Quick answer
When an email account is hacked, reset the password, force sign-out on every device and enable MFA immediately. Then find and delete the forwarding rules the attacker set (the most-forgotten step), review sign-in and mail logs, clear the outbound queue, check whether your IP is blacklisted, and notify partners in writing. Watch for fake “bank account change” emails (BEC), which cause the biggest losses.
Contents
How do you know your email account has been hacked?
The clearest sign is email leaving your account that you didn't send, or a flood of bounces for messages you never wrote.
- Clients or partners call asking about a strange email or login link “from you”
- Lots of bounce messages for emails you didn't send
- Unfamiliar messages in Sent Items or Deleted Items, or emails disappearing as if deleted
- Odd rules or forwarding — e.g. every message forwarded to an outside address, or messages containing “invoice” / “payment” moved to another folder
- You suddenly can't send at all — on Microsoft 365 you may see
550 5.1.8 Access denied, bad outbound senderbecause the account was restricted for sending spam
6 steps to take when your email is hacked
Do these in order, right away. Steps 1–3 should be done within the first hour.
-
Reset the password and sign out of every device
Set a long, unique password, then force sign-out of all sessions — an attacker who is still logged in can keep using the account even after the password changes.
- Microsoft 365: Microsoft 365 admin center → Users → select the user → Reset password and Sign out of all sessions
- Mail server / VPS: change the mailbox password in the control panel and end webmail sessions
-
Turn on MFA
A leaked password is useless if MFA is on. Prefer an authenticator app over SMS, and enable it for every account in the company, not only the one that was hit.
-
Find and delete forwarding and rules the attacker set
This is the most-forgotten step. Attackers often add rules that forward mail outside or hide replies, so they can keep reading even after you change the password. Check all three places:
- Outlook / webmail: every rule, especially ones that forward, delete or move mail to rarely opened folders (RSS, Archive)
- Server side: forwarders and filters in the mail server control panel, or mail forwarding in Microsoft 365
- Access: anyone with Delegate / Full Access to the mailbox, and any app passwords created
-
Review sign-in and mail logs
Look for sign-ins from unfamiliar IPs or countries, when they started, and how many messages the account sent and to whom. You'll need this to assess the damage and to notify the right people.
-
Clear the outbound queue and check blacklists
Delete spam stuck in the outbound queue, then check whether your mail server's IP has been blacklisted. If it has, the whole company's email will start bouncing. See Email bounced with 550 5.7.1? How to fix it.
-
Notify partners and review security company-wide
Tell clients and partners who may have received fake emails, in writing. Scan the affected user's computer for malware, and check whether other staff reuse the same password across systems.
Own mail server vs Microsoft 365: what's different when you're hacked?
The response principles are the same, but the tools and the blast radius differ.
| Topic | Mail server / VPS | Microsoft 365 |
|---|---|---|
| Impact of spam being sent | Server IP gets blacklisted → whole company can't send | Microsoft restricts only the affected account (code 5.1.8) |
| Sign-in history | Server / control panel logs | Microsoft Entra sign-in logs |
| Checking forwards / rules | Forwarders + filters in the panel, plus Outlook rules | Mailbox forwarding + inbox rules (Exchange admin) |
| MFA | Depends on the platform; some only protect webmail | Built in via Security defaults / Conditional Access |
| Lifting the block | Request delisting from every blacklist | Admin releases the user in Microsoft Defender's Restricted entities |
Why Hinet never closes a “hacked email” case with just a password reset
In compromised-account cases we handle, resetting the password is only the start: we keep monitoring the email logs and sign-in history after remediation to confirm the attacker hasn't come back.
Our view: changing the password alone locks the front door while the back door stays open. If the attacker's rules aren't removed, finance emails keep flowing out. Every case is closed only after checking forwards and rules in all three places and reporting to the client in writing.
How do you stop it from happening again?
MFA on every account is the single best-value control; the next is teaching staff to spot phishing.
- Enforce MFA on every account, including executives and shared mailboxes (info@, sales@)
- No password reuse with other websites — check whether company addresses have leaked at Have I Been Pwned
- Block automatic forwarding outside the organisation by default; allow it only when approved
- Train staff on phishing, especially fake Microsoft 365 login pages and “invoice” attachments
- Alert on foreign sign-ins and unusual outbound volume
When should you call an expert?
If more than one account is affected, money has already been sent to a wrong account, or you're not sure the attacker is fully out, have an IT team review the whole system immediately.
If customers' personal data may have been exposed, your company may have breach-notification duties under Thailand's PDPA — involve your legal adviser. The Hinet team secures Email Hosting and Microsoft 365 Business and provides IT Support Outsourcing for SMEs. You can report the incident to our engineers using the form below.
FAQ: hacked email accounts
I changed the password — why are strange emails still going out?
The attacker may still be signed in on another device, or may have set up forwarding, rules or app passwords. Force sign-out of all sessions, delete unknown rules and remove all old app passwords.
How did we get hacked when the computer has antivirus?
Most passwords aren't stolen by malware on the PC — they're typed into fake login pages (phishing) or reused from sites that were breached. Antivirus can't stop that; MFA can.
Which type of MFA is best for an SME?
An authenticator app (such as Microsoft Authenticator) is safer than SMS and easy enough for everyday staff. For executives and finance, consider passkeys or security keys for stronger protection.
Do we need to tell clients and partners that our email was hacked?
Yes, especially anyone who may have received fake emails or phishing links from your account, so they don't fall for them. If personal data was exposed, your company may have breach-notification duties under Thailand's PDPA — consult your legal adviser.
What does 550 5.1.8 mean on Microsoft 365?
Microsoft has blocked the account from sending because it detected spam. Secure the account first, then an administrator can release it in the Restricted entities page in Microsoft Defender.
How do we know the attacker is completely gone?
Keep reviewing sign-in logs for at least 1–2 weeks after remediation: no new sign-ins from unusual IPs, no new rules appearing, and outbound volume back to normal.
References
- Microsoft Learn — Responding to a compromised email account
- Microsoft Learn — Determine whether an account is compromised
- Have I Been Pwned — check whether an address has leaked
- ThaiCERT — Thailand Computer Emergency Response Team
- MXToolbox — Blacklist Check
Related guides
Technically reviewed by the Hinet Computer System engineering team · Last updated 10 Oct 2026