What to Do in the First 24 Hours After Your Business Email Gets Compromised

Back to Blog
What to Do in the First 24 Hours After Your Business Email Gets Compromised

It's usually a small thing that gives it away. A client calls asking why you sent an invoice with a different account number. Your assistant mentions an email you don't remember sending. Or you just can't log in anymore — the password that's worked for two years suddenly doesn't.

That's the moment. And what you do in the next few hours matters more than almost anything else in your incident response, because most of the damage from a compromised business email doesn't happen at the moment of the breach — it happens in the hours after, while the attacker still has access and you're still figuring out what's going on.

Here's what we tell clients to do, in order, when this happens.

First: stop trying to log in from the compromised device

This sounds backwards, but if there's any chance malware or a keylogger got you into this mess in the first place, logging back in from the same laptop just hands the attacker your new password too. Use a different device — your phone, a colleague's computer, anything clean — for every step that follows.

Change the password immediately, and don't make it a small tweak

Not "Password123!" to "Password124!" — a completely new, long, unrelated password. If your provider supports it (Google Workspace and Microsoft 365 both do), this is also the moment to force a sign-out of all active sessions. Somewhere in your account security settings there's an option like "Sign out of all devices" or "Revoke all sessions" — use it. Otherwise the attacker can still be sitting inside your inbox even after you've changed the password, because their existing session doesn't automatically end just because the password did.

Turn on two-factor authentication if it isn't already on

If it was already on and they still got in, that tells you something — the compromise likely happened through a phishing page that captured both your password and your 2FA code in real time, not through simple password guessing. That distinction matters for what you do next, because it means the entry point was probably a link you clicked, not a weak password.

Check the mailbox rules and forwarding settings

This is the step most business owners skip, and it's the one that causes the most damage weeks later. A common move for someone who compromises a business email isn't to send obvious spam — it's to quietly set up a forwarding rule that sends a copy of every incoming email to an external address, then leave. You could change your password, feel like the crisis is over, and still be leaking every invoice, every client conversation, every contract for months. Go into your mail settings and look specifically for forwarding rules, auto-reply rules, or filters you didn't create. Delete anything unfamiliar.

Check what was actually sent while you were locked out

Look at your Sent folder. This is often where you'll find the real reason for the breach — a message to your finance contact or a client asking them to pay an invoice into a "new" account number. If you find one, call the recipient directly. Not by email, not by replying to the thread — call them. We've seen this exact scenario play out with a logistics company here in Port Harcourt: an attacker sat in the founder's inbox for four days, learned the rhythm of how invoices were normally worded, then sent one convincing enough that a client almost paid it. The only reason it didn't go through was that the client's accountant called to confirm the new account details before releasing payment. That habit — calling to confirm any change in payment instructions — is worth building into your business regardless of whether you've ever been breached.

Tell your team before they hear it from a client

If a client or vendor received a fraudulent email from your address, your staff are going to start fielding confused calls. Get ahead of it. A short message to your team — "our email was compromised, don't act on anything unusual you see from our domain until we confirm it's secure" — costs you two minutes and saves you a much harder conversation later.

Check what else uses that email as a recovery address

Your business email is very likely the recovery address for your bank's business portal, your domain registrar, your hosting account, your social media pages, maybe even your accounting software. If someone had four days of access to that inbox, it's reasonable to assume they had enough time to identify which of these accounts matter and attempt a password reset on at least one of them, though this depends entirely on how deliberate and skilled the attacker was. Go through your important accounts and check for any password reset emails or login notifications you don't recognize.

Now — figure out how it actually happened

This is where most businesses stop too early. They fix the password, breathe a sigh of relief, and move on without ever finding out what let the attacker in. If you don't know the entry point, you have no real reason to believe it won't happen again next month. Was it a phishing link? A password reused from another account that was breached elsewhere? A public Wi-Fi login without a VPN? Malware from a downloaded file? We covered the more common entry points in a separate piece on how Nigerian businesses actually get hacked, and the pattern that shows up again and again isn't sophisticated attackers breaking through firewalls — it's ordinary human moments, a tired click on a Monday morning, a password typed into a page that looked close enough to the real one.

What about the Nigeria Data Protection Act?

If the compromised inbox held personal data belonging to customers — names, phone numbers, addresses, payment details — the Nigeria Data Protection Act 2023 is relevant here, not just as a compliance checkbox but as an actual obligation. I don't have the specific reporting thresholds and timelines from the Act in front of me to state precisely when a breach must be reported to the Nigeria Data Protection Commission, and getting that wrong in either direction — over-reporting or under-reporting — isn't something to guess your way through. If personal customer data was exposed, this is worth a direct conversation with a lawyer familiar with the Act, ideally within the same week the breach is discovered, not after the dust has settled.

The part nobody wants to hear

If this happened to you, the honest question to sit with isn't just "how do I fix this" — it's "why did this work." Was it because nobody on your team had ever been shown what a phishing email actually looks like? Was it because the same password was sitting on three different accounts? Was it because two-factor authentication felt like an inconvenience you kept meaning to set up? None of this is said to make you feel careless — these are genuinely common gaps, and most businesses only close them after something like this happens. But closing them now, while the memory is fresh and the cost of the near-miss is still visible, is a lot cheaper than closing them after the second incident.

The first 24 hours are about containment. The week after is about understanding what actually happened. Skip the second part, and you haven't really solved anything — you've just reset the clock until it happens again.

Keep reading

Related Posts

Newsletter

Want more insights like this?

Subscribe for the latest tech news, tips, and updates from Easy World Techs.