2026-08-10
Microsoft 365 Account Hacked: Warning Signs and Recovery Steps
As of 08/2026: a Microsoft 365 account may be hacked if users see unexpected MFA prompts, missing emails, strange sent messages, external forwarding, new inbox rules, sign-ins from unfamiliar regions, or invoice-payment conversations that no one remembers sending. The safest response is to revoke sessions, reset credentials, remove malicious rules, and review audit logs before assuming the account is clean.
What changed?
This guide was added because business email compromise is showing up in small offices without obvious malware. The attacker may never touch a workstation. Many cases start with one stolen password and end with invoice redirection, payroll fraud, or vendor impersonation.
What are the most common hacked-mailbox signs?
The most common hacked-mailbox signs are unexplained MFA prompts, customers receiving strange emails, messages missing from the inbox, unfamiliar forwarding rules, sent mail the user did not send, new app permissions, and logins from impossible travel locations. A mailbox can be compromised even when the computer itself is clean.
What should an owner or office manager do first?
Verify payment-change requests by phone using a known number, not the number in the email thread. Reset the affected user's password from a clean admin session, revoke active sessions, disable suspicious forwarding, and preserve suspicious messages. If admin access may be compromised, stop and get help before changing tenant-wide settings.
Microsoft 365 compromise response table
| Finding | What it may mean | Recovery step |
|---|---|---|
| External forwarding rule | Attacker is copying mail | Remove rule and check transport settings |
| Strange MFA prompts | Password may be known | Reset password and review sign-ins |
| Unknown OAuth app | App can read mailbox data | Revoke app permissions |
| Sent invoice-change email | Business email compromise | Notify affected vendors or customers |
| Legacy authentication activity | MFA bypass risk | Block legacy authentication |
How Virus Pros handles Microsoft 365 compromise
Virus Pros revokes sessions, resets credentials, audits rules and forwarding, reviews sign-in logs, checks OAuth grants, confirms MFA status, and documents likely exposure. After containment, Virus Pros hardens Microsoft 365 with MFA enforcement, legacy-auth blocking, admin account separation and alerting on suspicious sign-ins.
Frequently asked questions
Can a Microsoft 365 account be hacked even if the PC is clean?
Yes. Many business email compromise cases happen through stolen passwords or malicious app permissions without local malware.
Should we notify customers or vendors?
Possibly. If fraudulent payment instructions or suspicious messages were sent, affected contacts should be notified quickly using a trusted phone number.
Can you help after hours?
Yes. Virus Pros provides 24/7 response for Microsoft 365 compromise, ransomware and virus incidents in Northeast Houston.
Need incident help now?
Call Virus Pros before rebooting, wiping, restoring, or paying anyone.
Call (936) 251-6130