Incident guide · Cyber incident
Recovering from a Microsoft 365 business email compromise
A containment, payment-protection and recovery plan for an Australian small or medium-sized business.
What has happened
The starting point
A growing services business receives an urgent supplier query and discovers that a finance mailbox has unexpected forwarding rules. A recent payment-detail change may have been influenced by the compromised account.
Immediate concerns
- Contain access without destroying useful evidence
- Protect payments and affected relationships quickly
- Restore safe access without leaving persistence
- Explain decisions and corrective actions to management
Recovery direction
Affected identities are contained and rebuilt safely; payment risk is handled through trusted channels; mailbox, session, consent and administrative persistence are checked; and the business adopts verified payment changes, stronger administration and a rehearsed response path.
The response path
- 01
First-hour control
Name the incident and finance leads, preserve times and indicators, use safe communications, restrict affected access and contact the bank when payment risk exists.
- 02
Scope and records
Review sign-ins, sessions, multi-factor authentication changes, inbox rules, delegates, application consent, messages, administrative actions and affected contacts within the available log window.
- 03
Safe recovery
Remove persistence, reset and re-enrol authentication, validate devices, restore access in stages and monitor for recurrence.
- 04
Business repair
Confirm transactions and supplier details through known-safe channels, communicate based on verified facts and update approvals and incident controls.
- 05
Close-out review
Confirm corrective-action owners, record residual uncertainty and schedule a focused exercise of the payment and identity hand-offs.
Decisions during the incident
- When to involve the bank, insurer, legal adviser and Australian Signals Directorate
- Which accounts and devices require containment
- How to communicate without over- or under-stating the facts
- What records must be retained
Recovery checks
- All affected accounts and persistence paths have documented checks
- Finance confirms recent payment changes through trusted contacts
- Privileged access and MFA recovery are controlled
- The incident record includes timeline, scope, actions and residual uncertainty
- A follow-up review confirms corrective actions have owners and dates
Records to retain
- Incident timeline and evidence register
- Account and mailbox review record
- Payment-verification procedure
- Corrective-action plan and tabletop scenario
Official guidance for the response team
- Australian Signals Directorate, Australian Cyber Security Centre — Annual Cyber Threat Report 2024–25
- Australian Signals Directorate, Australian Cyber Security Centre — Business email compromise
- Australian Signals Directorate, Australian Cyber Security Centre — Implementing multi-factor authentication