You detect a hacked email account by monitoring for the tell-tale signs, especially new mail-forwarding or inbox rules, logins from unexpected locations, and unusual sending. Catching these early lets you lock the account and investigate before an attacker uses it to send fraudulent invoices or trick your suppliers. A quietly hijacked mailbox is one of the most dangerous threats to a contractor, because the criminal reads your mail and waits for a payment to target.
Attackers who get into a mailbox set it up to serve them silently. Here’s what to watch for, often called business email compromise.
1. Suspicious mail rules
A classic move is to create a rule that auto-forwards or hides certain emails, so the attacker sees everything and the real user misses the warning signs. An alert when a new forwarding or inbox rule appears is one of the strongest signals of compromise.
2. Logins from unexpected places
A UK-based account suddenly signing in from another country, or several failed attempts followed by success, can mean a stolen password is in use. Monitoring sign-ins helps us spot an account being accessed by someone who shouldn’t have it.
3. Unusual sending
A mailbox suddenly sending unusual volumes, or messages the user didn’t write, is a red flag. Catching this quickly limits the damage and stops it spreading to your clients and suppliers.
4. Act fast, with MFA already in place
When a sign of compromise appears, we lock the account, reset access and investigate. MFA across your firm makes compromise far less likely in the first place, and monitoring catches the cases that slip through.
A real example: a hostile mail rule caught early
We support a security and M&E contractor where alerts fired when inbox-forwarding rules were created across accounts, a classic sign of an attacker hiding their tracks. Because mail-rule changes were monitored, we could review each one and act on the hostile one, rather than discovering a silent forwarder weeks later.
For most building-services and M&E contractors, this sits within fully managed IT at about £45 to £100 per user per month, billed per user, with the security and on-site remote access your teams need built in.
Why security and M&E contractors choose First Stop IT
First Stop IT has supported businesses since 2002, including security, fire and M&E contractors and building-services firms with office and site-based teams. We know how these businesses run: hosted desktops for staff on site and in the office, QuickBooks and payroll, secure remote access for field engineers, Microsoft 365 and Google Workspace, and the layered security that protects a firm handling client sites and payments, from MFA and application allowlisting to managed threat detection. We support contractors in Harlow, Bishop’s Stortford and across Essex, Hertfordshire and London. Our credentials include:
- Cyber Essentials Certified
- IASME Cyber Assurance (Gold)
- NCSC Assured Service Provider (Cyber Advisor for Cyber Essentials)
- Microsoft Partner
- Crown Commercial Service Supplier (G-Cloud)
- Quality Principles Certified
We look after more than 2,000 endpoints across 50 companies, we’ve been named a Top 50 UK MSP for three years running, and we support organisations with 10 to 100 employees across Essex, Hertfordshire and London, including Harlow and Bishop’s Stortford.
Book a free IT and cyber security review
Want early warning of a hacked account? Book a free IT and cyber security review with First Stop IT and we’ll put monitoring in place.