Appearance
What to Do When Your Business Email Has Been Hacked
Estimated Time to Fix: 1 hourApplies to: Microsoft 365, Google Workspace, General Security
Article Type: Troubleshooting
Last Updated: 2026-07-21
Summary
Discovering your business email has been hacked is terrifying. For a solo business owner, your email is the master key to everything: your bank, your website, your social media, and your clients. Do not panic. If you follow these steps immediately, you can lock the hacker out and minimize the damage.
Symptoms
- Clients tell you they received a weird email or a fake invoice from you.
- You see emails in your "Sent Items" that you did not write.
- You randomly stop receiving emails from specific clients (because the hacker hid them).
- You receive a "Password changed" alert that you didn't initiate.
Prerequisites
- You must still be able to log into your account, or have the ability to reset the password via SMS/backup email.
Instructions
Step 1: Lock the Hacker Out
Changing your password is not enough. If the hacker is currently logged in, changing the password does not kick them out. You must force a sign-out.
- Change your password: Make it a 14+ character passphrase that you have never used anywhere else.
- Force a Sign-Out:
- Microsoft 365: Go to mysignins.microsoft.com, click Security Info, and look for the option to Sign out everywhere.
- Google Workspace: Go to myaccount.google.com/security, scroll down to Your devices, click Manage all devices, and click Sign out on everything you don't recognize.
Step 2: Delete Malicious Inbox Rules (CRITICAL)
Hackers are smart. They don't want you to know they are in your inbox. They will create "Rules" that automatically move emails from your biggest clients—or emails from your bank—into obscure folders like "RSS Feeds" or "Archive" so you never see them. They may also forward all your email to an external Yahoo address.
- Open Outlook on the web (or Gmail).
- Go to Settings > Mail > Rules.
- Delete any rule you do not explicitly remember creating.
- Go to Settings > Mail > Forwarding.
- If forwarding is turned on to an email address you don't own, turn it off immediately.
Step 3: Turn on MFA
If you had MFA, you wouldn't have been hacked. Turn it on now so it never happens again.
- Download the Microsoft Authenticator or Google Authenticator app on your phone.
- Go to your account security settings and enable Two-Step Verification / MFA.
- Scan the QR code with your phone. (See related articles below for a full guide).
Step 4: Audit the Damage
You need to know what the hacker did while they were inside.
- Check your Sent Items and your Deleted Items (hackers delete their sent mail to hide it).
- Did they send fake invoices to your clients with altered bank routing numbers?
- Did they request password resets for your bank, your domain registrar, or your accounting software?
Step 5: Notify Your Clients
If the hacker sent emails to your clients, you must do the hardest thing: tell them.
Send a brief, professional email to your contacts: "Earlier today, my email account was briefly compromised. If you received an email from me requesting payment to a new bank account, or containing a link to view a 'Secure Document,' please delete it immediately. The issue has been resolved and the account is secure."
Troubleshooting
WARNING
If you cannot log into your account at all because the hacker changed the password and the recovery phone number, you must contact Microsoft or Google Data Protection support immediately. Be prepared to provide legal documentation proving you own the business.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| I'm locked out by the hacker's MFA | Hacker added their own phone | If you are the global admin of a Microsoft tenant, you will have to call Microsoft Support to prove ownership. It can take several days to regain access. |
| Emails are still going missing | Missed a forwarding rule | Double-check Outlook Web > Settings > Mail > Forwarding. Also, check if they added an "Alias" to your account in the Admin Center. |