The First 48 Hours After You Find a Compromised Microsoft 365 Mailbox
Locking the attacker out of a Microsoft 365 mailbox takes minutes. The next 48 hours decide whether you recover the money, contain the legal exposure, and learn what was actually taken.
A controller at a Plano distribution company noticed something small on a Tuesday morning. A longtime supplier called to ask why the company had switched banks. She had not switched banks. Eleven minutes later her IT provider found a hidden rule sitting in her Microsoft 365 mailbox, quietly moving every message containing the word invoice into a folder she never opened. The rule had been running for nineteen days.
The IT provider did what most providers do. They deleted the rule, reset her password, signed her out of every active session, and told her the problem was handled. It was not handled. Over the next two days the company found a wire transfer that had already cleared, a second employee carrying the same hidden rule, and a customer who was drafting a demand letter. The break-in took nineteen days to discover and about eleven minutes to close. Everything that actually cost the company money was decided in the forty eight hours after that.
That gap is what this article is about. We have already written about the moment you discover a compromised Microsoft 365 account, and that piece walks through the immediate lockout steps. This one starts where that one ends. The two days that follow are where money is either recovered or gone for good, where legal exposure is either contained or manufactured, and where you either learn what the intruder actually read or you spend the next year guessing.
One definition before we go further. Microsoft 365 is the bundle that includes Outlook email, Teams chat, SharePoint document storage, and OneDrive file storage, all reached through a single login. When somebody steals a Microsoft 365 password, they do not simply get email. They get every system that login touches, and in most small companies that is the entire business.
Closing the Door Is Not the Same as Proving Nobody Is Inside
The most common mistake in the first two days is treating the password reset as the finish line. A password reset removes one way in. It does not remove the others, and modern email attackers almost always leave more than one.
The first thing to check is whether the attacker added their own multi-factor authentication method. Multi-factor authentication, usually shortened to MFA, is the second step that texts you a code or pings an app after you type your password. If an intruder registered their own phone or their own authenticator app while they were inside, then your password reset simply handed them a fresh password prompt they can satisfy. We have covered the ways attackers get around multi-factor authentication in more detail, but the short version is that resetting a password without auditing the registered MFA methods is closing a door while leaving a key under the mat.
The second thing to check is application consent. Microsoft 365 lets outside applications connect to a mailbox with the user's permission, and attackers routinely grant that permission to an app they control. The point of that trick is durability. The application keeps reading mail after the password changes, after the sessions are revoked, and after everyone has moved on, and nothing looks wrong from the user's side.
The third thing is forwarding, in all of its forms. Most people check the obvious inbox rule and stop. A copy of your mail can also leave through account-level forwarding, through transport rules that apply to the whole organization, and through delegate access that lets another account open the mailbox directly. If you only removed the rule you found, assume you removed the one the attacker was willing to lose.
None of this is exotic work, but it is methodical work, and it does not happen by accident at eight at night. This is where a hardened email security posture earns its cost, because the audit is far faster when the logging was already turned on.
Hour One to Twelve, Follow the Money Before You Follow Anything Else
Everything else can wait twelve hours. Money cannot.
Business email compromise, the polite industry term for a criminal reading your mail and then redirecting a payment, is not a data problem first. It is a banking problem first. The recovery window for a fraudulent wire is measured in hours, not days, and it closes hard. Once funds move through a receiving account and out again, the practical odds of getting them back fall off a cliff.
So the first call in hour one is not to your lawyer and not to your insurance carrier. It is to your bank, and the words you need are that you are reporting a fraudulent wire and requesting a recall. The second call is to the FBI Internet Crime Complaint Center, which operates a financial fraud kill chain that can freeze funds domestically if it is engaged fast enough. Small businesses skip that call because it feels like a formality. It is not, and it is free.
While that is in motion, someone has to pull every payment instruction that changed in the last sixty days. Not the last week. The mailbox in our opening example sat compromised for nineteen days, which is close to the norm, because the attacker's first act is usually to sit quietly and read. Any bank detail updated by email during that window should be re-verified by phone, using a number from an old invoice, never a number from the email requesting the change.
