Home›Guides›What to do if…

What to do if…

A mailbox has been emptied or hacked

An emptied or hacked mailbox is dealt with by first cutting off access and forwarding, then restoring a copy from before it was emptied. Restoring while the hacker’s forwarding rule is still active fills a mailbox that empties again straight away.

Updated October 20264 min read6 sources cited

Key points

  • Simple recent deletion: check the bin first. Messages sent without your knowledge, unknown forwarding rules: this is a hack.
  • In the event of a hack, cut off access before restoring: password, sessions, second factor, forwarding rules, connected applications.
  • Warn contacts exposed to payment fraud by phone.
  • Native recovery windows are short: 14 days by default in Exchange Online (30 at most), 30 + 25 days in Gmail.
  • Without a copy outside the service, anything beyond these windows is lost.

1. Confirm the situation

  • The user deleted a folder and has noticed: check the bin first. This is often enough if you are still within the Microsoft 365 or Google retention window (see the table below).
  • The mailbox is sending messages that nobody wrote, or customers are receiving payment requests: this is a compromise, even if the messages are still there.
  • Forwarding rules, an unknown delegation, a sign-in from an unexpected country in the logs: compromise.

Microsoft lists other signs: rules that move messages to rarely viewed folders (junk email, RSS feeds), a recently added external forward, a modified signature, unexplained password changes or account lockouts.

If it is simply a recent deletion, restore from the bin or the backup and go straight to step 4. If it is a hack, complete steps 2 and 3 before any restoration.

2. Stop the leak

From the admin portal, not from the user’s computer:

  • change the password and enforce a second factor if there was none. Do not send the new password by email: the hacker may still be reading the mailbox;
  • revoke sessions and tokens: a changed password does not always sign out sessions that are already open;
  • delete forwarding rules, automatic replies, delegations and third-party applications connected to the mailbox;
  • check the registered authentication methods: a hacker may have added their own phone;
  • review the account’s administrative roles, if it was a privileged account;
  • check whether other mailboxes show the same unusual sign-in. A hacker rarely holds just one mailbox when they have obtained a reused password.

Microsoft describes these steps precisely for Microsoft 365; the equivalent exists in the Google Workspace admin console.

3. Warn the people concerned

Contacts targeted by payment fraud must be warned through a channel other than the compromised mailbox (phone). Management decides on the message. This is not an optional IT step: it is often where the money goes.

The rule of caution is to contact the creditor directly about any request received by message to pay to new bank details. If a transfer has already gone, call the bank immediately to try to block it, then file a complaint with the police in your country.

If the mailbox contained personal data (customers, employees) and the breach presents a risk to individuals, your country’s data protection authority (for example the APD in Belgium, the CNPD in Luxembourg or the CNIL in France) must be notified within 72 hours (GDPR, Article 33). Your legal adviser confirms the case.

4. Restore

In the backup, choose the last date on which the folder was still there, before it was emptied. Restore the folder or the mailbox. Tell the user what will still be missing: messages received between that date and now, if they were destroyed before being copied. That is the RPO of your email, made tangible.

If no backup outside the service exists, you are left with the bin and the vendor’s tools, within their limited window:

ServiceRecovery by the userRecovery by the administratorAfterwards
Microsoft 365 (Exchange Online)Deleted Items, then “Recover deleted items”14 days by default for permanently deleted items, adjustable up to 30 daysPermanent deletion
Google Workspace (Gmail)30 days in the binA further 25 daysNo restoration possible

Beyond that period, some of the mail is permanently lost. Say so plainly. The limits are detailed in Does Microsoft 365 really include a backup? and Does Google Workspace really include a backup?.

5. Afterwards

A second factor for all administrators and for this mailbox. A unique password. Check that a backup of this mailbox really exists: shared mailboxes are often forgotten. Record the incident in the internal breach register, even if it was not notified.

At WeDoBack

Microsoft 365 and Google Workspace email is restored from WeDoBack copies, stored outside the vendor’s service, including calendars and contacts, provided the mailbox was within scope: one agent per address, plus storage for the volume. Without an agent on that address, there is no WeDoBack copy, however good the server backup may be. Support can be reached on +33 9 72 50 78 28, from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time), or at [email protected]. WeDoBack does not revoke Microsoft or Google sessions on your behalf: this is done in the vendor’s console, and it comes before the restoration.

Frequently asked questions

How long can deleted emails be recovered without a backup?

In Exchange Online, Microsoft keeps permanently deleted items for 14 days by default, adjustable up to 30 days. In Gmail, users have 30 days in the bin, then the administrator has a further 25 days to restore. Beyond these periods, only an independent backup lets you go back in time.

Is changing the password enough to lock out a hacker?

No. Sessions already open and access tokens may remain valid, and a forwarding rule keeps working without a password. Microsoft recommends resetting the password, revoking sessions, enabling multi-factor authentication and reviewing forwarding rules, authorised applications and administrative roles.

Should you file a police report or notify the data protection authority?

Filing a complaint with the police in your country is advisable, especially in cases of financial fraud. If the mailbox contained personal data of customers or employees and the breach presents a risk to them, the GDPR (Article 33) requires the data protection authority to be notified within 72 hours. In all cases, the incident is recorded in the internal breach register.

A transfer has been sent to fraudulent bank details: what should I do?

Call your bank immediately to try to block or recall the funds: every hour counts. Inform the creditor whose identity was spoofed, keep the messages and statements, and file a complaint with the police in your country, online where possible.

Need help now?

Do not restore anything until you have identified a clean copy. We can guide you.

Call +33 9 72 50 78 28or write to us

Dealing with an incident right now?

Our teams help you identify the right copy and restore it, Monday to Friday, 9 am to 1 pm and 2 pm to 5:30 pm (Paris time).