Initial Response
Account Compromise Quick Reference
Essential steps to contain and investigate a compromised user account, with focus on speed and preservation.
Initial Response · beginner · 30-60 min
Rapid response guide for when a user account is suspected or confirmed compromised.
Steps
5
01
Immediate Actions
Take these steps within the first 5 minutes.
- Reset the user's password immediately
- Revoke all active sessions (sign out everywhere)
- Disable MFA devices and re-enroll if needed
- Check and remove any forwarding rules
- Check for unauthorized OAuth app grants
Identity management console · Email admin
02
Initial Assessment
Understand how the account was compromised.
- Review authentication logs for suspicious sign-ins
- Check for logins from unusual locations or IPs
- Look for impossible travel scenarios
- Identify the likely compromise method (phishing, password reuse, etc.)
SIEM · Identity provider logs · Email security
03
Assess Impact
Determine what the attacker did with access.
- Review email sent folder for lateral phishing
- Check for accessed or downloaded files
- Look for inbox rules that forward or hide emails
- Check for calendar invite spam
- Review shared links and permissions changes
04
Contain Spread
Prevent the compromise from spreading.
- Alert users who received emails from the compromised account
- Block any malicious links that were sent
- Reset passwords for any exposed accounts
- Check if credentials were reused elsewhere
05
Recovery and Communication
Restore access and inform stakeholders.
- Work with user to securely reset password and MFA
- Verify no unauthorized changes to account settings
- Communicate with affected parties if needed
- Document the incident
Checklist
- Password reset completed
- All sessions revoked
- MFA devices reviewed/re-enrolled
- Email forwarding rules checked
- OAuth apps reviewed
- Authentication logs reviewed
- Impact assessed (sent emails, accessed files)
- Recipients of malicious emails warned
- User re-enabled with fresh credentials
- Incident documented
Evidence
- Authentication logs showing compromise timeline
- List of actions taken by attacker
- Emails sent from compromised account
- IP addresses used by attacker
- Timeline of compromise