Hacked mailboxes and business email compromise

Business Email Takeover Forensics

Do you do email forensics on mailboxes that were hacked? Yes. GDF has conducted hundreds of forensic analyses of compromised email accounts. We examine how access occurred, what the attacker did and whether access may remain.

Bagged hard drive beside a forensic write blocker.

The engagement

Find out what happened after an email account was compromised

A suspicious login, changed payment instruction or hidden forwarding rule can raise urgent questions. We examine Microsoft 365, Gmail and Google Workspace accounts and supporting evidence to determine what can be established about unauthorized access and data exposure.

Business email takeover means an attacker gained access to an account. Business email compromise can also involve a spoofed address or lookalike domain without a hacked mailbox. We test these explanations instead of assuming that every fraudulent message proves account access.

We work with authorized business contacts, IT responders and counsel to preserve evidence and explain findings. If access is ongoing, containment and evidence preservation need coordinated attention.

Scope

  • Entry and phishing analysis

    Test credential theft, malicious sign-ins, application access and other supported explanations.

  • Access and exposure

    Correlate email, security logs and file activity to assess the supported scope.

  • Persistence review

    Examine forwarding, rules, permissions, sessions, applications and relevant endpoints.

How did the attacker get in?

We build a timeline from available sign-in activity, security records, messages and relevant device evidence. The analysis may support stolen passwords, successful phishing, compromised sessions, unauthorized application permissions or another entry path. We test the explanation against the records rather than treating an unfamiliar location as proof of the attack vector.

Lawful dark web exposure research can identify previously exposed account information and help test a credential-theft hypothesis. An exposed credential alone does not prove it was used in this incident. We correlate exposure information with the actual account activity and state when the initial access path cannot be established.

Was phishing successful?

We examine suspicious messages, headers, links and attachments alongside the account timeline. Where evidence is available, we look for the sequence from message delivery to interaction and subsequent unauthorized access. A delivered phishing message is not, by itself, proof that the recipient clicked or supplied credentials.

We also distinguish a spoofed sender from a message sent through an accessed account. That distinction matters when determining which systems and people may be affected and which records should be preserved next.

Concerned about an active email takeover?

Call to discuss the affected accounts and immediate evidence priorities. Do not send passwords or sensitive evidence through the website form.

Call 1-800-868-8189 Discuss a compromised account

What data was accessed or exfiltrated?

We compare mailbox actions, message records, file activity, forwarding and available download or synchronization evidence. The report separates confirmed actions from possible exposure and unsupported assumptions. An account with access to email may also have access to cloud files, depending on its permissions.

Some logs record system access or synchronization rather than proof that a person read a particular message. Missing logs do not demonstrate that no data was taken. We explain the available coverage, time period and limitations so counsel and responders can evaluate the exposure. See Microsoft guidance on mail access evidence and Google guidance on Gmail log events.

Is the attacker still in the mailbox or computer?

A password change may not address every route back into an account. We examine available evidence of forwarding rules, delegated access, permissions, connected applications and active sessions. When relevant and authorized, the scope includes endpoint evidence to assess whether the computer itself remains compromised.

We identify supported persistence mechanisms and work with the response team to document remediation and follow-up checks. The findings describe the systems and time period examined; they do not claim that the absence of a visible event proves an attacker is gone. Microsoft provides guidance on responding to a compromised email account.

Preserve the evidence while stopping ongoing access

Mailbox content, security logs and device evidence answer different questions. We help prioritize short-lived records and document changes made during response. Forwarding a few suspicious messages is not a substitute for preserving the original messages, relevant account activity and settings.

Much of the collection can be performed remotely. Unlike routine eDiscovery collection, an active takeover may require blocking access, revoking sessions or restricting account use. We coordinate with authorized responders so urgent containment is not delayed solely for collection, and record the effect of response actions on the evidence.

Clear findings for the people making decisions

GDF brings deep email-log and tracking experience to hacked-account analysis. We organize the incident chronology, supported entry path, affected accounts, data exposure evidence and persistence findings into a report that business leaders and counsel can understand.

Our in-house processing tools help collect and organize evidence, identify duplicate material and prepare review sets. Where litigation or a broader document review follows, we can prepare agreed production formats and provide expert support. The scope, remaining gaps and recommended follow-up are stated plainly.

Methodology

Answer the incident questions in order

  1. Scope and coordinate

    Identify affected accounts, authorized contacts, time constraints and ongoing access.

  2. Preserve relevant records

    Collect available messages, logs, settings and supporting file or endpoint evidence.

  3. Reconstruct the activity

    Test entry, phishing, access, exfiltration and persistence against correlated sources.

  4. Report and support response

    Explain confirmed findings, possible exposure, gaps and follow-up priorities.

Evidence commonly examined

Evidence reviewed

  • Original suspicious messages, headers and attachments
  • Available sign-in, mailbox, application and file activity records
  • Forwarding, permission and session evidence
  • Relevant endpoint records and lawful credential-exposure research

What you can expect

What you receive

  • Incident timeline and supported initial-access findings
  • Account and data-exposure assessment with evidence limitations
  • Persistence findings and documented response follow-up
  • A clear report and evidence package for counsel and authorized stakeholders

Frequently asked

Common questions

Can you determine how the attacker obtained credentials?

We test possible entry paths using email, account logs, device evidence and lawful exposure research. The available records may establish a path or leave more than one explanation; we report that distinction.

Can you prove which emails were read or stolen?

Sometimes records support specific access or transfer activity, but coverage varies. We distinguish recorded access, possible exposure and evidence of transfer; not every access event proves that a person read a message.

Is a password reset enough?

Not always. Rules, permissions, sessions, connected applications or a compromised endpoint may provide continuing access. We assess the relevant evidence with the authorized response team.

Can you analyze Microsoft 365 and Google Workspace accounts remotely?

Yes. Authorized collection can often be conducted remotely. A compromised account may need access restricted while the incident is contained, so continued use cannot be promised.

Work with the email evidence team

Meet our forensic experts or explore eDiscovery collections and production.

Concerned about an active email takeover?

Call to discuss the affected accounts and immediate evidence priorities. Do not send passwords or sensitive evidence through the website form.

Call 1-800-868-8189 Discuss a compromised account

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.