What to Do If Your Credentials Are Breached

A first-hour checklist for blocking access, removing persistence, checking impact, and deciding who needs to know.

01

Act on suspicion, not certainty

An alert, staff report, unexpected sent message, changed payment instruction, or unfamiliar sign-in is enough reason to begin this checklist. Do not wait for complete proof before limiting access. Work from a separate, trusted administrator account and record the time and result of each action.

02

Contain the account

A password change is only one part of containment. An attacker may still hold an active session, an OAuth token, or another sign-in method.

  • Block sign-in or temporarily suspend the account from a trusted administrator session.
  • Reset the password, revoke active sessions and tokens, and remove app passwords.
  • Review authentication methods and recovery details, then remove anything the user does not recognize.
  • If the password was reused, change it on every affected system, starting with administrator and financial access.
03

Remove persistence and check the scope

Once access is blocked, find out what changed and what the account reached. Work forward from the earliest suspicious sign-in you can identify. Preserve alerts, log exports, message details, and a timeline as you investigate.

IdentityReview sign-ins, authentication methods, recovery details, administrator changes, and unfamiliar devices.
EmailCheck inbox and forwarding rules, delegates, sent and deleted messages, and message delivery records.
ApplicationsReview OAuth grants, third-party applications, service principals, and other authorized connections.
DataCheck SharePoint, OneDrive, Drive, and Shared Drive activity for access, downloads, and sharing changes.
DevicesIdentify the device used during the compromise and check it before allowing the user to sign in again.

In Microsoft 365, use Entra sign-in and audit records, the Microsoft 365 audit log, mailbox rules, message trace, and application consent records. In Google Workspace, review user log events, token activity, Gmail routing and filters, Drive activity, and administrator audit records. Available detail depends on the platform edition and logging already enabled.

04

Decide who needs to know

Keep the first internal update factual: which account is affected, what access is restricted, who is leading the response, and where staff should report suspicious messages. Separate what is confirmed from what is still being investigated.

If the account sent invoices, payment instructions, or requests for sensitive information, contact affected people through a known phone number or a separate trusted channel. Do not rely on the email thread or account involved in the incident. Contact the bank or payment provider promptly if money may have moved.

Client, insurer, privacy, or regulator notification depends on the information involved, the evidence available, and the organization's legal and contractual duties. Preserve the records and involve the appropriate privacy, legal, insurance, and leadership contacts early. Do not make a broad assurance before the investigation supports it.

05

Close the path that worked

AuthenticationRequire phishing-resistant MFA for administrators and other high-risk accounts where the platform supports it.
PrivilegesRemove unnecessary administrator roles, delegates, guest access, and shared credentials.
Email and appsRestrict automatic forwarding and application consent, then monitor for unexpected changes.
MonitoringAlert on risky sign-ins, new authentication methods, forwarding rules, and unusual sending.
PeopleBrief affected staff on the actual lure or behaviour used, without turning the review into a blame exercise.

Finish with a short after-action record covering the entry point, timeline, confirmed impact, containment work, remaining unknowns, and assigned improvements. The useful outcome is a control change with an owner and a due date.

Want this handled for your organization?

Book a call to see how Teclara helps businesses and nonprofits put these controls in place without disrupting day-to-day work.