forumNew topic

Emails are being sent from our Gmail accounts in other people's names, accounting sent 50k

ZZafer S***Member
Job title
Store associate
Sector
Insurance
Organization type
sole proprietorship
Joined
Dec 2025
Message
67
#1

Customers are calling: 'Are we depositing money to the account, email from Accounting'. But the Accounting manager says 'I didn't write any of that'. Our Gmail accounts were hacked but even if we change the password, emails are still being sent in someone else's name.

Worse: a customer paid a bank instruction to an email address named 'muhasebe@mail.com', 50 thousand lira. The hacker writes 'muhasebe' in the email subject but actually sends it from another account.

I'm wondering if someone inside did this. I changed passwords, Google 2FA is active but emails are still being sent. I asked IT, they say 'our hub apps have unlimited access'.

EErcan G***MemberCommunity member
Joined
Dec 2023
Message
282
Most Helpful#2

This scenario isn't 'account takeover', it's 'sender name spoofing' (email spoofing). The hacker is sending mail from their own server by writing the mail header as a fake address.

Things to do immediately for Gmail: 1) Check login history, 2) Revoke apps with login access, 3) Add SPF / DKIM / DMARC records to DNS.

50 thousand lira: complain to police cyber crimes unit + BDDK. There is evidence of fake email (headers), this is a serious crime.

MMurat T***MemberCommunity member
Joined
Apr 2025
Message
53
#3

my gmail got hacked too. even though gmail changed the password, emails are still being sent. i spent 10 mins on google, turned on 2fa and got backup codes. no issues for 6 months

MMehmet C***Member
Job title
Store associate
Sector
Electrical-electronics
Organization type
120-person company
Joined
May 2025
Message
263
#4

did this happen because google 2fa was off? if it was on, how can a hacker log in without a password? maybe the email relay (smtp) account was hacked instead of the main account?

YYiğit A***VeteranCommunity member
Joined
Jan 2025
Message
2
#5

add SPF / DKIM / DMARC immediately. check the 'Mail Forwarding' section in Gmail settings to see if there are any unauthorized forwards.

MMert Y***Member
Job title
Purchasing manager
Sector
Accounting & advisory
Organization type
two-branch business
Joined
Mar 2023
Message
3

Doki · Log management setup · 2024

#6

send an urgent email to clients saying 'accounting instructions will only be confirmed via phone number X, do not trust emails'.

BBurcu Ş***Member
Job title
Social media manager
Sector
Media and publishing
Organization type
workshop
Joined
Mar 2025
Message
406
#7

open Google Security Checkup (myaccount.google.com/security-checkup) and go through all the company's Gmail accounts. check login devices and app passwords for each account.

BBeyza K***MemberCommunity member
Joined
Dec 2022
Message
3
#8

i disagree with you on this point. the answer varies greatly by industry; there is no one-size-fits-all rule.

trying to do this alone is the most expensve way.

FFurkan U***Member
Job title
Administrative manager
Sector
Energy
Organization type
40-person manufacturing company
Joined
Jul 2025
Message
84
#9

Timely topic. When making a decision, first look at what data you have on hand.

Your time to detect an issue directly determines its cost. Good luck with that.

DDilara A***Member
Job title
Data Analyst
Sector
Sports and fitness
Organization type
120-person company
Joined
Aug 2023
Message
113

Doki · Infrastructure migration · 2024

#10

Sorry, but this doesn't apply in every case. If it's your first time start small; scaling comes later.

Your time to detect an issue directly determines its cost. If you post the result here it will help others too.

NNurMember
Job title
Web Designer
Joined
Aug 2024
Message
96
#11

quick summary for newcomers: Start with a small trial; don't commit to everything at once.

of course, it varies if your situation is different.

GGökhan B***Expert
Job title
Information Security Specialist
Sector
Software
Organization type
8-person team
Joined
Nov 2023
Message
20
#12

quick summary for newcomers: An untested backup is not a backup.

EEmine K***MemberCommunity member
Joined
Jan 2026
Message
296
#13

let me write how it's done in practice. tbh trying to do this alone is the most expensiive way.

this is my opinion I'm not claiming it's absolute truth.

CCengizNew member
Job title
Auto repair
Organization type
20-person company
Joined
Jul 2024
Message
27
#14

We need to make a distinction here. Most incidents start with a leaked password, not a vulnerability.

Hope this helps.

ZZehra B***ExpertCommunity member
Joined
Jan 2025
Message
379
#15

I agree.

VVolkan A***Expert
Job title
Operations director
Sector
Jewelry
Organization type
cooperative
Joined
Nov 2022
Message
314
#16

I've been dealing with this for a long time. If permission and scope aren't in writing, don't start that test.

Correct me if I'm wrong.

KKader K***MemberCommunity member
Joined
Oct 2023
Message
6
#17

Correct.

LLevent U***MemberCommunity member
Joined
Mar 2022
Message
270
#18

I partly agree partly disagree. If permission and scope aren't in writing don't start that test.

Hasty decisions become decisions you have to fix six months later. Proven by experience.

DDeniz B***VeteranCommunity member
Joined
May 2025
Message
243
#19

Let me share what happened to me; it might be useful. Start with a small trial; don't commit to everything at once.

Good luck with that.

TTamerMember
Job title
Service network
Organization type
two-branch business
Joined
Jul 2024
Message
78
#20

Thanks, this was very helpful. Taking measures without an inventory leaves doors you haven't seen open.

I'm also curious if anyone does it differently.

Reply