
It can start with an ordinary-looking email. An employee clicks a link, reaches what appears to be a familiar Microsoft 365 or Google Workspace login page and enters their password. Nothing dramatic happens. The page may even redirect them somewhere legitimate. They carry on working and forget about it. Behind the scenes, however, somebody else may now have their login details.
A compromised business email account can give an attacker access to far more than messages. Email is often connected to cloud storage, customer conversations, password resets, invoices and other business applications. A responsive IT support service London can help identify suspicious activity, secure the affected account and investigate whether the incident has spread beyond one user’s inbox.
Speed matters, but so does knowing what to look for. Sereno IT Support can help businesses protect their technology environment, respond to security incidents and strengthen controls that reduce the likelihood of another compromise.
So, what actually happens after a criminal gains access to a business email account?
What Does a Compromised Email Account Mean?
An email account is compromised when somebody who should not have access manages to sign in or otherwise control it.
This might happen because:
- a password was stolen;
- an employee entered credentials into a phishing website;
- malware captured login information;
- a reused password was exposed elsewhere;
- an attacker obtained an active session;
- a weak authentication process was exploited.
The legitimate employee may still be able to use the account normally. That makes email compromise particularly dangerous. There may be no obvious “Your account has been hacked” warning.
The First Step Is Often Phishing
Phishing remains one of the simplest ways to steal account credentials.
A fake message might claim:
- a document has been shared;
- a password is about to expire;
- a mailbox is full;
- an invoice needs approval;
- a colleague sent a Teams or Google Drive file.
The link leads to a convincing imitation of a real login page. The employee enters their details and, within seconds, the attacker has them too. Sometimes the fake page even redirects the employee to the genuine service afterwards, making the incident less noticeable.
What Does the Attacker Do After Getting Access?
Not every criminal acts immediately. Some remain inside the mailbox quietly. Why?
Because the information in an email account can be more valuable than the account itself.
An attacker may study:
- who approves payments;
- which suppliers the company uses;
- when invoices are expected;
- how executives communicate;
- which clients are valuable;
- how employees sign their emails.
This allows the attacker to understand how the business works before making a move.
Attackers May Search for Financial Conversations
A compromised finance or senior management mailbox can be particularly valuable.
Attackers may search for terms such as:
- invoice;
- payment;
- bank;
- transfer;
- account details;
- purchase;
- payroll.
They are looking for conversations they can exploit. For example, if a supplier is expecting a £20,000 payment next week, the attacker may wait until the right moment and send new bank details.
The fraudulent request appears inside a genuine conversation. That makes it much harder to spot.
Business Email Compromise Can Lead to Payment Fraud
Business Email Compromise – often shortened to BEC – involves using trusted business identities to commit fraud.
An attacker may impersonate:
- a director;
- a supplier;
- a finance employee;
- a lawyer;
- a customer.
The request often involves urgency:
“Please process this today.”
or:
“We’ve changed our bank details. Use the attached information for the next payment.”
The language may sound convincing because the attacker has already read previous conversations.
The Account Can Be Used to Attack Other People
One compromised account can become a launching point for additional attacks. Imagine receiving a file-sharing email from a colleague you speak to every day.
Would you trust it more than an unexpected message from a stranger? Probably. Attackers know this. They may use the compromised account to send phishing messages to:
- colleagues;
- clients;
- suppliers;
- partners.
Because the message comes from a genuine business address, recipients may be more likely to click.
One compromised account can therefore create a chain reaction.
Attackers May Create Hidden Inbox Rules
This is one of the less obvious warning signs.
An attacker may create mailbox rules that:
- move replies into hidden folders;
- delete security warnings;
- forward selected emails;
- hide messages containing certain words.
For example, if the attacker sends fraudulent bank details to a customer, they might create a rule that moves any reply containing “bank details” away from the employee’s normal inbox.
The legitimate user continues working without seeing the conversation. Sneaky? Absolutely – and effective if nobody checks.
Data Can Be Stolen from the Mailbox
Business email often contains sensitive information.
Depending on the employee’s role, this might include:
- personal data;
- contracts;
- invoices;
- customer details;
- internal documents;
- commercial information.
