Someone comes to your desk and says they clicked something they probably shouldn't have. Maybe they entered a password. Maybe they aren't sure. They look like they'd rather be anywhere else.
The next thirty minutes decide whether this is a non-event or the opening of an intrusion, and almost none of that work is technical. It is asking the right questions, not letting the wrong instincts run, and looking at a short list of settings in your email system.
This is written for the person who is actually standing there - the owner, the office manager, whoever people come to. Not a technician.
The single most damaging thing you can do in the first minute is react in a way that teaches everyone else to stay quiet. Reported quickly, this is usually containable. Reported three days later because somebody was embarrassed, it usually isn't.
So the first words are some version of: you did the right thing by telling me, let's sort it out. Mean it, and say the same thing afterward regardless of how it turns out. Every future incident in your business gets reported faster or slower depending on how this one goes.
Ask these before you touch anything. Write the answers down as they speak.
Lock the account first, before you investigate. This is the part people get backwards. Investigation takes time; an attacker with a working password does not wait for you to finish. If a password was typed into anything, reset it from a clean device and, in the same pass, sign the account out of everywhere. A password reset on its own does not end a session that is already running - the attacker stays signed in until the sessions themselves are revoked. In Microsoft 365 that is the sign-out-of-all-sessions action on the user; in Google Workspace it is the option to sign the user out of all devices.
Then look at what was changed while you were not watching. Attackers do the same small set of things immediately after they get into a mailbox, because those things buy them persistence and quiet. That list is short enough to check by hand and is covered below.
Then widen it. Find out who else received the message and whether any of them interacted with it. Your email admin tools can search across all mailboxes for a message; that search is worth doing before you assume this was one person.
Then decide whether you are done. Not by how you feel about it - by the specific conditions further down.
Both platforms expose the same handful of things. You are looking for changes you did not make.
Mailbox rules. The classic move is a rule that files incoming mail into an obscure folder, marks it read, or deletes it - so the account owner never sees the replies to messages the attacker sends. Look at every rule on the affected mailbox and confirm the user recognizes each one. A rule nobody remembers creating is not ambiguous.
Forwarding. Check whether mail is being forwarded to an outside address, both in the user's own settings and in the admin settings for that mailbox. Forwarding set at the admin level will not show up in the user's own mail app.
Connected apps and permissions. If the message led to a consent screen, an application may now hold standing access to that mailbox or file storage. That access survives a password change and survives MFA. Review the third-party apps connected to the account and remove anything unfamiliar.
Authentication methods. Look at the phone numbers, authenticator apps, and alternate email addresses registered to the account for sign-in and password recovery. An added method is how an intruder keeps an account after you reset the password. Remove anything the user does not recognize.
Sign-in history. Pull the recent sign-ins for that account around the time they gave you. You are looking for successful sign-ins from places or devices that do not fit, and for successful sign-ins that happened after the click. A failed sign-in from somewhere strange is background noise on the internet. A successful one is an incident.
Sent mail and deleted items. If the account was used, it usually shows: messages the user did not send, and an empty or recently purged sent folder.
Anything financial they touched. If the message was about an invoice, a payment, or a bank change, check whether a payment detail was actually altered somewhere - in your accounting system, with your bank, or in a reply to a customer. This is the version of the incident that costs money immediately.
Treat it as contained when all of these are true: nothing was typed in and nothing was approved, no successful unexpected sign-in appears after the click, no rules, forwarding, connected apps or authentication methods were added, and the account has been reset and signed out everywhere as a precaution. Write it up, tell the person they did the right thing, and move on.
Treat it as not contained, and get help, when any one of these is true:
The line between these two lists is not how bad it looks. It is whether anything happened that you cannot explain.
Sensitive data raises the stakes independently. If the mailbox held health information, financial account details, or personal data about customers or employees, containment is no longer the only question - whether a notification obligation was triggered is a separate determination with its own clocks, and it is not one to make casually.
Do this while it is happening, not afterward. A page of contemporaneous notes is worth more than a careful reconstruction later, and if this becomes an insurance claim or a regulatory question, the timeline is the first thing anyone asks for.
Record: who reported it and when they reported it; when they say the click happened; what the message was and who it appeared to come from; exactly what they clicked and what they entered or approved; who else received it; every check you ran and what you found, including the checks that came back clean; every action you took and the time you took it; who else you told and when.
The clean findings matter as much as the dirty ones. "We reviewed mailbox rules and forwarding and found none" is a real finding, and six weeks later nobody will remember whether you looked.
Most businesses handle this well in the first five minutes and badly in the next twenty-five - because the first five are instinct and the rest require knowing where to look.
The practical fix is to settle two things before it happens. First, who has the administrative access to actually check mailbox rules, forwarding, connected apps and sign-in history. If the answer is "our IT person, when he gets back to us," the answer is not good enough, because the useful window is measured in minutes. Second, the phone number the person standing there is supposed to dial, written somewhere that does not require logging into the system you are worried about.
It is also worth saying plainly: the reason this article does not open with security awareness training is that training changes the odds, not the outcome. People will click. A business that has decided what happens after the click loses very little. A business that hasn't is doing forensics and notification analysis at the same time, under pressure, with an employee who is convinced he ruined everything.
If you are in the middle of one right now, call +1 (888) 966-7228. A human answers, you don't need to be a customer, and you don't need to be sure it's real. If you are reading this while nothing is happening, our security self-check will tell you which of the checks above you could actually run today, and our Cyber Risk Management work is where the monitoring that catches the sign-in you'd otherwise miss lives.
Disclaimer. This article is provided for general information only. It is not legal, regulatory, or professional advice, and reading it does not create a client relationship with WOM Technology Management Group. Regulations, threats, and vendor products change; specific obligations depend on your industry, jurisdiction, contracts, and data. Verify anything you plan to rely on against the primary source and consult qualified counsel or a security professional before acting.
Sources are cited as of the last-reviewed date shown above. Where a linked source has moved or been withdrawn, the citation reflects what was verifiable at review time.