Then look in the other direction. If the attacker sent invoices from your employee's account to your customers, then your customers are the ones about to lose money, and they do not know yet. That call is unpleasant. It is far less unpleasant than the one where they tell you they already paid it. How these schemes are built and stopped is covered in our guide on business email compromise and wire fraud.
Hour Twelve to Twenty Four, Find Out What They Read
By the second half of day one, the immediate financial bleeding is either stopped or it is not, and attention has to shift to scope. Scope means one question. What did this person actually have access to, and what did they take.
Owners tend to picture a mailbox as a stream of messages that arrive and get answered. In practice a business mailbox is an archive, and the archive is the asset. Five years of contracts. Payroll spreadsheets somebody emailed instead of uploading. Scans of driver licenses from onboarding. A folder of passwords an employee mailed to themselves because it was convenient. An attacker with nineteen days of quiet access searched for the words that lead to money and identity, and downloaded what they found.
This is also the moment to remember that the login opens more than Outlook. SharePoint and OneDrive sit behind the same credential, so the shared drive is in scope too, and those download logs need to be pulled alongside the mailbox logs. A compromise reported as an email incident that turns out to include the company file share is a materially different event with different obligations.
What you are building here is not a feeling. It is a defensible record of which accounts were touched, which files were accessed or exported, and over what dates. That record is what your attorney relies on to decide whether a notification obligation exists, and what your insurance carrier requires before paying anything. Companies that skip this step are not saving money. They are choosing to answer every future question with a guess.
If nobody in house can pull and interpret those logs, bring in outside help now rather than three days from now, once log retention has started aging out the evidence. Our incident response team does this work for businesses across McKinney and the wider DFW area, and the single biggest predictor of a clean outcome is how early the call comes.
The Credential Problem You Inherit on Day Two
Here is the part that surprises people most. Even a perfectly executed cleanup leaves a problem that does not live on your network at all.
Whatever the attacker copied out of that mailbox is now theirs permanently. Not blocked, not recalled, not expired. If your employee ever emailed a password, and employees do this constantly, that password is now on a list. If your vendor portal login, your payroll system login, or your bank credentials ever passed through that inbox, those are on a list as well. Stolen credential sets get traded and resold on criminal marketplaces for months and sometimes years, which means the risk from a two day incident in August can surface as an unrelated-looking login attempt the following spring.
That is why dark web monitoring belongs in the day two plan rather than in a budget conversation next quarter. Watching for your own domain and your own employee addresses to appear in a credential dump is how you learn that the incident is not finished.
The companion task gets skipped. Every password that appeared in that mailbox has to be changed in the system it belongs to, and every shared vendor login rotated. It is a tedious afternoon, and it is the difference between an incident that ends and one that returns through a side door in six months.
The Assistant Nobody Thought to Check
There is a newer wrinkle that did not exist in most North Texas businesses two years ago.
If your company turned on an AI assistant that connects to Microsoft 365, and a large number of businesses in Frisco and Plano did exactly that over the past eighteen months, then that assistant has been indexing mail and documents so it can answer questions quickly. That is the entire point of it. The uncomfortable consequence is that an assistant tied to a compromised account can summarize, search, and surface material the attacker would otherwise have had to dig for by hand. A criminal who would have needed hours of manual searching to find your banking relationships can ask a question in plain English and get an organized answer.
So day two includes a question almost nobody asks. Which AI tools were connected to this account, what were they permitted to see, and what did they retrieve during the exposure window. The same question applies to assistants employees connected on their own, which happens far more often than owners believe. Getting a defensible answer requires knowing what is connected in the first place, which is the practical starting point of AI security for a business. This is not a reason to abandon the technology. It is a reason to know what it can reach before an incident rather than during one.
What You Are Legally and Contractually Obligated to Do
By the end of the second day you need a decision on notification, and that decision is not a technical one.