A compromised mailbox can therefore become a data security incident as well as an account security problem. Businesses should investigate what the attacker could access rather than assuming the incident ends when the password is changed.
Cloud Applications May Also Be Exposed
Email accounts rarely exist in isolation.
A Microsoft 365 identity might also provide access to:
- OneDrive;
- SharePoint;
- Teams;
- business applications connected through single sign-on.
A Google Workspace account might provide access to:
- Google Drive;
- Docs;
- Sheets;
- Meet;
- other connected applications.
That means the incident may extend beyond email. The investigation should consider the entire identity rather than only the inbox.
Common Warning Signs of Email Compromise
Some attacks remain hidden, but there are warning signs employees and IT teams can watch for.
| Warning Sign | What It Could Mean |
| Unexpected password reset | Someone may be attempting account takeover |
| Unknown login location | Credentials may have been stolen |
| Missing emails | Inbox rules may be hiding messages |
| Unusual sent messages | Account may be sending phishing emails |
| Unexpected MFA requests | Someone may be trying to sign in |
| New forwarding rules | Email may be leaving the organisation |
| Client reports strange request | Account may be used for impersonation |
Unexpected MFA Requests Should Never Be Ignored
An employee receives a login approval notification on their phone. They are not trying to sign in.
What should they do? Reject it and report it.
Repeated unexpected multi-factor authentication requests may indicate that somebody already knows the password and is trying to complete the login. Employees should never approve an MFA prompt simply to make the notifications stop.
What Should You Do Immediately After Discovering a Compromise?
Once a business suspects an email account has been compromised, the priority is containment. Do not simply change the password and assume the job is finished.
A proper response may involve:
- securing the account;
- ending active sessions;
- reviewing authentication methods;
- checking login history;
- examining mailbox rules;
- checking forwarding settings;
- reviewing sent messages;
- investigating connected applications;
- assessing data exposure.
The exact steps depend on the platform and incident.
Secure the Account
The affected password should be changed to a new, unique credential. Any suspicious authentication methods should be removed.
Active sessions may also need to be revoked so that an attacker who is already logged in cannot simply remain connected after the password changes.
Multi-factor authentication should be reviewed or enabled where appropriate.
Check Inbox Rules and Forwarding
IT should inspect the mailbox for unusual rules.
Look for rules that:
- delete messages;
- move emails automatically;
- forward correspondence externally;
- hide security notifications.
Automatic forwarding settings should also be checked. Removing the attacker from the account is not enough if a hidden forwarding rule continues sending business email elsewhere.
Review Sign-In Activity
Login records can help establish:
- when suspicious activity began;
- where access originated;
- which devices were used;
- whether multiple accounts are involved.
This information helps determine the scope of the incident. If the suspicious login happened three weeks ago, the investigation needs to consider three weeks of potential activity – not just what happened today.
Check Whether Other Accounts Are at Risk
The affected employee may have reused the same password elsewhere. Other employees may also have received the same phishing message.
IT should therefore consider:
- whether similar messages reached other users;
- whether anyone else clicked;
- whether credentials were reused;
- whether related accounts show unusual activity.
One compromised mailbox should be treated as a possible warning of a wider attack.
Contact Clients or Suppliers When Necessary
If fraudulent emails were sent externally, affected contacts may need to be warned.
This is particularly urgent when messages involve:
- payment requests;
- changed bank details;
- malicious attachments;
- phishing links.
Clear communication can stop another organisation from becoming a victim. It may feel uncomfortable to tell a customer that an account was compromised, but allowing them to act on a fraudulent message would be worse.
What If Money Has Already Been Transferred?
Act immediately. Contact the bank or payment provider using trusted contact details and explain that the transaction may be fraudulent.
Do not use telephone numbers or contact information contained in suspicious emails. The faster financial institutions are notified, the greater the chance that action can be taken.
Consider Whether Personal Data Was Exposed
If an attacker accessed personal information, the incident may have data protection implications.
Businesses should determine:
- what information was accessible;
- whether it was viewed or exported;
- who may be affected;
- what risks the exposure creates.
