Incident Response

What to Do in the First Hour After a Business Email Compromise

A woman in a suit on a phone call, working at a laptop displaying security warning alerts, with urgent documents on her desk

A business email compromise can feel like someone has walked into your office, picked up your company stamp, and started sending instructions in your name.

It is stressful, but the first hour is not the time to panic or argue about how it happened. It is the time to contain the damage, protect payments, and preserve the evidence you may need later.

This guide is written for Australian small businesses that have discovered, or strongly suspect, that an email account has been accessed without permission. It is practical, plain-English, and focused on what to do first.

What is a business email compromise?

A business email compromise is when someone gains access to a real business email account and uses it to commit fraud, steal information, or monitor conversations.

It is different from a fake spam email. The criminal may actually be inside the mailbox, reading sent items, watching invoices, and sending messages from the real account.

Common signs include:

  • Customers or suppliers reporting strange emails from your address.
  • Invoices being sent with changed bank details.
  • Emails disappearing, being marked as read, or being forwarded somewhere unexpected.
  • New inbox rules you did not create.
  • Login alerts from unusual locations or devices.
  • Staff saying their password no longer works.

If payments, payroll, client records, contracts, or supplier details are handled through that mailbox, treat it as urgent.

The first rule: contain first, investigate second

In the first hour, your goal is not to fully understand the whole incident. Your goal is to stop the attacker using the account right now.

Many businesses lose valuable time looking through emails, debating who clicked what, or trying to work out how long the attacker has been there. That can wait. If the attacker still has access, they can keep sending messages, changing rules, and covering their tracks.

Think of it like a burst pipe. First turn off the water. Then work out what caused it.

First hour emergency checklist

Use this checklist as your immediate response plan. If you have an IT provider, call them straight away and ask them to work through these steps with you.

1. Stop using the affected mailbox for normal work

Do not keep sending normal emails from the affected account. Do not reply to suspicious messages from inside the same mailbox.

If you need to coordinate internally, use another trusted channel such as a phone call, Teams chat, or a different confirmed email account. Assume the attacker may be reading the compromised mailbox until access has been removed.

2. Disable active sessions

Changing the password is important, but it may not be enough by itself.

Modern email systems such as Microsoft 365 and Google Workspace often keep people signed in across phones, laptops, browsers, and apps. If a criminal already has an active session, they may stay connected even after a password change unless those sessions are ended.

Ask your IT administrator to sign the user out of all devices and revoke active sessions. In plain English, this kicks everyone out and forces a fresh login.

This should be done before or at the same time as the password reset.

3. Reset the password properly

Reset the affected account password to something new, long, and not used anywhere else.

Do not change it to a small variation of the old one. If the old password was BlueDog2024, do not use BlueDog2025. Choose a strong passphrase instead, such as a few unrelated words joined together.

If the same password may have been used for banking, accounting software, social media, supplier portals, or remote access, those passwords should also be changed. Reused passwords are a common way one problem turns into several.

4. Turn on or check multi-factor authentication

Multi-factor authentication, often called MFA, means the user needs something extra as well as a password, such as an app approval or code.

If MFA was not enabled, enable it immediately. If it was enabled, check whether the attacker added a new method, such as their own phone number or app.

Remove anything you do not recognise. Also check for backup codes or alternative email addresses that may have been added without approval.

5. Check mailbox rules and forwarding

This is one of the most important steps and it is often missed.

Criminals commonly create hidden-looking mailbox rules to move certain emails out of sight. For example, they may send messages containing words like invoice, payment, bank, payroll, remittance, or quote straight to deleted items or an archive folder.

They may also set up forwarding so copies of your emails go to an outside address.

Check for:

  • Inbox rules you did not create.
  • Rules that delete, archive, move, or mark messages as read.
  • Forwarding to unknown external addresses.
  • Delegates or shared mailbox access you do not recognise.
  • Automatic replies that mention changed payment details.

Do not just turn off the obvious suspicious rule and move on. Record what you found first, then remove it.

6. Warn anyone who may pay you or be paid by you

If there is any chance the attacker sent payment instructions, changed bank details, or accessed invoice conversations, act quickly.

Call key customers, suppliers, bookkeepers, and anyone currently dealing with invoices. Use a trusted phone number you already have on file, not a number from a suspicious email.

