Using classic Outlook for Windows in business environments
Hi,
Based on what you described, including fraudulent ACH requests, messages sent from lookalike email addresses, and inbox rules that keep returning, your Microsoft 365 email account may be compromised.
Changing the password alone may not remove an attacker if they still have an active session, a connected application, automatic forwarding, or another method of access. Please contact your Microsoft 365 administrator or IT security provider immediately and ask them to try the following steps:
- Temporarily block access to the account
- Sign in to the Microsoft 365 Admin Center with a Global administrator account.
- Go to Users > Active users.
- Select the affected user.
- Select Block sign-in.
- This temporarily prevents additional access while the account is being secured.
- Reset the password from a trusted device
- Still on the affected user page, select Reset password.
- Use a new, unique password that has not been used for any other account.
- Reset the password from a trusted computer after the computer has been scanned for malware.
- Do not save the new password in an unfamiliar browser extension or password manager.
- Revoke all active sessions
- Sign in to the Microsoft Entra Admin Center.
- Go to Entra ID > Users.
- Select the affected user.
- Select Revoke sessions.
- This is important because an unauthorized person may still have an authenticated session, even after the password has been changed.
- Enable multifactor authentication
- On the affected user page, select Authentication methods.
- Remove any authentication method, phone number, email address, or device that is not recognized.
- Remove suspicious inbox rules
- Sign in to Outlook on the web: https://outlook.office.com
- Select Settings > Mail > Rules.
- Delete any rule that is not recognized.
- Pay particular attention to rules that:
- Forward or redirect messages
- Delete messages automatically
- Mark messages as read
- Move messages to Archive, Junk Email, Deleted Items, Notes, or RSS Subscriptions
- Contain terms such as “payment,” “ACH,” “invoice,” “bank,” “fraud,” or “phishing”
- Because the rules keep returning, the Microsoft 365 administrator should also check for hidden inbox rules using Exchange Online administrative tools.
- If a rule returns after being deleted, treat that as an indication that unauthorized access may still be active.
- Check mailbox forwarding
- Sign in to the Exchange Admin Center.
- Go to Recipients > Mailboxes.
- Select the affected mailbox.
- Open Mailbox settings > Manage email forwarding.
- Remove any forwarding address that is not recognized or authorized.
- The affected user should also sign in to Outlook on the web at https://outlook.office.com and check Settings > Mail > Forwarding.
- Confirm that forwarding is disabled unless there is a legitimate business reason for it.
- Review mailbox permissions and delegates
- On the affected mailbox page, open Delegation or Mailbox delegation.
- Review the following permissions:
- Send as
- Send on behalf
- Read and manage, also called Full Access
- Remove any person, mailbox, or account that should not have access.
- Review recent sign-in activity
- Go to the Microsoft Entra Admin Center.
- Go to Entra ID> Users > All users.
- Select the affected user.
- Open Sign-in logs.
- Review the entries for unfamiliar:
- Locations
- IP addresses
- Devices
- Applications
- Browsers
- Sign-in dates and times
- IP-based locations are approximate, so the administrator should review all available details together.
- Save or export suspicious sign-in information before making changes, since it may be needed for the investigation.
I hope the information I shared earlier was somewhat helpful in addressing your issue. If you have any further questions or updates, please don’t hesitate to share. I’m always happy to assist further if needed.