Microsoft, Microsoft 365, Outlook, SharePoint, OneDrive, Microsoft Teams, Microsoft Graph, Azure, and Entra are trademarks of the Microsoft group of companies. ImpressionsDirect360 is an independent provider and is not affiliated with, sponsored by, or endorsed by Microsoft.
If you believe someone else is in a mailbox, treat it as in progress rather than finished. Phone us; do not wait on a ticket queue.
Phone us — do not wait on a ticket.
+1 (314) 339-4936 · Monday–Friday, 9:00 AM – 6:00 PM Central. If it is outside those hours and something is actively happening, call anyway and leave the details.
Call rather than email. An attacker sitting in a mailbox may be reading the mail you send about the incident, and a ticket in a queue moves too slowly for an intrusion that is still live.
Leave the suspicious rules, messages, and forwards in place until we have captured them. They tell us what was reached and how, and deleting them first removes the only record of what happened.
Resetting a password alone leaves existing sign-in tokens valid, so the attacker stays in. We reset the credentials and revoke the active sessions together, then re-register multi-factor.
Inbox rules that hide replies, forwarding to an outside address, added mailbox delegates, and consented third-party apps. Password theft is the way in; these are how the access is kept.
We review the sign-in and mailbox activity available in the tenant and give you a plain account of what was accessed, what was sent, and what you should tell your customers and your bank.
Invoice fraud is the usual goal. Anyone sent bank details from that mailbox during the window should confirm them by phone, on a number they already had, before paying.
Change it, yes — but it is not enough on its own. Sessions already signed in stay valid until they are revoked, and any inbox rule or mail forward the attacker created keeps working after the password changes. Call us so the whole set is closed at once.
Not before we have seen them. Those rules are the clearest evidence of what happened and are often what tells us which other accounts to check. Screenshot them if you can, and leave them in place.
From the sign-in and mailbox activity Microsoft records for the tenant. How much detail exists depends on the licences in place and how far back the retention goes, so we tell you what the records actually show rather than guessing.
Possibly. If personal data was exposed you may have a reporting duty, and if payment details were sent from the mailbox your customers and your bank need to know quickly. We give you the facts of what was accessed; the notification decision is yours, ideally with your legal advisor.
Immediately, by phone, at any hour it is noticed. This is the one issue where we would rather have a false alarm than a delayed report.
If the fault turns out to be in the Microsoft service rather than your setup, we take it from there — you keep one point of contact.