Appearance
Understanding What to Do When You Suspect Your Account Has Been Hacked — An Employee Incident Response Guide
Applies to: Microsoft 365 (Outlook, Teams, OneDrive, SharePoint), Windows 10, Windows 11
Article Type: Informational
Last Updated: 2026-06-17
Summary
This article is your emergency checklist when you suspect your Microsoft 365 account has been compromised. It walks through the immediate actions to take in the first 15 minutes, how to investigate what happened, how to lock down your account, and when to escalate to IT. Unlike a technical security guide, this is written for the employee who is sitting at their desk thinking "I think I've been hacked — what do I do right now?"
Prerequisites
- A Microsoft 365 account.
- Access to a web browser (even if you cannot access Outlook or other apps).
- No admin rights required — every step in this guide is available to standard users.
Instructions
1. Recognise the Warning Signs
Before you act, confirm you are dealing with a potential compromise. These are the most common indicators:
- Unexpected password change notifications — You receive an email or text saying your password was changed, but you did not change it.
- MFA prompts you did not trigger — Your phone buzzes with an Authenticator approval request when you are not trying to sign in.
- Emails you did not send — Colleagues or contacts tell you they received emails from your address that you did not write.
- Missing or deleted emails — Emails have been read, moved, or deleted without your knowledge.
- Unfamiliar sign-in alerts — You receive a Microsoft security alert about a sign-in from an unfamiliar location, device, or IP address.
- Account locked out — You are suddenly unable to sign in to your account.
- Unexpected forwarding — You notice incoming emails are not arriving, or someone outside your organisation is receiving copies of your mail.
- Apps or services you do not recognise — New apps appear in your connected accounts or app permissions page.
If one or more of these applies to you, proceed immediately to Step 2. Do not wait.
2. Change Your Password Immediately
This is the single most important action. Changing your password revokes most active sessions and blocks an attacker from continuing to access your account.
- Open a browser and go to myaccount.microsoft.com.
- Sign in with your current credentials. If you cannot sign in, skip to Step 3.
- Click Security info in the left menu, then Change password.
- Enter your current password and create a new one that is:
- At least 16 characters long (longer is better).
- Unique — not reused from any other account, past or present.
- A mix of uppercase, lowercase, numbers, and symbols — or a long passphrase (e.g.,
Coffee-Mountain-Laptop-7!Blue).
- Click Submit to save.
- After changing your password, Microsoft signs you out of most other sessions. This means the attacker loses access on any device where they were signed in.
3. If You Cannot Sign In — Use Self-Service Password Reset
If the attacker changed your password and locked you out, you may still be able to regain access.
- Go to passwordreset.microsoftonline.com in your browser.
- Enter your work email address.
- Complete the CAPTCHA verification.
- Choose a recovery method:
- Authenticator app — Approve the notification on your phone.
- Phone — Receive a code via SMS or phone call.
- Alternate email — Receive a code at your backup email address.
- Create a new password and sign in.
- If none of these methods work — for example, the attacker changed your MFA settings — call IT by phone; do not email, as your email may be compromised. Ask them to reset your password and remove the MFA method you do not recognise, and say "my account is compromised and I am locked out" so it is treated as an active incident rather than a routine password reset.
4. Do NOT Approve Any MFA Prompts You Did Not Initiate
This deserves its own step because it is one of the most common attack vectors.
- If your phone shows an Authenticator approval prompt and you are not actively signing in, tap Deny or No, it's not me.
- Attackers who have your password will repeatedly trigger MFA prompts hoping you will approve one by mistake or out of frustration. This is called MFA fatigue or prompt bombing.
- Every time you deny a prompt, the attacker is blocked. Do not approve any prompt unless you are actively signing in at that moment.
5. Check Your Sign-In Activity
After securing your password, review what the attacker may have done.
- Go to mysignins.microsoft.com (or myaccount.microsoft.com > My Sign-ins).
- Review the list of recent sign-in attempts. For each entry, check:
- Location — Is it a city or country you have not been in?
- Device / Browser — Is it a device or browser you do not use?
- Time — Was the sign-in at an hour you would not normally be active?
- Status — Successful sign-ins from unknown locations are the most concerning.
- Write down or screenshot any suspicious entries — IT will need this information.
6. Check for Unauthorised Email Rules and Forwarding
This is critical. Attackers almost always set up hidden email rules to maintain access even after you change your password.
- Open Outlook on the Web (outlook.office.com) — use the web version because it shows the most complete view of your rules.
