How do I know if my Microsoft 365 email has been hacked?
The short answer: the clearest sign is people telling you they've had odd emails from you that you didn't send. Other clues are inbox rules you didn't create, email being forwarded to an outside address, missing messages, and sign-in or MFA prompts you didn't trigger. If you see any of these, change your password from a safe device straight away and sign out everywhere, then work through the steps below.
Warning signs to look for
Attackers who get into a mailbox usually try to stay quiet, so the signs are often small. Watch out for:
- Contacts receiving emails you didn't send. Often a "shared document" link, a fake invoice or a request to update bank details. If a customer asks "did you mean to send this?", take it seriously.
- Strange inbox rules. Rules that move emails to obscure folders like RSS Feeds or Archive, mark them as read, or delete anything containing words like "invoice", "payment" or "hacked".
- Forwarding to an outside address. A forwarding setting that copies all your email to an address you don't recognise.
- Missing emails. Replies you're expecting never arrive, because a rule is hiding them.
- Odd Sent Items or Deleted Items. Emails you didn't send, or a Sent Items folder that's been emptied.
- Sign-in alerts or MFA prompts you didn't trigger. An approval request on your phone when you're not signing in is a big red flag. Don't approve it.
- Your password has stopped working. Someone may have changed it. See locked out of your Microsoft 365 account.
What to do straight away
Work through these in order. Speed matters more than perfection.
- Change your password from a safe device. Use a computer or phone you trust, not one that might be infected. Make it long and unique.
- Sign out everywhere. In your account settings at myaccount.microsoft.com, use Sign out everywhere. An admin can also revoke your sessions from the Microsoft 365 admin centre.
- Check your inbox rules. In Outlook on the web, go to Settings > Mail > Rules. Delete anything you didn't create.
- Check forwarding. In the same settings, look at Forwarding and turn off anything you don't recognise.
- Check your MFA methods. At Security info in your account settings, remove any phone number or authenticator app you didn't add. Attackers often add their own so they can get back in.
- Tell your IT person. They can check sign-in logs, look for other affected accounts and see what was sent from yours.
- Warn your contacts. Send a short message to anyone who may have received a fake email, telling them to ignore it and not to click any links.
If money might be involved
If the attacker may have sent fake invoices or changed bank details, act fast:
- Phone your bank immediately if you think a payment has gone to the wrong account. The sooner they know, the better the chance of stopping it.
- Phone (don't email) any customers or suppliers who may have been sent new bank details.
- Report it to Report Fraud (which replaced Action Fraud in December 2025), the UK's national reporting service for fraud and cybercrime, at reportfraud.police.uk or on 0300 123 2040. In Scotland, report it to Police Scotland on 101.
Do you need to tell the ICO?
If the mailbox held personal data, such as customer details, staff records or anything sensitive, you may have had a personal data breach. Under UK GDPR, if a breach is likely to put people's rights at risk, you must report it to the Information Commissioner's Office within 72 hours of becoming aware of it. The ICO website has a self-assessment tool to help you decide. If in doubt, record what happened and why you made your decision either way.
Stop it happening again
Most mailbox takeovers start with a stolen password and no extra protection. The best defences are:
- MFA on every account, preferably using the Microsoft Authenticator app.
- Blocking automatic forwarding to outside addresses, which an admin can switch off for everyone.
- SPF, DKIM and DMARC on your domain, so attackers find it harder to fake your address. See SPF, DKIM and DMARC explained.
Our free Microsoft 365 audit checks these settings for you.
Common questions
Is changing my password enough?
No. Attackers often leave rules, forwarding or their own MFA method behind so they can carry on reading your email. Signing out everywhere and checking those settings is just as important.
How did they get my password?
Usually from a fake sign-in page in a phishing email, or a password reused from another website that was breached. It rarely means someone guessed it.
Someone is sending emails "from" me but my account looks fine. Have I been hacked?
Not necessarily. Your address may be being faked (spoofed) from outside without anyone touching your account. Check the sending address carefully. Setting up DMARC on your domain makes spoofing much harder.
Should I delete the fake emails from Sent Items?
Not straight away. They're useful evidence of what was sent and to whom. Let your IT person look first.
Want us to check yours?
Our free Microsoft 365 audit looks at your licences, security, email and backups, and tells you in plain English what to fix first. No card, no obligation.