1. Unexpected sign-in activity
Review security alerts and sign-in logs for locations, devices or authentication attempts that do not match normal user activity.
2. Unfamiliar inbox or forwarding rules
Attackers may create rules that hide, delete or forward messages. Review mailbox rules and forwarding settings for changes the user did not make.
3. Messages the user did not send
Unexpected messages in Sent Items, reports from contacts about unusual payment requests, or suspicious links sent from the account can indicate misuse.
4. Account lockouts or password changes
Unexpected authentication failures, session changes or password resets can be signs that an account needs immediate investigation.
5. Missing mail or unusual delivery reports
Missing conversations, unexpected bounced messages or unusual mailbox behaviour should be investigated promptly.
Immediate response
Reset compromised credentials, revoke active sessions, remove unauthorised forwarding rules, enforce multi-factor authentication, review administrator access and notify relevant staff or financial partners when payment fraud may be involved.
Need business IT support in Sydney?
Talk to ITnetfix about managed IT support, cybersecurity, Microsoft 365, networking and backup services.
Contact ITnetfix