- Click Settings (gear icon) > View all Outlook settings > Mail > Rules.
- Review every rule in the list. Look for rules that:
- Forward all emails (or emails from specific people) to an external email address.
- Delete incoming messages or move them to obscure folders.
- Mark messages as read automatically.
- Delete any rule you did not create.
- Next, go to Settings > Mail > Forwarding.
- Check whether Enable forwarding is turned on. If it is forwarding to an address you do not recognise, turn it off immediately.
7. Review Connected Apps and Permissions
Attackers can grant malicious apps access to your account. These apps can continue reading your email and files even after a password change.
- Go to myapps.microsoft.com and review the list of apps that have access to your account.
- If you see an app you do not recognise, click on it and select Revoke or Remove.
- Also go to myaccount.microsoft.com > Security info and review your MFA methods.
- If you see an unfamiliar phone number or authenticator device listed, do not remove it yourself — notify IT so they can investigate first. Removing an attacker's MFA method without IT's knowledge may lose forensic evidence.
8. Check OneDrive and SharePoint for Unauthorised Sharing
If an attacker had access to your account, they may have accessed or shared your files.
- Go to onedrive.com and sign in.
- Click Shared in the left menu, then Shared by you.
- Review the list for files or folders you did not share — especially those shared with external email addresses.
- For any suspicious shares, click the … menu next to the file and select Manage access > Stop sharing.
- Check Recent in the left menu to see if files were opened or modified that you did not touch.
9. Report to IT — What to Tell Them
Even if you have secured your account, contact IT so they can take additional server-side actions that you cannot do yourself.
Call IT by phone (do not email if your email was compromised). Tell them:
- What happened: "I suspect my Microsoft 365 account was compromised."
- When you noticed: The approximate time you first noticed something wrong.
- What you have done so far: "I changed my password, checked my sign-in activity, and reviewed my email rules."
- What you found: Share any suspicious sign-in locations, forwarding rules, or unknown apps you discovered.
- Whether you clicked a link or opened an attachment recently — if a phishing email is the suspected entry point, IT needs to know so they can alert other employees.
IT will typically:
- Force-revoke all active sessions across all devices.
- Review server-side audit logs for your account.
- Check whether the attacker accessed other accounts from yours.
- Re-enable or reset your MFA methods.
- Place your account on heightened monitoring.
10. After the Incident — Prevent It from Happening Again
Once IT confirms your account is secure, take these steps to harden your defences:
- Enable additional MFA methods — If you only had SMS verification, add the Microsoft Authenticator app as a stronger second factor. Go to myaccount.microsoft.com > Security info > Add method.
- Review your passwords on other services — If you reused the same password anywhere else (personal email, banking, social media), change those passwords immediately.
- Learn to spot phishing — Most account compromises start with a phishing email. Review the warning signs so you can recognise the next attempt.
- Be cautious with MFA prompts — Never approve an Authenticator prompt unless you are actively signing in at that exact moment.
- Check your security info quarterly — Set a reminder to visit myaccount.microsoft.com > Security info every few months and verify that all listed phone numbers, email addresses, and devices are yours.
Troubleshooting
WARNING
If you cannot sign in to your account and self-service password reset does not work, call your IT helpdesk by phone immediately and ask them to reset your password and revoke every active session on your account. Do not send email (your email may be compromised) and do not wait — every minute an attacker has access increases the potential damage.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| Cannot sign in — password was changed by someone else | Attacker changed the password | Use self-service password reset (Step 3). If that fails, call IT by phone and ask them to reset your password and revoke all active sessions. |
| MFA prompts keep appearing on your phone | Attacker has your password and is trying MFA fatigue | Deny every prompt. Change your password immediately (Step 2). Report to IT. |
| Emails are being forwarded to an unknown address | Attacker set up a forwarding rule | Disable forwarding and delete the rule (Step 6). |
| Colleagues received phishing emails from your address | Attacker sent emails from your account | Change password (Step 2), check sent folder, notify IT so they can warn recipients. |
| Files were shared externally without your knowledge | Attacker shared OneDrive/SharePoint files | Revoke sharing (Step 8) and report to IT. |
| Unfamiliar app has access to your account | Attacker granted a malicious app consent | Revoke the app (Step 7) and report to IT. Do not remove unfamiliar MFA methods without IT guidance. |
| Account locked after multiple failed sign-in attempts | Brute-force attack or attacker testing passwords | Wait for the lockout period to expire (usually 15–30 minutes), then change your password. Ask IT to confirm whether any sign-in succeeded before the lockout, and from where. |