7 critical checks to ensure a compromised account is fully secured
When a Business Email Compromise (BEC) is identified, one of the first remediation actions is almost always a password reset. While changing the password is essential, it is rarely sufficient on its own.
Threat actors often establish additional methods of access, maintain active sessions, or compromise multiple accounts within an environment. If these issues are not identified and addressed, organisations may remain exposed even after credentials have been reset.
Below are some of the key areas that we recommend reviewing following a suspected compromise. While we have specifically referenced a Microsoft 365 environment, the principles apply to all platforms.
1. Revoke Active Sessions
One of the most commonly overlooked remediation steps is revoking active user sessions.
A threat actor may already possess valid access tokens or authenticated sessions. In some scenarios, a password reset alone does not immediately terminate these sessions, allowing unauthorised access to continue after the password has been changed.
Revoking active user sessions forces all currently authenticated sessions to reauthenticate using the new credentials. This helps ensure the threat actor cannot continue using previously issued tokens or cookies.
2. Determine What Was Actually Accessed
A common question from organisations following a compromise is:
"What did the threat actor actually look at?"
Unfortunately, the answer is rarely as simple as reviewing sent emails.
Microsoft 365 audit data can often provide insight into mailbox interactions conducted by the threat actor, allowing investigators to identify:
- Emails that were accessed
- Emails that were synchronised to external devices
- Deleted mail items
- Search activity conducted within the mailbox
Understanding which messages were accessed is critical when assessing the potential exposure of sensitive information and determining whether notifications or follow-up actions may be required.
3. Review Enterprise Applications and Third-Party Access
Many organisations focus solely on the user account itself, but threat actors frequently abuse application-based access.
Investigators should review Enterprise Applications and App Registrations for:
- Recently consented applications
- Unexpected OAuth grants
- Third-party mail clients
- Applications requesting extensive mailbox permissions
Particular attention should be paid to mail applications that can synchronise mailbox contents to external devices.
While these applications are often legitimate business tools, they can also be abused by threat actors to establish persistence or facilitate bulk access to mailbox contents.
In some cases, a threat actor may no longer require repeated sign-ins if an application has already been granted access.
4. Review Mailbox Rules
Mailbox rules remain one of the most common persistence mechanisms encountered during BEC investigations.
Threat actors may create rules to:
- Move emails into hidden folders
- Send messages directly to Deleted Items
- Forward emails to external addresses
- Hide security alerts and notification emails
Even relatively simple rules can significantly reduce the likelihood that a user notices suspicious activity.
All mailbox rules should be reviewed and validated following a compromise, with particular attention paid to any rules that were created or modified around the suspected compromise period.
5. Identify the Original Source of Compromise
Understanding how access was initially obtained is often just as important as remediating the affected account.
Potential causes include:
- Phishing emails
- Credential reuse
- Password spray attacks
- Legacy authentication
- Consent phishing
- Adversary-in-the-Middle (AiTM) attacks
If a phishing email is identified, the investigation should not stop with the affected user.
Questions that should be considered include:
- Who else received the email?
- Did other users interact with it?
- Were any credentials submitted?
- Were additional accounts compromised?
It is not uncommon for investigations that begin with a single compromised user to ultimately reveal multiple affected accounts.
6. Review Sign-In Activity Across the Tenant
BEC incidents are often initially discovered through suspicious activity involving a single user.
However, threat actors rarely restrict themselves to one account if additional opportunities exist.
A review of tenant-wide authentication activity may help identify:
- Additional compromised users
- Unusual locations
- Unknown devices
- Suspicious application activity
- Authentication attempts against privileged accounts
Examining only the affected user's logs may result in broader compromise activity being missed entirely.
7. Consider an Identity Threat Detection and Response (ITDR) Service
Many of the indicators described above are difficult to identify during day-to-day operations.
Identity Threat Detection and Response (ITDR) solutions are designed to provide visibility into identity-based attacks and suspicious authentication activity across the environment.
Benefits typically include:
- Detection of account compromise
- Monitoring for suspicious authentication patterns
- Identification of unusual sign-ins
- Visibility into persistence mechanisms
- Early warning of credential theft activity
- Continuous monitoring of Microsoft 365 and identity infrastructure
Given that identity-based attacks continue to be one of the most common causes of cyber incidents, organisations should consider whether additional monitoring would strengthen their security posture.
Final Thoughts
A password reset is an important first step following a Business Email Compromise, but it is rarely the only step. Effective remediation requires organisations to understand what was accessed, identify any persistence mechanisms, determine whether other users have been affected, and confirm that threat actors no longer have access to the environment.
By taking a broader investigative approach, organisations can reduce the risk of ongoing exposure and prevent a single compromised account from becoming a wider security incident.
If you have experienced a suspected BEC incident or would like to strengthen your visibility into identity-based threats, the Solis team can help with both incident response and identity monitoring solutions.
Contact our team today at ask@solissecurity.com