Change that password and end sessions immediately, check for forwarding rules and connected apps, and thank the person, because blame is what makes the next one go unreported.

The first hour

Act on the account before anything else, since the credential is already elsewhere and may be in use.

Change the password on that account, then end every session, in that order.

Enable two-step verification if it was not on, which prevents the credential being useful even where it has been taken.

Then check the same password is not in use anywhere else, because it usually is, and every account sharing it needs changing too.

That sequence takes about fifteen minutes and closes most of the exposure.

Then check what was done with it

The first is the one that persists after a password change, and it is the standard move: a rule silently copying messages elsewhere, which keeps working after you think you have closed everything.

The fourth matters as much, since a changed recovery address lets somebody reset the password back.

Warn the people it may have reached

Since a compromised mailbox is mostly used to send more.

Check whether anything was sent from the account, including messages deleted afterwards.

Where anything went to customers or suppliers, tell them directly and quickly, saying what happened and what to ignore.

That is uncomfortable and it is considerably better than a supplier acting on a fraudulent instruction that appeared to come from you.

Pay particular attention to anything about payment details, since the most damaging use of a compromised mailbox is to send a plausible message changing where money goes.

A short honest message beats an explanation, and speed matters more than wording.

How you respond decides the next one

The part that matters most in the long run and is decided in about ten seconds.

Somebody who reports a mistake immediately has given you the chance to contain it, which is worth far more than the mistake cost.

Somebody who is blamed for it will not report the next one, and neither will anybody who watched.

Unreported means undetected, and undetected means weeks rather than an hour, which is the difference between an inconvenience and a serious incident.

So the response is to thank them, plainly, in front of others where possible, and to say so afterwards.

That is not softness. It is the mechanism that makes early reporting the norm, and early reporting is the only defence that works after a click.

A worked example

A member of staff entered credentials into a page that looked like the company's own email login and told the owner within a few minutes.

The password was changed and sessions ended inside ten minutes.

A forwarding rule had already been created, copying everything to an external address, which was found and removed.

Nothing had been sent and no money moved.

The owner thanked her at the next morning's briefing and used it as the example of what to do, without naming it as a mistake.

Two months later somebody else reported a similar message within a minute of receiving it, which the owner attributed directly to how the first had been handled.

These are convincing now

Worth saying to anybody inclined to think it would not happen to them.

The messages are well written, correctly branded, and frequently reference something real: an invoice number, a supplier's name, a recent delivery.

The fake login pages are copies of the real ones, at addresses that look almost right.

They arrive at plausible moments, sometimes as a reply within an existing conversation from a compromised mailbox elsewhere.

Careful people fall for these regularly, and treating it as carelessness is both wrong and the reason it goes unreported.

Write down what to do

So the fifteen minutes are not spent working it out.

One short page: who to tell, what to change first, what to check, and who contacts customers if needed.

Include the specific steps for your own email provider, since finding the forwarding rules under pressure is harder than it should be.

Say explicitly that reporting immediately is what is expected and that nobody is in trouble for it.

Give it to everybody and mention it occasionally, since a page written once and never referred to is not a plan.

Reducing the next one

Briefly, since prevention is a separate subject.

Two-step verification is the single measure that makes a stolen password mostly useless, and it belongs on email above all.

A password manager helps, since it will not offer credentials to an address that does not match, which catches the fake page before the person does.

And a standing rule that payment detail changes are verified by phone, on a number you already hold, removes the most expensive outcome regardless of who clicked what.

Those three do more than any amount of telling people to be careful.

Check whether it reached anybody else

Since the same message almost certainly went to more than one person.

Ask everybody whether they received it, promptly, rather than waiting to find out.

Somebody who received it and did nothing may still have it sitting unread, and somebody who clicked and has not said so is the case you most want to find.

Asking as a group question rather than an investigation makes that second person considerably more likely to speak up.

Then delete it from every mailbox where you can, since a message left in place gets clicked weeks later by somebody catching up.

The counter-case

Not every click is an incident.

Opening a message, or clicking a link and closing the page without entering anything, is usually nothing, and treating it as a crisis produces fatigue.

The threshold is whether credentials were entered or a file was opened, and it is worth telling people that distinction so reports are proportionate.

There is also a point at which this needs somebody who does it professionally, particularly where customer data or payments are involved.

Change the password, end sessions, check the rules, warn anybody affected, and thank the person who told you.

The order

  1. Change that password immediately.
  2. End every session.
  3. Turn on two-step verification.
  4. Change it anywhere else it was used.
  5. Check forwarding rules and connected apps.
  6. Warn anybody it may have reached.
  7. Thank the person, visibly.

Step seven is the one with the longest effect, since it determines whether the next person tells you in one minute or in three weeks.

Recognising these before the click is covered in the email that looks like your supplier.


Frequently asked questions

What comes first?

Change the password on that account, then end every session, in that order. Ending sessions first lets whoever has the credential sign back in.

What persists after a password change?

Email forwarding rules and connected applications, which keep working, and a changed recovery address, which lets somebody reset the password back.

Who needs warning?

Anybody the account may have sent to, especially customers and suppliers. Pay particular attention to anything about payment details, which is the most damaging use.

Why does blame matter?

Because somebody blamed will not report the next one, and neither will anybody watching. Unreported means weeks rather than an hour, which is the whole difference.

Are these easy to spot?

No. They are well written, correctly branded, reference real invoices or suppliers, and sometimes arrive as a reply within an existing conversation. Careful people fall for them.

What reduces the next one?

Two-step verification, a password manager that will not offer credentials to a wrong address, and a rule that payment changes are verified by phone on a number you already hold.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Somebody just told you they clicked?

Change the password, end sessions, then check for a forwarding rule. Then thank them where other people can hear it.

Start a Conversation