What to Do If Your Business Email Gets Hacked (NZ Checklist)
Start here for the first 15 minutes, same-day clean-up, provider evidence packet, customer/cashflow checks, common misses, and a basic prevention baseline.
Reading path
A calm order to work through mailbox compromise, MFA recovery, and persistence checks (forwarding rules, delegates, and third-party app access). If a business mailbox was compromised, start here.
Start here
The fastest way to stop ongoing harm is to reset access and remove persistence. Then you can review sign-in history, inbox rules, and deliverability records without racing an attacker.
Start here for the first 15 minutes, same-day clean-up, provider evidence packet, customer/cashflow checks, common misses, and a basic prevention baseline.
Identity/MFA redundancy, admin control, mailbox hygiene, and handover basics that prevent repeat incidents.
Use this when the recovery work involves admin access, MFA reset paths, shared mailboxes, device sign-in, or tenant settings.
Use this when the aftermath includes spoofing, rejected mail, suspicious forwarding, or domain-authentication cleanup.
First choice
The deeper business email compromise checklist is the best first stop when there may be active access, hidden forwarding, payment fraud, or provider escalation ahead. Use the other pages after access is contained and the evidence trail is clear.
It covers password reset, session revocation, forwarding/rule checks, app access, recovery methods, and what to preserve before deleting suspicious messages.
It helps gather timeline notes, mailbox-control evidence, message evidence, domain/DNS evidence, and the details a provider or bank may ask for later.
Once the incident is stable, continue through Microsoft 365 setup, DNS/email authentication, deliverability, and safer AI/data-handling boundaries.
Decision path
Not every email problem is a security incident. Some are normal Microsoft 365 setup, some are DNS or deliverability problems, and some need a recovery-first response because there may still be active access or hidden persistence. Pick the path that matches the failure mode before changing settings.
Use the incident checklist when there are suspicious sign-ins, unexpected forwarding, missing messages, payment-detail changes, or signs that someone else may still have access.
Use Microsoft 365 support when the issue is MFA recovery, tenant admin access, mailbox rules, shared mailbox access, or a provider escalation packet.
Use Microsoft 365 setup when the work is baseline setup: admin ownership, MFA methods, Teams/SharePoint/OneDrive, mailbox basics, and first-week verification.
Use deliverability support when the issue is SPF, DKIM, DMARC, sender inventory, suspicious sending, spam placement, or bounce evidence.
Use DNS and routing support when nameservers, MX records, TXT records, TTL, propagation, provider routing, or different network results are involved.
Use the IT support reading path when the mailbox issue sits beside device access, remote support, Wi-Fi, fibre, or handover documentation.
Recovery stages
A mailbox incident becomes much easier to manage when the first response is staged. Contain access, remove persistence, check business impact, then harden the setup. That order avoids losing useful evidence while still stopping the immediate problem.
Reset the password, review MFA methods, sign out active sessions, check admin roles, and confirm there is a safe recovery path that does not rely on the compromised account.
Look for forwarding rules, hidden inbox rules, suspicious delegates, app passwords, OAuth consents, shared-mailbox access, and unexpected transport behaviour.
Review recent invoices, payment-detail changes, customer replies, deleted mail, sent items, and any accounts that use the mailbox for password resets.
Write down what changed, update recovery details, add MFA coverage, improve admin separation, and keep short notes for staff or future support.
Evidence notes
Even for an SME, a short timeline helps with provider tickets, insurance questions, customer follow-up, and future prevention. The timeline does not need to be dramatic; it needs to be clear enough that another person can understand what happened.
Capture the first noticed symptom, affected accounts, sign-in locations or timestamps, rules removed, password resets, MFA changes, and provider ticket numbers.
Preserve suspicious messages, headers, forwarding destinations, transaction details, screenshots, and customer reports before deleting or overwriting them.
Check whether the same password was reused elsewhere, whether billing or payroll details changed, and whether any third-party app still has mailbox access.
Use the path
The useful order is containment, persistence checks, evidence notes, then prevention. Do not start by changing every setting at once; that makes it harder to know what fixed the problem and harder to explain the event to staff, customers, or providers.
Reset passwords, review MFA methods, revoke risky sessions, and confirm there is more than one safe admin recovery path.
Check inbox rules, forwarding, delegates, app passwords, OAuth app consent, shared mailboxes, and suspicious transport behavior.
Write a short timeline with sign-in times, affected accounts, settings changed, customer impact, and provider ticket numbers.
Improve MFA coverage, admin separation, SPF/DKIM/DMARC records, backup access, and staff reporting habits after the mailbox is stable.
Hardening
Once the mailbox is stable again, the next goal is to reduce repeat incidents and reputational damage: correct recovery methods, predictable admin ownership, and basic email authentication records.
Registrar/DNS control points, SPF/DKIM/DMARC basics, and a reversible change workflow.
Practical boundaries that reduce accidental leakage while an incident is still unfolding.
After recovery
Once urgent access is contained, the next value comes from reducing repeat incidents: record ownership, schedule recurring checks, and make support handover evidence easier to find.
Use this route to choose between ownership, DNS routing, Microsoft 365 setup, deliverability, and recovery control points.
Use the maintenance calendar to schedule password, MFA, backup, domain, renewal, and mailbox hygiene checks after the incident is stable.
Use the tools hub for practical launch, maintenance, and planning checklists that make follow-up work repeatable.
Use the services hub when the recovery notes reveal a broader setup, support, deliverability, website, or DNS handover problem.
Use remote support when the next step is evidence gathering, account checks, reversible changes, or a provider-ready handover note.
Use the wider IT path when mailbox recovery touches device access, admin handover, MFA coverage, and ongoing Microsoft 365 support.
Related support
These pages are the next step when a checklist finds a real identity, deliverability, or admin-ownership problem.
Context
If you need current professional context or software project notes, start with the About page and Projects hub.