Incident Response

📧 Compromised Email Account

An email account may have been accessed by someone unauthorized (phishing, credential theft, suspicious login).

Right now
  • Change the account password immediately, from a different, trusted device.
  • Enable multi-factor authentication if it wasn't already active.
  • Sign out of all active sessions for the account (most email providers have a "sign out everywhere" option).
  • Check for and remove any suspicious forwarding rules, mailbox delegation, or inbox rules the attacker may have set up.
First few hours
  • Review sent mail and account activity logs for anything sent or accessed while compromised.
  • Notify contacts who may have received phishing emails sent from the compromised account.
  • Check whether the account had access to other systems (password managers, financial tools, cloud storage) that may also need review.
  • Notify your Incident Lead.
Recovery
  • Confirm no persistent access remains (forwarding rules, app passwords, connected third-party apps).
  • Review what sensitive information may have been exposed via the account.
  • Document the incident for your records.
Notification obligations

If the mailbox contained personal data belonging to clients, employees, or other individuals, this may trigger breach notification obligations depending on your state and industry. Consult legal counsel promptly.

Developed and supported by iConsulting — a working vCISO practice.Contact us for vCISO services →