HD Field Guide 08

The first hour after suspected account compromise

Calm containment steps for a suspicious login, stolen session, malicious mailbox rule or account-recovery scam.

Control area
Incident response
Audience
Everyone
Reading time
6 min
Reviewed
16 July 2026

Fast action matters, but unplanned changes can destroy evidence or leave active sessions behind. Use a known-clean device and follow your organisation’s incident process where one exists.

Contain the identity, not only the password

Changing a password may not end stolen web sessions or malicious app consent. Revoke sessions, remove unknown devices and review connected applications and authentication methods.

If the account is used to recover other services, protect those linked accounts as well.

Look for attacker persistence

Check inbox and forwarding rules, delegates, filters, automatic replies, app passwords, API tokens and newly registered MFA methods. Review messages sent to contacts or suppliers.

For organisational accounts, security teams should inspect sign-in logs, endpoint evidence and related identities.

Notify people who may be affected

Warn contacts if the compromised account sent requests, links or payment instructions. Use a different trusted channel and be specific about what recipients should ignore or verify.

Document times, actions and evidence for later investigation, reporting and improvement.

Completion check

Before you close the guide

  • Incident reported through trusted channel
  • Password, recovery and MFA reviewed from clean device
  • Sessions, apps and mailbox persistence removed
  • Affected contacts warned and evidence recorded

Trusted references

Continue with primary guidance

Defensive guidance boundary

This guide provides general educational information. Adapt it to your organisation’s policies, contracts, legal obligations and incident process. For an active incident, use trusted professional and official support channels.