Tell them plainly:

  • Your business is investigating unauthorised access to an email account.
  • They should not act on recent payment or bank detail changes sent by email.
  • They should verbally confirm bank details before making any payment.
  • They should contact you immediately if they received unusual instructions.

Speed matters here. A short phone call can stop money leaving the wrong account.

7. Preserve evidence before cleaning up too much

It is natural to want to delete the suspicious emails and remove anything embarrassing. Do not do that in the first hour.

You may need evidence for your insurer, bank, police report, legal advice, or a privacy assessment. Removing items too quickly can make it harder to understand what happened.

Preserve:

  • Suspicious emails, including full message details if your IT provider can capture them.
  • Login alerts and sign-in history.
  • Mailbox rules and forwarding settings before they are removed.
  • Examples of fraudulent invoices or bank detail changes.
  • Names of people who reported unusual emails.
  • Times and dates of key events.

If you are unsure, take screenshots and save copies in a secure location outside the affected mailbox. Your IT provider can also export logs and mailbox information properly.

8. Check whether money has moved

Contact your bank immediately if there is any chance funds have been sent to the wrong account. Do not wait until the full investigation is complete.

Ask whether the payment can be stopped, recalled, or flagged. If a customer or supplier made the payment, ask them to contact their bank as well.

Bank recovery is time-sensitive. The earlier the bank is told, the better the chance of action.

9. Notify your cyber insurer if you have one

If your business has cyber insurance, check the policy process and notify the insurer early.

Some policies require prompt notification and may have preferred incident response providers, legal contacts, or forensic steps they want followed. Calling them early can help avoid accidentally affecting a claim.

Do not assume the incident is too small. If there was unauthorised mailbox access, possible payment fraud, or exposure of client information, it is worth notifying them.

10. Decide who else needs to know

After the first containment steps, you may need to consider whether personal information was accessed and whether any formal notification is required.

This depends on what was in the mailbox, who was affected, and the likely risk of harm. For example, a mailbox containing tax file numbers, identity documents, health information, contracts, or payroll records is more serious than a mailbox with general enquiries only.

Get advice before making broad public statements. But do not ignore the issue. Clear, timely communication is usually better than silence.

What not to do in the first hour

A few well-meaning actions can make the situation worse.

  • Do not email everyone from the affected account before it is secured.
  • Do not delete suspicious emails before preserving evidence.
  • Do not assume a password reset alone has fixed it.
  • Do not trust bank details received by email during the incident.
  • Do not let the affected user keep working as normal until sessions, rules, and access have been checked.
  • Do not delay calling the bank if money may be involved.

A simple first-hour action plan

If you only remember one section, use this order:

  1. Stop using the affected mailbox for normal work.
  2. Call your IT provider or administrator.
  3. Sign the account out of all devices and disable active sessions.
  4. Reset the password and check MFA methods.
  5. Check mailbox rules, forwarding, delegates, and automatic replies.
  6. Warn customers, suppliers, and accounts staff about payment risks.
  7. Preserve emails, screenshots, logs, and suspicious settings.
  8. Contact the bank if any payment may be affected.
  9. Notify your cyber insurer if you have one.
  10. Plan the next steps, including a wider mailbox and data review.

After the first hour: do not stop at the one mailbox

Once the immediate risk is contained, the next step is to understand the bigger picture.

You should check whether other accounts were accessed, whether the same password was reused, and whether the attacker had access to shared mailboxes, cloud files, accounting systems, or customer records.

You should also review how the compromise happened. It may have come from a fake login page, a stolen password, weak MFA, an infected personal device, or an old account that was never disabled.

The lesson is not to blame one person. The aim is to close the gap so it does not happen again.

Need help right now?

If you suspect a business email compromise, act quickly and keep the response calm. Contain access first, protect payments, preserve evidence, and get the right people involved early.

JCPIT Support helps Australian small businesses respond to email compromise incidents and strengthen their systems afterwards. If you are not sure whether your business is exposed, book JCPIT’s free security check and we will help you identify the practical steps to reduce your risk.

Jake
Jake
JCPIT Support — Keeping IT Simple.
← Previous Article
The 7 Microsoft 365 Settings Every Small Business Should Check