Skip to content

Need urgent help? Call us at 440-991-9980

Passwords & Accounts

Suspicious sign-in alert, or you think your account was compromised

What to do the moment you suspect someone else has your work account — the immediate steps that limit the damage, and what to leave to us.

3 min read Updated
  • security
  • compromise
  • phishing
  • incident
On this page

If you think someone has your password — you entered it on a page that turned out to be fake, you approved a sign-in prompt you did not trigger, or Microsoft emailed you about unusual activity — treat it as urgent. Attackers move fast, usually within minutes, and the first thing they do is set up mail forwarding so they can read your messages quietly.

This is one of the few articles where step one is call us. Everything else can happen while we are on the line.

Right now, in this order

  1. Call 440-991-9980. Do not email. If the account is compromised, whoever is in it may be reading and deleting your mail.
  2. