forumNew topic

Employee's Microsoft account compromised — what should we do in the first hour?

TTaner A***Veteran
Job title
Intern
Sector
Advertising and promotion
Organization type
two-branch business
Joined
Mar 2025
Message
406
#1

We are a 14-person logistics agency based in Frankfurt. This morning, suspicious emails regarding invoice updates and changed bank details started being sent to clients from our operations manager's corporate email account. When we accessed the admin portal, we noticed active sessions logged in from various overseas IP addresses, and certain incoming emails were automatically being moved to the deleted items folder.

We pay an 800 Euro monthly maintenance fee to an outsourced local IT firm, but we currently cannot reach our technical contact by phone. The situation is critical because our clients might assume these emails containing payment details are genuine and transfer funds.

We are currently in the admin portal. Without causing further operational disruption, exactly what steps should we take in the first hour, and in what order?

NNevinMember
Job title
Language school
Joined
Apr 2024
Message
92
Most Helpful#2

Short answer: The most critical actions to take in the first hour are terminating the attacker's sessions, resetting the password, and clearing any forwarding rules created in the background. If you disrupt this order, the attacker may maintain access through an active session or generate a new password.

First, access the admin center to revoke all active sessions for the user and sign them out of all devices. Immediately assign a temporary, complex new password. Next, audit the user's multi-factor authentication methods; the attacker may have registered their own authenticator app or phone number. Delete any unverified authentication devices and configure new ones.

The second critical step is reviewing mailbox rules. Attackers routinely set up rules that dump incoming emails into the trash, hide them, or forward them to an external address. Reset all forwarding and inbox rule lists via both the web interface and the admin center. Finally, export sign-in and audit logs to document which messages the attacker read and which addresses were contacted.

PPınar N***Member
Job title
Human Resources Manager
Sector
Insurance
Organization type
family business
Joined
Jan 2026
Message
249
#3

Send an urgent notice to clients immediately or call them directly. Tell them to disregard any recent emails regarding invoices or bank account changes originating from your systems. If a client issues a wire transfer while you're busy resetting passwords, recovering that financial loss will be far harder than handling the technical fix.

KKoray Ç***Member
Job title
Network Administrator
Sector
Tourism
Organization type
sole proprietorship
Joined
Apr 2025
Message
55

Doki · Penetration test · 2026

#4

Just clicking the sign-out button might not be enough; check APIs and authorized third-party apps as well. Sometimes they connect external app permissions to the account, allowing them to keep reading mail via bearer tokens even after the session is closed. Definitely scan the enterprise applications and permissions list in the portal.

ÖÖzgür A***ExpertCommunity member
Joined
Feb 2025
Message
1
#5

Stay calm and do not delete any records. Panicking administrators sometimes purge the entire inbox or delete the user account; however, under German data protection regulations and local cyber incident notification mandates, you will need those log records. Download the audit logs immediately as forensic evidence.

AAslı Ç***Member
Job title
Production planning
Sector
Consulting
Organization type
300-person organization
Joined
Dec 2025
Message
124

Doki · KVKK compliance consulting · 2026

#6

happened to us last year too. tbh definitely dont skip the rules part they were auto-forwarding and deleting any mail containing the word invoice took us two weeks to realize unfortunately.

BBanu Ş***Member
Job title
Pharmacist
Joined
Mar 2024
Message
81
#7

Once the incident is contained, I recommend contacting your data protection officer. If it is determined that third-party personal data or trade secrets were exfiltrated, you may be required to formally notify the competent supervisory authority and affected clients within statutory deadlines.

İİlknur G***VeteranCommunity member
Joined
Nov 2024
Message
80
#8

The real issue to question is why the firm you pay 800 Euro a month to is unreachable during an emergency. Isn't there an SLA response time clause in your contract? Once this crisis passes, review that agreement, because support that doesn't answer within the first hour provides zero security assurance.

İİbrahim S***Expert
Job title
Store Manager
Sector
Printing
Organization type
20-person company
Joined
Nov 2022
Message
1
#9

Let me summarize what needs to be done right now in order: 1) Terminate the user's sessions from the global admin panel. 2) Delete mailbox forwarding rules. 3) Update the password and multi-factor authentication methods. 4) Back up the sign-in logs for that user over the past 48 hours. 5) Brief the finance and operations teams regarding the fraudulent bank detail emails.

İİbrahim Y***MemberCommunity member
Joined
Dec 2024
Message
182
#10

In short, on the tech side, revoking active sessions, resetting passwords, clearing authentication devices, and wiping forwarding rules are absolute musts. On the administrative side, you need to warn clients over the phone and back up and store system logs in case of a potential data breach risk. You can deal with your IT support provider regarding contract terms later.

RRecep N***MemberCommunity member
Joined
Jul 2023
Message
85
#11

Saved. When you try to change everything at once, nothing settles.

RReyhan K***Member
Job title
Production planning
Sector
Leather
Organization type
early-stage startup
Joined
Dec 2025
Message
385
#12

I have a question. btw payment information changes are never verified through the channel they came from.

Im also curious if anyone does it differently.

YYavuz Ö***Expert
Job title
Graphic Designer
Sector
Cleaning services
Organization type
chain store
Joined
Jul 2023
Message
95
#13

Noted, thanks.

PPolat A***ExpertCommunity member
Joined
Apr 2024
Message
365
#14

How did you solve this? Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Forgotten test environments are more often the entry point than live systems. Hope this helps.

DDamla P***MemberCommunity member
Joined
May 2024
Message
191
#15

I'd appreciate it if you shared the outcome. The answer varies greatly by industry; there is no one-size-fits-all rule.

Of course it varies if your situation is different.

EEbru K***MemberCommunity member
Joined
Aug 2025
Message
113
#16

Correct in theory, but it doesn't work that way in practice. Start with a small trial; don't commit to everything at once.

Payment information changes are never verified through the channel they came from. Just leaving this note, it might be useful.

DDoruk D***Member
Job title
IT manager
Sector
Freight
Organization type
a company within a holding
Joined
Jun 2022
Message
11

Doki · Incident response support · 2026

#17

Three different views emerged, they all complement each other. Payment information changes are never verified through the channel they came from.

That's all, sorry if I went on too long.

PPerihan Ş***MemberCommunity member
Joined
Apr 2024
Message
1
#18

If you're going this route, sort this out first. An untested backup is not a backup.

İİsmail E***Member
Job title
Logistics planning
Sector
Energy
Organization type
medium-sized business
Joined
Jun 2025
Message
144

Doki · E-commerce infrastructure · 2023

#19

id say dont rush then the answer varies greatly by industry; there is no one-size-fits-all rule.

if I were you, I'd go this route.

SSelin T***Member
Job title
Software developer
Sector
Printing
Organization type
40-person manufacturing company
Joined
Oct 2025
Message
409
#20

We need to make a distinction here. Processes without records never improve, because you don't know what to fix.

Reply