Business email compromise often begins quietly. A staff member enters a password on a convincing fake page, or reuses a password that was exposed in an unrelated breach. The attacker signs in to cloud email, reads messages for days, creates rules to hide replies and then sends a request for a payment change or a document with a believable-looking tone. By the time someone notices, the damage may be done.
This post lays out investigation steps for a suspected mail account compromise in cloud email. It is written for administrators and office managers who need to understand what is being done, and for IT staff who do the work. If resident information could be involved, treat this as a security incident and bring in your privacy and security officer, your IT provider and, as appropriate, legal counsel and your insurance carrier.
Do not wait for a full picture before acting.
Reset the account password to a strong, unique one.
Sign the user out of all active sessions and revoke tokens, so the attacker's existing sessions end.
Require or confirm multi-factor authentication, and check that the attacker has not added their own method.
Temporarily block the account from sending if needed.
Keep notes with times of every action.
Preserve evidence by exporting logs before they age out. Many platforms keep sign-in and audit data for a limited period.
Sign-in logs show who accessed the account, when and from where.
Unfamiliar locations or countries, especially ones the employee has never visited.
Impossible travel, such as logins from two distant places within minutes.
Unusual devices, browsers or applications. Look for older protocols or tools the user does not normally use.
Odd hours, such as a burst of activity at 3 a.m. local time.
Failed attempts followed by a success, which suggests password guessing or spraying.
Note the first suspicious sign-in. It marks the earliest possible start of the compromise and sets the window for the rest of your investigation. Be careful, however, since an employee's own travel, phone or a VPN can create false alarms. Confirm with the user.
Attackers frequently create rules that hide their activity from the real user. Check for:
Rules that delete or move messages to rarely used folders such as RSS feeds, archive or deleted items
Rules that forward or redirect mail to an outside address
Rules triggered by keywords such as invoice, payment, wire, bank or the names of vendors
Changes to delegates and permissions, which give another account access to the mailbox
Newly connected applications or authorization grants that keep access even after a password change
Remove malicious rules and permissions, but capture screenshots or exports first for the record.
Audit logs and message trace tools can show what the attacker did.
What messages were sent from the account during the compromise window, and to whom?
Were any messages sent to many people, which suggests phishing from a trusted sender?
Which messages were read, searched, downloaded or deleted?
Were attachments or contact lists accessed?
Look especially for conversations about money, bank details or resident information.
Healthcare organizations must consider whether protected health information was acquired or viewed. Review the mailbox content for the relevant period. The HIPAA Breach Notification Rule requires a documented risk assessment unless an exception applies, so your privacy officer should lead this analysis. Do not assume that no data was viewed simply because you cannot prove it was.
If the attacker had access to one account, they may have tried others.
Search for the same malicious sender or link in other mailboxes and remove it.
Check whether other accounts show similar sign-in anomalies.
Warn finance staff and vendors to verify any payment or banking change requests by phone using a known number.
Reset credentials for accounts that share passwords with the compromised one.
Confirm the account is clean and the user is retrained on how the compromise happened.
Notify affected parties as required by law, contract and policy.
Turn on or tighten multi-factor authentication, conditional access and sign-in alerts.
Disable legacy sign-in methods that bypass modern protections.
Alert on new forwarding rules.
Record lessons learned and update your incident response plan.
Mailbox investigations involve both technical detail and legal obligations. UnityCare IT assists healthcare organizations in preserving logs, tracing activity and coordinating next steps with counsel and insurers. The sooner we are called, the more evidence is typically available.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172