HD Field Guide 08
The first hour after suspected account compromise
Calm containment steps for a suspicious login, stolen session, malicious mailbox rule or account-recovery scam.
Fast action matters, but unplanned changes can destroy evidence or leave active sessions behind. Use a known-clean device and follow your organisation’s incident process where one exists.
Contain the identity, not only the password
Changing a password may not end stolen web sessions or malicious app consent. Revoke sessions, remove unknown devices and review connected applications and authentication methods.
If the account is used to recover other services, protect those linked accounts as well.
Look for attacker persistence
Check inbox and forwarding rules, delegates, filters, automatic replies, app passwords, API tokens and newly registered MFA methods. Review messages sent to contacts or suppliers.
For organisational accounts, security teams should inspect sign-in logs, endpoint evidence and related identities.
Notify people who may be affected
Warn contacts if the compromised account sent requests, links or payment instructions. Use a different trusted channel and be specific about what recipients should ignore or verify.
Document times, actions and evidence for later investigation, reporting and improvement.
Before you close the guide
- Incident reported through trusted channel
- Password, recovery and MFA reviewed from clean device
- Sessions, apps and mailbox persistence removed
- Affected contacts warned and evidence recorded
Continue with primary guidance
This guide provides general educational information. Adapt it to your organisation’s policies, contracts, legal obligations and incident process. For an active incident, use trusted professional and official support channels.