Resource Hub

Manufacturing Security

How to Respond to a Compromised Microsoft 365 Account

Microsoft 365 account compromise is one of the most common security incidents manufacturers actually experience, far more common day to day than a full ransomware event, and it is often the opening move that leads to one.

By Ahmed HegaziFounder & Principal Security Consultant|3 min read

The Problem

Microsoft 365 account compromise is one of the most common security incidents manufacturers actually experience, far more common day to day than a full ransomware event, and it is often the opening move that leads to one. An employee reports an email they do not recall sending, a customer asks about a suspicious message, or unusual login alerts show up from an unfamiliar location, and the business has to decide what to do in the next few minutes, not the next few days.

Why it Matters Operationally

A compromised account can be used to intercept invoices and redirect payments, launch phishing attacks against employees, customers, and vendors, or serve as the foothold an attacker uses to reach deeper into the network. Attackers who gain mailbox access often move fast, especially when the goal is financial fraud, and payment reversal windows are frequently measured in hours, not days. How the first hour is handled has a major effect on whether the incident stays small.

The Simple Explanation

The priority is containment first, investigation second. Disable the account or reset the password immediately, but just as importantly, revoke all active sessions and refresh tokens, since a password change alone often does not log an attacker out of a session that is already active. Then check for the changes attackers commonly make to maintain access: unfamiliar mailbox forwarding or delete rules, newly registered MFA devices the user did not set up, and OAuth application consents that grant a malicious app ongoing access even after the password is reset.

Practical Checklist

  • Has the account been disabled or had its password reset immediately
  • Have all active sessions and refresh tokens been revoked, not just the password changed
  • Have mailbox rules been reviewed for unfamiliar forwarding or deletion rules
  • Have MFA devices and methods been reviewed for anything not set up by the legitimate user
  • Have OAuth application consents been reviewed and revoked if suspicious
  • Have sign-in logs been reviewed to understand what was accessed and from where
  • Has finance been alerted if any fraudulent payment or wire request may have gone out
  • Has the bank been notified immediately if financial fraud is a possibility

What You Can Do Now

Confirm today that MFA is enabled on every mailbox, and if it already is, confirm the method is an authenticator app or hardware key rather than SMS codes, which are more easily intercepted. Make sure whoever handles IT knows the exact steps above well enough to execute them without looking them up during an actual incident.

When Outside Help Makes Sense

Because a compromised mailbox is frequently the first stage of a larger attack, scoping the full impact, checking whether the same credentials were reused elsewhere, and determining whether the account had access to sensitive systems benefits from experienced incident responders who do this regularly. If the compromise involves financial fraud or signs of lateral movement, bring in outside help immediately rather than handling it entirely in-house.