What to Do Immediately After a Business Email Account Is Hacked
Practical steps South African SMBs should take immediately after a business email account is hacked to limit damage, restore access and secure systems.
Introduction
A hacked business email account can be disruptive and dangerous. For South African small and medium-sized businesses (SMBs), timely, decisive action reduces financial loss, reputational damage and regulatory exposure. This guide outlines clear, practical steps to take immediately after an email compromise, with local context and realistic options for businesses in Johannesburg and across Gauteng.
Immediate first actions (first 0–60 minutes)
Act quickly but calmly. Early containment limits what attackers can do with access to your correspondence, calendar and business systems.
1. Confirm the breach
- Identify signs: unexpected password reset emails, unfamiliar sent messages, login alerts from odd locations or devices, or staff reporting missing messages.
- Check recent activity in the webmail or email admin console for unfamiliar IP addresses or devices.
2. Isolate the compromised account
- Temporarily disable or block the account in your email admin panel (Microsoft 365 admin center, Google Workspace console or your hosting control panel).
- If you cannot disable the account, change the password immediately and revoke active sessions if the platform allows it.
3. Notify key personnel
- Inform your IT lead or managed service provider (MSP) — ideally RandTech IT or the company responsible for your support.
- Alert senior management and any staff who may be targeted next, such as finance and HR teams.
Containment and assessment (within the first few hours)
Once immediate containment is in place, assess the scope and impact so you can prioritise recovery steps.
4. Assess what the attacker did
- Review sent items, deleted items and auto-forwarding rules to see if emails were exfiltrated or redirected.
- Check calendar entries for unauthorised meetings and contacts for new or modified entries.
- Search for password reset emails to other services — attackers often use email to reset accounts on banking, cloud or payroll platforms.
5. Identify affected systems and data
- List systems that use the compromised email as a login or recovery address (bank accounts, cloud services, vendor portals).
- Prioritise systems that could cause financial loss or regulatory risk, such as payroll or client data storage.
Recovery steps (same day)
Restore control securely and close any easy routes back in.
6. Secure the account
- Reset the account password to a strong, unique passphrase. Use a password manager to generate and store it.
- Set up multi-factor authentication (MFA) if not already active. Use app-based authenticators or hardware tokens rather than SMS where possible.
- Remove suspicious forwarding rules, connected apps and delegated access.
7. Restore communications and notify contacts
- Send a brief, factual notification to internal staff and key clients or suppliers if their data or interactions may have been affected.
- Advise recipients to ignore suspicious messages that originated during the compromise and to verify any payment requests by phone using known numbers.
Containment beyond the account (24–72 hours)
An email compromise often indicates wider security gaps. Extend your response to related systems.
8. Check related user accounts and devices
- Inspect other accounts that use the same password or recovery email. Reset passwords and enable MFA where needed.
- Scan and update devices that accessed the compromised account for malware using reputable endpoint tools.
9. Work with banks and payment partners
- If invoices or payment details were altered, contact your bank immediately. In South Africa, report potential fraud to your bank’s fraud desk and keep all supporting evidence.
- Consider instructing suppliers and customers to pause high-value transactions until you’ve validated the payment instructions.
Documentation and legal/regulatory steps
Keep a clear record of the incident and actions taken. This supports recovery, insurance claims and any legal or regulatory obligations.
10. Document everything
- Record timestamps, actions taken, people involved and evidence such as suspicious emails and logs.
- Preserve logs from the email service provider and any relevant server or firewall logs.
11. Consider reporting to authorities
- If the breach caused financial loss, theft of personal data, or targeted clients, report to the South African Police Service (SAPS) and your insurer.
- For data breaches involving personal information, check obligations under the Protection of Personal Information Act (POPIA) and notify affected data subjects if required.
Steps to prevent future incidents
After recovery, implement measures to reduce the likelihood of recurrence and to speed future response.
12. Harden account security
- Enforce organisation-wide MFA and strong password policies.
- Use role-based access control and restrict privileged account rights to only those who need them.
13. Improve email defences
- Enable advanced email filtering, DMARC, DKIM and SPF to cut phishing and spoofed messages.
- Consider email security gateways or the advanced features in business suites like Microsoft 365 Defender.
14. Train staff and run simulations
- Phishing is a common vector. Regular, practical training and simulated phish tests reduce click-through rates.
- Make incident reporting simple so staff report suspicious emails immediately.
When to call in specialist help
If the compromise is complex, involves theft of funds, or you lack internal IT capacity, get experienced incident responders involved quickly.
What specialist responders do
- Perform forensic analysis of email logs, devices and network traffic to determine scope and persistence.
- Coordinate recovery, liaise with banks and authorities, and implement technical remediations.
FAQ
- Q: How fast should we respond to a hacked business email?
A: Immediately. The first hour is critical to block access and prevent fraudulent payments or data loss. - Q: Do we need to inform clients if our email was hacked?
A: Yes, inform affected clients promptly if their data or transactions were impacted, and advise them how to verify communications. - Q: Can we recover everything from a hacked account?
A: Often you can restore access and remove attacker persistence, but you must verify whether emails were copied or data exported and act accordingly. - Q: Is SMS-based two-factor authentication adequate?
A: SMS is better than nothing but vulnerable to SIM-jacking. Use app-based authenticators or hardware tokens for stronger protection. - Q: Should we report the incident to POPIA authorities?
A: If personal information was compromised and the breach presents a risk to data subjects, POPIA notification requirements should be considered and legal advice sought.
Conclusion
A hacked business email account is urgent but manageable. Fast containment, thorough assessment and careful recovery protect finances, clients and reputation. Strengthening technical controls and staff awareness reduces future risk.
If you need practical, experienced assistance to recover from an email compromise or to harden your systems, contact RandTech IT. Our engineers prioritise rapid resolution so your business can get back to work with confidence.


