Email & Hosting Urgent Steps 1–3 are DIY

Email Account Hacked and Sending Spam? 6 Steps to Stop the Damage

A client calls about a strange email from you, or your inbox is full of bounces you never sent? Your account has likely been taken over. This guide lists what to do in time order to stop the damage as fast as possible.

Quick answer

When an email account is hacked, reset the password, force sign-out on every device and enable MFA immediately. Then find and delete the forwarding rules the attacker set (the most-forgotten step), review sign-in and mail logs, clear the outbound queue, check whether your IP is blacklisted, and notify partners in writing. Watch for fake “bank account change” emails (BEC), which cause the biggest losses.

Contents
  1. Signs your email was hacked
  2. 6 steps to take
  3. Mail server vs Microsoft 365
  4. From Hinet's real cases
  5. Preventing a repeat
  6. When to call an expert
  7. FAQ: hacked email accounts

How do you know your email account has been hacked?

The clearest sign is email leaving your account that you didn't send, or a flood of bounces for messages you never wrote.

  • Clients or partners call asking about a strange email or login link “from you”
  • Lots of bounce messages for emails you didn't send
  • Unfamiliar messages in Sent Items or Deleted Items, or emails disappearing as if deleted
  • Odd rules or forwarding — e.g. every message forwarded to an outside address, or messages containing “invoice” / “payment” moved to another folder
  • You suddenly can't send at all — on Microsoft 365 you may see 550 5.1.8 Access denied, bad outbound sender because the account was restricted for sending spam
Response timeline for a hacked email account Three phases: within 15 minutes lock the account by resetting the password and signing out all devices; within 1 hour remove forwarding and rules set by the attacker and review logs; within 24 hours check blacklists, notify partners and review company-wide security. Within 15 minutes Within 1 hour Within 24 hours Stop the bleeding • Reset the password • Sign out all devices • Turn on MFA • Pause sending if needed Close the back door • Remove odd forwards/rules • Delete old app passwords • Review sign-in logs • Review outbound mail logs Recover + prevent • Clear queue, check blacklists • Notify partners in writing • Scan the user's device • Company-wide security review
The response sequence the Hinet team follows — the faster you close each door, the less damage.

6 steps to take when your email is hacked

Do these in order, right away. Steps 1–3 should be done within the first hour.

  1. Reset the password and sign out of every device

    Set a long, unique password, then force sign-out of all sessions — an attacker who is still logged in can keep using the account even after the password changes.

    • Microsoft 365: Microsoft 365 admin center → Users → select the user → Reset password and Sign out of all sessions
    • Mail server / VPS: change the mailbox password in the control panel and end webmail sessions
  2. Turn on MFA

    A leaked password is useless if MFA is on. Prefer an authenticator app over SMS, and enable it for every account in the company, not only the one that was hit.

  3. Find and delete forwarding and rules the attacker set

    This is the most-forgotten step. Attackers often add rules that forward mail outside or hide replies, so they can keep reading even after you change the password. Check all three places:

    • Outlook / webmail: every rule, especially ones that forward, delete or move mail to rarely opened folders (RSS, Archive)
    • Server side: forwarders and filters in the mail server control panel, or mail forwarding in Microsoft 365
    • Access: anyone with Delegate / Full Access to the mailbox, and any app passwords created
  4. Review sign-in and mail logs

    Look for sign-ins from unfamiliar IPs or countries, when they started, and how many messages the account sent and to whom. You'll need this to assess the damage and to notify the right people.

  5. Clear the outbound queue and check blacklists

    Delete spam stuck in the outbound queue, then check whether your mail server's IP has been blacklisted. If it has, the whole company's email will start bouncing. See Email bounced with 550 5.7.1? How to fix it.

  6. Notify partners and review security company-wide

    Tell clients and partners who may have received fake emails, in writing. Scan the affected user's computer for malware, and check whether other staff reuse the same password across systems.

Watch for “we've changed our bank account” emails — the costliest outcome of a hacked mailbox isn't spam, it's Business Email Compromise (BEC): the attacker reads your finance emails and sends a fake invoice with new bank details. Whenever you get a request to change bank details, call back on a number you already know — never the one in the email.

