You notice sent messages you didn’t write. A customer calls asking about a strange invoice “you” emailed them. Or you’re simply locked out. If your business email has been hacked, the next hour matters more than the next week — attackers move fast, and so should you.
We’ve helped Roanoke Valley businesses recover from exactly this. Here’s the step-by-step process, in the order that matters.
Step 1: Change the Password — From a Clean Device
Change your email password immediately, and do it from a device you trust — if a keylogger on your usual computer is how they got in, changing the password from that same machine hands them the new one. Use a phone on cellular data or a different computer if there’s any doubt. Make the new password long, unique, and never reused from another account.
Locked out entirely? Go straight to your provider’s account recovery process, and don’t stop trying — the longer an attacker holds the account, the more damage compounds.
Step 2: Sign Out Every Session, Everywhere
Changing the password doesn’t always kick out someone who’s already logged in. Both Google and Microsoft accounts have a “sign out of all sessions/devices” option — use it. This severs the attacker’s active connection instead of just locking the door behind them.
Step 3: Hunt Down Forwarding Rules and Filters
This is the step everyone misses, and it’s the attacker’s favorite trick. Hackers quietly create rules that forward copies of your mail to their address, or filters that auto-delete password-reset emails and replies from your bank — so they keep reading your mail long after you’ve “recovered” the account.
Check your email settings for forwarding addresses, inbox rules, and filters you didn’t create, and delete anything unfamiliar. Also review connected apps and delegated access while you’re in there.
Step 4: Turn On Two-Factor Authentication
If two-factor authentication had been on, you probably wouldn’t be reading this. Enable it now — an app-based authenticator is stronger than text messages. This single setting stops the vast majority of account takeovers cold.
Step 5: Check What Else That Account Unlocks
Your email is the master key to everything: banking, payroll, vendor portals, social media, your website. An attacker with your inbox can reset the password on nearly any account tied to it. Change passwords on your critical accounts — especially anything financial — and review those accounts for unfamiliar activity while you’re at it.
Step 6: Warn Your Contacts
Swallow the embarrassment and send the message: your account was compromised, and any recent emails asking them to click a link, pay an invoice, or update banking details should be ignored and verified by phone. Business email compromise scams work by exploiting the trust in your name — a quick warning can save a customer or vendor from wiring money to a criminal. It’s also the professional move, and people respect it.
Step 7: Figure Out How It Happened
Recovery without diagnosis invites a repeat. Was it a phishing email? A reused password exposed in a breach? Malware on a machine? Scan your computers, check whether other staff got the same phishing message, and close the actual hole — not just the symptom.
Don’t Want to Do This Alone?
Under pressure, it’s easy to miss a forwarding rule or an app connection — and one miss means the attacker is still inside. Jackrabbit Tech handles account takeover recovery for Roanoke Valley small businesses: we lock the attacker out, audit everything they touched, and harden your accounts so it doesn’t happen twice.
Suspect your email’s been compromised? Don’t wait. Call us at 540.300.1121 or request a free consultation today.

