Your preparation
0 of 0 safeguards readyMake the next decision with evidence
Regain the mailbox and identity provider, stop hidden persistence, then trace every financial, customer, and account-recovery action the attacker could perform.
Capture before evidence disappears
- Export identity and mailbox sign-in events, IP addresses, devices, session IDs, MFA changes, OAuth grants, app passwords, and recovery-method changes.
- Record forwarding rules, inbox rules, delegates, shared-mailbox access, sent and deleted messages, filters, transport rules, and mailbox audit events.
- Search for password resets, invoices, bank-detail changes, domain or registrar messages, customer exports, and conversations the attacker viewed or answered.
- Preserve suspicious messages as original files with headers. Screenshots alone omit routing and authentication evidence.
Decisions that change the response
| Question | Act when | Action |
|---|---|---|
| Disable the mailbox? | An attacker still has sessions, rules, or recovery control and targeted revocation is uncertain. | Suspend sign-in, preserve mail flow, and provide a known-good emergency contact. |
| Warn payment contacts? | The mailbox handled invoices, payroll, refunds, procurement, or bank-detail changes. | Call affected parties using known numbers. Freeze pending changes and verify recent payments. |
| Treat messages as exposed data? | The attacker accessed search, mail, attachments, or exports containing personal or confidential information. | Start a data-impact assessment based on accessible messages, not only confirmed downloads. |
Proof that recovery worked
- All sessions, app passwords, OAuth grants, delegates, rules, and recovery methods are enumerated and approved.
- Fresh tests confirm external forwarding, auto-delete, impersonation, and unauthorized sending no longer work.
- High-risk account resets, financial requests, and customer conversations are reconciled with trusted owners.
- DMARC reports and mailbox audit logs show no continuing spoofing or unexplained access during monitoring.
Controls to put in place
- Require phishing-resistant MFA for mail and the identity provider; disable legacy authentication.
- Alert on forwarding rules, OAuth grants, recovery changes, impossible travel, and mailbox delegation.
- Require out-of-band verification for bank, payroll, password-reset, and domain changes.
- Keep two emergency administrators and customer-contact channels outside the email tenant.
Use a test mailbox to create a hidden forwarding rule and OAuth grant. A second administrator must find both, revoke every session, verify a recent invoice, and publish an alternate contact within 20 minutes.
Involve the mail provider, bank or payment processor, insurer, counsel, and law enforcement when money moved, tax or payroll data was exposed, customers were impersonated, or the attacker retains tenant-level control.
What this means
Business email is usually the recovery key for every other service. A password change alone may not remove forwarding rules, active sessions, OAuth grants, app passwords, delegates, filters, or administrator changes.
Assume messages and attachments were read during the confirmed access window. Payment instructions and password resets sent through the account need special review.
Warning signs
- Sign-in, password-reset, recovery, or 2FA alerts you did not request.
- Sent, deleted, archived, or forwarding activity you do not recognize.
- Customers receive unusual invoices, file links, or payment changes.
- Mail rules hide security alerts or replies.
- A user, administrator, OAuth app, delegate, or recovery method is unfamiliar.
Recover now
First 15 minutes
- Use a trusted device. If malware or session theft is possible, do not recover from the affected computer.
- Secure a known administrator. Reset its password, use phishing-resistant 2FA, and verify recovery methods.
- Suspend or reset the affected mailbox. Revoke sign-in cookies, sessions, OAuth tokens, app passwords, and mobile access using the provider’s admin controls.
- Preserve logs. Export sign-in, admin, OAuth, email, forwarding, and audit events before making broad changes.
- Warn about payment fraud through another channel. Tell staff and high-risk contacts to verify new payment or password-reset instructions verbally.
Today
- Review forwarding, filters, delegates, inbox rules, recovery details, app passwords, OAuth apps, groups, aliases, and administrator roles.
- Build the access window from sign-in and audit logs.
- Identify password resets, invoices, file shares, and sensitive messages accessed or sent during that window.
- Secure every account recoverable through the mailbox, starting with password manager, domain, cloud, source control, payments, banking, and payroll.
- Contact recipients of fraudulent messages using a verified channel.
- Get legal and security advice when personal data, contracts, financial records, or regulated information may have been exposed.
Verify recovery
- Old passwords, sessions, OAuth grants, app passwords, and recovery methods fail.
- Forwarding, filters, delegates, aliases, groups, and administrator roles are expected.
- No unexplained sign-in or message activity appears during a monitoring period.
- High-risk services have independent strong 2FA and correct recovery details.
- Fraudulent payment instructions have been identified and corrected.
Prepare now
Access
- At least two administrators use separate named accounts.
- Administrators use security keys or passkeys where supported.
- Recovery accounts are secured and do not form a circular dependency.
- Users cannot install unrestricted OAuth apps without review.
Detection
- Sign-in, forwarding, OAuth, and administrator-change alerts are enabled.
- Audit logs are retained long enough to investigate.
- Payment-detail changes require verification outside email.
- Domain email authentication uses SPF, DKIM, and DMARC.
Practice
- A second administrator can suspend a test user, reset sessions, find forwarding rules, and review sign-in logs.
Common mistakes
- Changing only the password. Sessions, tokens, rules, and app passwords may remain.
- Using email to warn about an email compromise. The attacker may read or alter the warning.
- Securing downstream accounts too late. Email can reset them while the attacker still has access.
- Deleting rules before recording them. You lose useful evidence about intent and scope.
- Ignoring sent payment changes. Business email compromise often targets invoices, not data.
Sources
- Google Workspace: Identify and secure compromised accounts
- Google Workspace: Reset a user’s password and sign-in cookies
- Google: Secure a hacked or compromised account
- Google Workspace: Troubleshoot administrator sign-in