Own mail server vs Microsoft 365: what's different when you're hacked?

The response principles are the same, but the tools and the blast radius differ.

TopicMail server / VPSMicrosoft 365
Impact of spam being sentServer IP gets blacklisted → whole company can't sendMicrosoft restricts only the affected account (code 5.1.8)
Sign-in historyServer / control panel logsMicrosoft Entra sign-in logs
Checking forwards / rulesForwarders + filters in the panel, plus Outlook rulesMailbox forwarding + inbox rules (Exchange admin)
MFADepends on the platform; some only protect webmailBuilt in via Security defaults / Conditional Access
Lifting the blockRequest delisting from every blacklistAdmin releases the user in Microsoft Defender's Restricted entities
First-hand experience

Why Hinet never closes a “hacked email” case with just a password reset

3places we always check for forwards and rules (client · server · access)
101Email & Hosting cases handled in 19 months
20+years managing email for Thai businesses

In compromised-account cases we handle, resetting the password is only the start: we keep monitoring the email logs and sign-in history after remediation to confirm the attacker hasn't come back.

Our view: changing the password alone locks the front door while the back door stays open. If the attacker's rules aren't removed, finance emails keep flowing out. Every case is closed only after checking forwards and rules in all three places and reporting to the client in writing.

How do you stop it from happening again?

MFA on every account is the single best-value control; the next is teaching staff to spot phishing.

  • Enforce MFA on every account, including executives and shared mailboxes (info@, sales@)
  • No password reuse with other websites — check whether company addresses have leaked at Have I Been Pwned
  • Block automatic forwarding outside the organisation by default; allow it only when approved
  • Train staff on phishing, especially fake Microsoft 365 login pages and “invoice” attachments
  • Alert on foreign sign-ins and unusual outbound volume

When should you call an expert?

If more than one account is affected, money has already been sent to a wrong account, or you're not sure the attacker is fully out, have an IT team review the whole system immediately.

If customers' personal data may have been exposed, your company may have breach-notification duties under Thailand's PDPA — involve your legal adviser. The Hinet team secures Email Hosting and Microsoft 365 Business and provides IT Support Outsourcing for SMEs. You can report the incident to our engineers using the form below.

FAQ: hacked email accounts

I changed the password — why are strange emails still going out?

The attacker may still be signed in on another device, or may have set up forwarding, rules or app passwords. Force sign-out of all sessions, delete unknown rules and remove all old app passwords.

How did we get hacked when the computer has antivirus?

Most passwords aren't stolen by malware on the PC — they're typed into fake login pages (phishing) or reused from sites that were breached. Antivirus can't stop that; MFA can.

Which type of MFA is best for an SME?

An authenticator app (such as Microsoft Authenticator) is safer than SMS and easy enough for everyday staff. For executives and finance, consider passkeys or security keys for stronger protection.

Do we need to tell clients and partners that our email was hacked?

Yes, especially anyone who may have received fake emails or phishing links from your account, so they don't fall for them. If personal data was exposed, your company may have breach-notification duties under Thailand's PDPA — consult your legal adviser.

What does 550 5.1.8 mean on Microsoft 365?

Microsoft has blocked the account from sending because it detected spam. Secure the account first, then an administrator can release it in the Restricted entities page in Microsoft Defender.

How do we know the attacker is completely gone?

Keep reviewing sign-in logs for at least 1–2 weeks after remediation: no new sign-ins from unusual IPs, no new rules appearing, and outbound volume back to normal.

References

Technically reviewed by the Hinet Computer System engineering team · Last updated 10 Oct 2026

Hinet IT Support

Still stuck? Let the Hinet team fix it

Report the incident briefly. Our engineers will help lock the account, review logs and close the gaps, and get back to you as quickly as possible.

  • Supporting Thai businesses since 2004
  • Mail servers / VPS, Microsoft 365 and Google Workspace
  • Free initial assessment, no obligation

Report an IT issue

Fields marked * are required

We only use your details to follow up on this issue, per our privacy policy.

LINE Get help