Act on suspicion, not certainty
An alert, staff report, unexpected sent message, changed payment instruction, or unfamiliar sign-in is enough reason to begin this checklist. Do not wait for complete proof before limiting access. Work from a separate, trusted administrator account and record the time and result of each action.
Contain the account
A password change is only one part of containment. An attacker may still hold an active session, an OAuth token, or another sign-in method.
- Block sign-in or temporarily suspend the account from a trusted administrator session.
- Reset the password, revoke active sessions and tokens, and remove app passwords.
- Review authentication methods and recovery details, then remove anything the user does not recognize.
- If the password was reused, change it on every affected system, starting with administrator and financial access.
Remove persistence and check the scope
Once access is blocked, find out what changed and what the account reached. Work forward from the earliest suspicious sign-in you can identify. Preserve alerts, log exports, message details, and a timeline as you investigate.
In Microsoft 365, use Entra sign-in and audit records, the Microsoft 365 audit log, mailbox rules, message trace, and application consent records. In Google Workspace, review user log events, token activity, Gmail routing and filters, Drive activity, and administrator audit records. Available detail depends on the platform edition and logging already enabled.
Decide who needs to know
Keep the first internal update factual: which account is affected, what access is restricted, who is leading the response, and where staff should report suspicious messages. Separate what is confirmed from what is still being investigated.
If the account sent invoices, payment instructions, or requests for sensitive information, contact affected people through a known phone number or a separate trusted channel. Do not rely on the email thread or account involved in the incident. Contact the bank or payment provider promptly if money may have moved.
Client, insurer, privacy, or regulator notification depends on the information involved, the evidence available, and the organization's legal and contractual duties. Preserve the records and involve the appropriate privacy, legal, insurance, and leadership contacts early. Do not make a broad assurance before the investigation supports it.
Close the path that worked
Finish with a short after-action record covering the entry point, timeline, confirmed impact, containment work, remaining unknowns, and assigned improvements. The useful outcome is a control change with an owner and a due date.

