Report to the FBI’s IC3
- BEC Recovery Timeline: What to Expect
- When to Bring in Professional Help
- How to Prevent Future BEC Attacks
- Frequently Asked Questions