Texas requires notification to affected individuals when sensitive personal information is compromised, and also requires notice to the Attorney General once the count reaches a threshold. What counts as sensitive is broader than most owners assume, and it includes routine material sitting in ordinary mailboxes, such as Social Security numbers on onboarding paperwork, financial account numbers, and health information. If you serve healthcare, financial services, or government clients, additional rules stack on top, and the deadlines are shorter.
Separately from the law, look at your contracts. Many customer agreements, especially with larger organizations, include a clause requiring you to notify them of a security incident within a defined window, often seventy two hours or less. That clock started when you discovered the compromise, not when you finished investigating it. Missing a contractual notification deadline is a breach of contract on its own terms, entirely independent of whether any of your customer's data was ever touched.
Your cyber insurance policy has its own timeline, and it is usually stricter than either. Many carriers require notice promptly upon discovery and require you to use their approved vendors. Businesses have paid for their own cleanup and then had the claim reduced or denied because they called their regular IT provider first and the carrier second. Read the policy on day one, not on day four.
Sorting out which obligations apply to your situation, on the evidence you gathered, is exactly the kind of question our compliance team handles, and it is worth an hour of expert time rather than a week of internal debate. For companies without an internal security leader, our professional services group provides the senior guidance to run that decision properly, so a small business is not making a legal exposure call based on what somebody read online.
Closing Day Two With Something You Can Point To
The last hour of the second day should produce a written record, and it should be written while everyone still remembers the details.
That record needs the timeline, meaning when the compromise started, when it was discovered, and when each containment step happened. It needs the scope, supported by the logs you pulled, and the financial outcome, including any wires attempted, recovered, or still outstanding. It needs the notification decision and the reasoning behind it, plus what you changed so the same path does not work twice.
That document is worth real money later. It is what an insurance carrier reads and what your biggest customer's security questionnaire will ask about next year. Reconstructing it from memory four months later produces something vague.
The changes themselves are usually modest. Turn off the ability for regular users to consent to outside applications. Alert whenever a new mail forwarding rule or transport rule is created, because legitimate users create those rarely and attackers create them immediately. Require a phone call to a known number before any payment detail changes, and write that into the accounting procedure rather than leaving it as a habit. Confirm that mailbox and file recovery actually works by testing it, which is the argument we make at length about backup and recovery. If your technology is handled by a provider focused on uptime rather than intrusions, the honest conversation is about how a security specialist works alongside your existing IT provider.
The distribution company in the opening recovered most of the wire, because someone made the bank call inside the first three hours. They lost the customer relationship anyway, because that customer heard about the fraudulent invoice from their own accounts payable department before they heard about it from anyone at the distributor. The technical response was adequate. The communication response was two days late. Across McKinney, Plano, Frisco, and the rest of Collin County, that is the far more common way these events actually hurt a business.
Get Help Before the Clock Runs Out
If you are reading this because something is happening right now, stop reading and call. The wire recall window and the contractual notification window are both running, and neither one waits for you to finish researching.
Innovation Network Design works with businesses across McKinney, Plano, Frisco, Allen, and the wider DFW area on email compromise response, scope investigation, and the notification decisions that follow. Call 512-518-4408 and we will start with the questions that matter in the next hour rather than the next week.
If nothing is on fire today, the better time to have this conversation is now. A free security assessment will show you what your Microsoft 365 environment currently exposes, which accounts lack real multi-factor protection, and which outside applications already have permission to read your mail. You can also reach us through our contact page to set up a short call. Forty eight hours is enough time to contain this well, but only if the plan exists before the clock starts.
Need Help With This?
Innovation Network Design helps businesses across McKinney, Dallas, and nationwide with expert cybersecurity services.
Mark Sullivan
Innovation Network Design
With nearly a decade in cybersecurity and IT infrastructure, our team delivers expert insights to help businesses in McKinney, Dallas, and across DFW make informed security decisions. Have a question? Get in touch.
Ready to Secure Your Business?
Get a free security assessment and find out where your organization stands.