Modern phishing targets identity, not machines: a convincing sign-in page harvests the password, and an adversary-in-the-middle kit steals the session token so MFA (Multi-Factor Authentication) does not save you. Invoice-redirect fraud is the small-business favourite — a mailbox rule quietly forwards supplier mail while the attacker edits bank details.
The first hour on a suspected compromise: reset the password, revoke all sessions and refresh tokens, re-register MFA methods, inspect mailbox rules and forwarding addresses, check recent sign-in locations, look at consented applications, and search whether the account sent anything to staff or clients.
Then decide the blast radius. What did that account have access to? Which files, which finance systems, which shared mailboxes? Notify the owner in writing with facts and timeline. If payment details or regulated data are involved, escalate to their insurer, legal counsel or compliance officer — that is their decision, but you must surface it.
Prevent the repeat: mandatory MFA with number matching, block legacy authentication, disable auto-forwarding to external addresses, enable mailbox auditing, and run short, frequent phishing awareness rather than one annual video nobody finishes.