Knowledge base · incident response
What to do after phishing or account compromise
Speed matters after a suspicious click, but blindly changing passwords is not always enough. First contain further access, preserve relevant evidence and then determine how the attacker entered and what they changed.
Updated: 4 September 2026
Opened only, or were details submitted?
Establish exactly what happened: was the message merely opened, was a link clicked, was a file executed, were credentials entered or was an MFA prompt approved? Record the time, affected account, device and URL or attachment. Do not delete the message before necessary evidence has been preserved.
Report the incident immediately to the internal administrator or IT provider. If payments or bank details are involved, the financial owner must promptly use a separate trusted channel to verify whether transactions can be stopped.
Contain the account
Temporarily disable a suspected compromised account or reset its password through the managed recovery process. Revoke active sessions and suspicious tokens and require fresh sign-in. Review registered MFA methods, recovery details, linked devices and application consent for unknown changes.
Use a clean, trusted administration account and device for recovery. If the same credentials were used elsewhere, those accounts also need unique passwords. Enable MFA where absent, but first ensure the attacker did not add their own verification method.
Investigate mailbox and activity
Review sign-in logs for unfamiliar locations, addresses and clients. Inspect sent and deleted items, audit data, inbox rules and external forwarding. Attackers often create rules to hide alerts or forward financial correspondence. Check whether the account sent phishing to colleagues or external contacts.
Investigate the endpoint when a file was opened or executed. Changing only the cloud password does not remove malware or stolen browser sessions from a device. Preserve logs and a timeline where personal data or financial harm may be involved.
Recover, communicate and prevent recurrence
Remove malicious rules, permissions and unknown verification methods. Restore normal access only after major persistence routes have been checked. Warn recipients of fraudulent messages clearly without redistributing a clickable malicious link.
Assess breach notification duties and record decisions. Review why the attack succeeded and implement the smallest effective improvements: phishing-resistant MFA, restrictions on forwarding, better email authentication, reduced privilege and scenario-focused training. A short rehearsed response card is more reliable under pressure than a long plan nobody has practised.
Technical sources
Would you like to improve security after an incident?
JotaSec helps translate findings into actionable hardening and verification.