← Back to Blog
Cybersecurity

Microsoft 365 Account Hacked and Sending Spam?

3 October 2026 · By Ethan Fernandes

Microsoft 365 Account Hacked and Sending Spam?

Odd emails sent from you, bounces you didn't send, or "user is restricted from sending email"? Here's what to do when a Microsoft 365 account is hacked.

Clients are ringing to ask about a strange email you sent: a "shared document", an urgent invoice or a DocuSign link. Your inbox is filling with "Undeliverable" bounces for messages you never wrote. Or you suddenly can't send at all, and see "Your message couldn't be delivered because you weren't recognized as a valid sender" or an admin alert that a "User restricted from sending email".

These are the classic signs of a compromised Microsoft 365 mailbox. Speed matters: the attacker may be reading your email, emailing your clients and setting up invoice fraud. Here's what to do, in order.

Quick answer

Reset the password and revoke all sessions immediately, then check and remove any inbox rules, forwarding, unknown MFA methods and suspicious app consents. Once the account is clean, an admin can unblock it from the Restricted entities page in Microsoft Defender. Then warn your contacts and review what the attacker accessed.

Why This Happens

Most compromises start with a phishing email that leads to a convincing Microsoft sign-in page. Modern phishing kits can capture both your password and your MFA session, so even accounts with MFA get taken over. Once in, attackers typically hide their activity with inbox rules, send phishing to everyone in your contacts, and look for invoices to tamper with. Microsoft detects the spam surge and restricts the account from sending.

Signs an Account Is Compromised

  • Bounces and replies to emails you didn't send.
  • Sent Items or Deleted Items containing unfamiliar messages, or nothing at all where you'd expect them.
  • Emails disappearing because a rule moves them to RSS Feeds, Archive or Conversation History.
  • Sign-in alerts from unfamiliar locations, or MFA prompts you didn't trigger.
  • The account being blocked from sending.

Don't just reset the password and move on. Attackers often leave behind forwarding rules, an extra MFA method or an app with access to your mailbox, any of which lets them carry on after a password change.

Step 1: Lock the Attacker Out

For your Microsoft 365 admin

  1. Reset the password in the Microsoft 365 admin centre (Users > Active users, select the user, Reset password). Use a long, unique password.
  2. Revoke sessions. In the Entra admin centre, open the user and choose Revoke sessions. This invalidates refresh tokens so stolen sessions stop working. With Microsoft Graph PowerShell, Revoke-MgUserSignInSession -UserId user@yourdomain.co.uk does the same.
  3. If you can't act quickly on the rest, temporarily block sign-in for the user while you investigate.

Step 2: Remove What the Attacker Left Behind

Inbox rules. In Outlook on the web, go to Settings > Mail > Rules and delete anything you didn't create. In Exchange Online PowerShell:

  • Get-InboxRule -Mailbox user@yourdomain.co.uk | Format-List Name,Description,Enabled
  • Remove-InboxRule -Mailbox user@yourdomain.co.uk -Identity "RuleName"

Forwarding. Check Settings > Mail > Forwarding in Outlook on the web, and as admin:

  • Get-Mailbox user@yourdomain.co.uk | Format-List ForwardingAddress,ForwardingSmtpAddress,DeliverToMailboxAndForward
  • Set-Mailbox user@yourdomain.co.uk -ForwardingAddress $null -ForwardingSmtpAddress $null

MFA methods. In the Entra admin centre, check the user's Authentication methods and delete any phone number or Authenticator registration the user doesn't recognise.

Mailbox permissions and delegates. Get-MailboxPermission -Identity user@yourdomain.co.uk shows who else has access. Remove anything unexpected.

App consents. In the Entra admin centre, look under Enterprise applications (and the user's applications) for apps the user consented to recently, especially mail or file access apps with unfamiliar names. Remove them.

Signatures and auto-replies. Check these haven't been changed to include malicious links.

Step 3: Unblock the Account

Only once the account is clean:

  1. Go to the Microsoft Defender portal and look for Restricted entities (under Email & collaboration, Review).
  2. Select the user and choose Unblock.
  3. Alternatively, in Exchange Online PowerShell, use Get-BlockedSenderAddress to confirm and Remove-BlockedSenderAddress -SenderAddress user@yourdomain.co.uk to release it.

It can take a while, sometimes up to a day, for sending to resume fully.

Step 4: Find Out What Happened

  • Sign-in logs in the Entra admin centre show where and how the attacker signed in.
  • The audit log in Microsoft Purview shows mailbox and file actions, if auditing is on.
  • Message trace in the Exchange admin centre shows what was sent and to whom.
  • Check whether the user's password was reused elsewhere and change it there too.

Step 5: Tell the Right People

  • Email or call your contacts to warn them not to open recent messages or links from you, and especially not to act on any change of bank details without confirming by phone.
  • Tell your bank if you think invoices or payment details were tampered with.
  • If personal data may have been accessed, you may need to report it to the ICO within 72 hours of becoming aware. Report fraud or cybercrime to Action Fraud.

Our guide on what to do when your business gets hacked covers the wider response.

How to Stop It Happening Again

  • Require MFA for everyone, preferably phishing-resistant methods such as passkeys or Windows Hello for Business for admins and finance staff.
  • Use Conditional Access to block legacy authentication and limit sign-ins to compliant devices where practical.
  • Keep external automatic forwarding blocked by default.
  • Restrict users from consenting to apps themselves, with an admin approval process instead.
  • Turn on alerts for suspicious inbox rules and forwarding, and actually monitor them.
  • Train staff to spot phishing. Our guide to spotting a phishing email is a good start.

When to Call in Help

If you're not confident you've found everything, or financial data, client data or payments may be involved, get specialist help now rather than later. Our cybersecurity team can contain the incident, investigate and harden your tenant, and our managed IT service includes ongoing monitoring. Contact us straight away. Afterwards, a free IT health check can show where else you're exposed.

Common questions

Common signs are bounces for emails you didn't send, contacts receiving odd messages from you, unknown inbox rules or forwarding, and being blocked from sending. Your admin can confirm by checking the Entra sign-in logs.

First secure the account by resetting the password, revoking sessions and removing malicious rules. Then an admin can release the user from the Restricted entities page in the Microsoft Defender portal or with Remove-BlockedSenderAddress in PowerShell.

No. Attackers often leave inbox rules, forwarding, extra MFA methods or app permissions that keep working after a password change. All of these need checking and removing, and sessions need revoking.

If personal data may have been accessed and the breach is likely to pose a risk to people, UK GDPR requires you to report it to the ICO within 72 hours of becoming aware. If you're unsure, document your assessment and take advice.

Want to talk about this?

Book a free 15-minute call and we'll discuss how this applies to your business.

Get IT tips in your inbox

Practical advice for small businesses. No spam.