The Information Commissioner’s Office guidance on personal data breaches explains how organisations should assess breaches and when incidents may need to be reported.
How Can Businesses Reduce the Risk?
No security measure can guarantee that an account will never be attacked. However, several controls can make compromise considerably harder.
Use multi-factor authentication
A stolen password should not automatically provide access to an account.
Use unique passwords
Employees should not reuse business passwords on personal services.
Improve email filtering
Suspicious links, attachments and impersonation attempts should be filtered where possible.
Keep systems updated
Security patches reduce the number of vulnerabilities attackers can exploit.
Monitor suspicious sign-ins
Unusual authentication activity should trigger investigation.
Train employees
People need to recognise phishing, suspicious MFA prompts and unusual financial requests.
Introduce Payment Verification Procedures
Technical controls alone cannot stop every BEC attack. Businesses should also have clear financial procedures.
For example: Never change supplier bank details based solely on an email request.
Instead, confirm the change using a known telephone number or another trusted communication channel.
The same principle can apply to:
- unusual payments;
- urgent executive requests;
- new suppliers;
- large transfers.
A two-minute verification call can prevent a very expensive mistake.
Encourage Employees to Report Mistakes Quickly
Employees sometimes hesitate to report that they clicked a suspicious link. They may feel embarrassed or worry they will be blamed. That delay helps the attacker.
Businesses should create a culture where employees are encouraged to report mistakes immediately. The message should be simple:
Clicked something suspicious? Tell IT straight away.
Fast reporting gives the support team more time to contain the incident.
Why Professional IT Support Matters
Email compromise is not merely a password-reset problem.
A proper response may require investigation across:
- identity systems;
- email;
- cloud applications;
- devices;
- security logs;
- connected accounts.
IT support can also help introduce preventive measures such as MFA, monitoring, secure configurations and employee awareness.
The goal is not simply to recover one account. It is to understand how the incident happened and make the environment harder to compromise next time.
Frequently Asked Questions
Can someone access my email after I change the password?
Potentially. Existing sessions, authentication methods or malicious forwarding rules may remain active, which is why a complete account review is important.
How do I know if a business email has been compromised?
Warning signs include unusual login activity, unknown sent messages, unexpected MFA prompts, hidden inbox rules and reports of suspicious emails from contacts.
Is changing the password enough?
Not always. Active sessions, mailbox rules, forwarding settings and connected applications should also be reviewed.
Should a compromised email account be reported?
It depends on the circumstances. Fraud may need to be reported to relevant authorities, while personal data breaches may create reporting obligations under UK data protection law.
Can MFA prevent business email compromise?
MFA significantly improves account security, although it should be combined with monitoring, employee awareness and other security controls.
Conclusion
A compromised business email account can begin with something as simple as one convincing login page. Yet the consequences can extend far beyond a stolen password.
An attacker may quietly monitor conversations, steal confidential information, create hidden forwarding rules, impersonate employees, redirect payments or use the account to target customers and colleagues.
That is why businesses need to respond quickly and investigate thoroughly.
Secure the affected identity, review account activity, remove suspicious rules, check connected systems and determine whether information or money has been exposed. Then use what happened to strengthen the organisation’s defences.
Most importantly, employees should know that reporting a suspicious click quickly is far better than staying quiet and hoping nothing happened.
One wrong click does not have to become a major business incident – provided the organisation knows what to do next.
Local news needs your support
We are proud that we were at the forefront of reporting on the recent local elections. We can’t do this without the support of our readers.
Independent news outlets like ours – reporting for the community without rich backers – are under threat of closure, turning British towns into news deserts.
If our coverage has helped you understand our community a little bit better, please consider supporting us with a monthly, yearly or one-off donation.
ACT NOW!
Monthly direct debit
Annual direct debit
£5 per month supporters get a digital copy of each month’s paper before anyone else, £10 per month supporters get a digital copy of each month’s paper before anyone else and a print copy posted to them each month. £50 annual supporters get a digital copy of each month's paper before anyone else.
More information on supporting us monthly or yearly
More Information about donations








Enjoying Enfield Dispatch? You can help support our not-for-profit newspaper and website from £5 per month.