T The Triage ManualTechnical Guides for IT Emergencies
P1 · Cyber Incident Response

Business Email Compromise / mailbox takeover

Attacker has access to a mailbox and is sending fraudulent emails (invoice redirects, supplier impersonation). Containment + invoice protection + notification.

Indicators

Likely causes

Diagnostic steps

  1. Reset compromised user's password and revoke all sessions: Revoke-MgUserSign-InSession (Graph) or 'Sign out from all sessions' in admin portal
  2. Re-enrol MFA from clean device — kill any rogue authenticator entries
  3. Audit and remove malicious inbox rules: Get-InboxRule -Mailbox <user>; document before deleting
  4. Check Sent / Deleted / RSS / Conversation History for the attacker's outbound emails. Recover via single-item recovery if within retention
  5. Notify any recipients of attacker emails — especially suppliers / customers receiving fake invoice
  6. Customer or supplier already paid attacker bank details? Notify Action Fraud and the customer's bank within hours

Resolution path

Prevention

Tools

References

becmailbox-compromisephishingexchange-onlinefraud