Incident guide · Cyber incident

Recovering from a Microsoft 365 business email compromise

A containment, payment-protection and recovery plan for an Australian small or medium-sized business.

What has happened

The starting point

A growing services business receives an urgent supplier query and discovers that a finance mailbox has unexpected forwarding rules. A recent payment-detail change may have been influenced by the compromised account.

Immediate concerns

  • Contain access without destroying useful evidence
  • Protect payments and affected relationships quickly
  • Restore safe access without leaving persistence
  • Explain decisions and corrective actions to management

Recovery direction

Affected identities are contained and rebuilt safely; payment risk is handled through trusted channels; mailbox, session, consent and administrative persistence are checked; and the business adopts verified payment changes, stronger administration and a rehearsed response path.

The response path

  1. 01

    First-hour control

    Name the incident and finance leads, preserve times and indicators, use safe communications, restrict affected access and contact the bank when payment risk exists.

  2. 02

    Scope and records

    Review sign-ins, sessions, multi-factor authentication changes, inbox rules, delegates, application consent, messages, administrative actions and affected contacts within the available log window.

  3. 03

    Safe recovery

    Remove persistence, reset and re-enrol authentication, validate devices, restore access in stages and monitor for recurrence.

  4. 04

    Business repair

    Confirm transactions and supplier details through known-safe channels, communicate based on verified facts and update approvals and incident controls.

  5. 05

    Close-out review

    Confirm corrective-action owners, record residual uncertainty and schedule a focused exercise of the payment and identity hand-offs.

Decisions during the incident

  • When to involve the bank, insurer, legal adviser and Australian Signals Directorate
  • Which accounts and devices require containment
  • How to communicate without over- or under-stating the facts
  • What records must be retained

Recovery checks

  • All affected accounts and persistence paths have documented checks
  • Finance confirms recent payment changes through trusted contacts
  • Privileged access and MFA recovery are controlled
  • The incident record includes timeline, scope, actions and residual uncertainty
  • A follow-up review confirms corrective actions have owners and dates

Records to retain

  • Incident timeline and evidence register
  • Account and mailbox review record
  • Payment-verification procedure
  • Corrective-action plan and tabletop scenario

Official guidance for the response team

  1. Australian Signals Directorate, Australian Cyber Security Centre — Annual Cyber Threat Report 2024–25
  2. Australian Signals Directorate, Australian Cyber Security Centre — Business email compromise
  3. Australian Signals Directorate, Australian Cyber Security Centre — Implementing multi-factor authentication

A practical next step

Plan the work around the real environment.

Share what is not working, what is changing or what decision needs to be made. Technical answers can come after the business context is clear.