Security & Compliance

What to Do If a Business Mailbox Is Compromised — 2026

2,681 VIEWS
5 COMMENTS
June 9, 2026

What to Do If a Business Mailbox Is Compromised

Act like minutes matter. If someone controls you@yourdomain.com on MailShrine (or any host), they can reset other accounts, invoice fraud victims, and hide their tracks with inbox rules.

This is an operations playbook, not a forensic or legal brief. For privacy notifications under Nigerian rules, see NDPR basics and consult counsel when personal data may be exposed.


Real-life example: Northline Supplies

Kemi noticed clients asking about “wire instruction” emails she never sent. Her Sent folder showed messages she didn’t write, and a filter silently moved mail containing invoice to Archive.

She followed the sequence below: kill sessions → reset password → enable 2FA → purge rules → warn clients → harden DNS. Spoofed follow-ups still arrived from lookalikes later — she pointed customers to SPF/DMARC so they could tell compromised vs. forged.


First 30 minutes (stop the bleeding)

OrderActionDone when
1Change the mailbox password from a clean deviceOld password fails
2Sign out / revoke other sessions & app passwordsOnly your device works
3Turn on 2FAAuthenticator required
4Check forwarding + filters/rulesNo silent BCC/forward
5Scan Sent / Trash / Drafts for fraudTimeline noted

Step 1: Use a clean device

Do not reset security settings on the same laptop you suspect is phished. Phone hotspot + a known-clean browser is fine for emergencies.


Step 2: Reset credentials and factors

  1. Change the MailShrine password to a unique 16+ character secret (password policy).
  2. Enable authenticator 2FA; regenerate backup codes.
  3. Revoke IMAP app passwords and OAuth apps you don’t recognise.
  4. If the attacker enrolled their 2FA, use account recovery / support immediately — do not stall.

Step 3: Hunt for persistence

Look for:

  • Auto-forward to an external address
  • Rules deleting or filing security alerts
  • Delegates / shared access you didn’t grant
  • Signature changes pushing fake payment details
  • Drafts of scam templates

Delete malice, screenshot evidence first if you may need police/bank reports.


Step 4: Contain blast radius

  1. Reset passwords on banking, payment gateways, social, and hosting using email reset — attacker may still receive links until you finish Step 2.
  2. Tell finance contacts: “Ignore wire changes until voice-confirmed.”
  3. Check DNS at your registrar for unexpected MX/TXT edits (MX basics).
  4. Confirm SPF/DKIM/DMARC still match MailShrine (spoofing guide).

Step 5: Communicate and prevent repeats

AudienceMessage
StaffCompromised address + what not to click
Key clients / vendorsChannel for verifying payment changes
Host / IT helpTicket with timestamps
Counsel / NDPC path (if required)When personal data likely exposed

Then fix root causes: 2FA everywhere, password manager, phishing drills, DMARC toward reject.


Checklist

  • Password reset from clean deviceCompleted
  • Sessions / app passwords revokedCompleted
  • 2FA onCompleted
  • Forwards and rules auditedCompleted
  • Related accounts resetCompleted
  • Clients warned about payment fraudNot completed
  • DMARC policy reviewedNot completed

Common mistakes

  1. Only changing the password and skipping inbox rules.
  2. Reusing the same password “for ease.”
  3. Assuming every fake From: means compromise (could be spoofing).
  4. Waiting days to warn people who pay invoices.

Next steps

Related on YouTube · 1 of 4
Did Your Email Get Hacked? Here's What To Do!

Citations & References


Written by Isabelle R., Incident Response Educator. Isabelle writes calm, ordered playbooks for first-hour mailbox compromises in small companies.

Discussion

R

Rukiyat Salami

June 19, 2026

The silent invoice filter was exactly our issue. Would have only changed the password without step 3.

T

Tomás Rivera

June 27, 2026

Clean device callout matters — we almost reset MFA on the infected laptop.

A

Aisha Garba

July 5, 2026

Warned vendors the same afternoon and stopped a wire. Spreading this playbook to our accountants WhatsApp group.

B

Ben Cartwright

July 19, 2026

Helpful reminder that a fake From: can still be spoofing. We checked DNS/MX before assuming the password was out.

L

Lola Adeyemi

August 6, 2026

Following the next-steps links to DMARC next. Don’t want a round two.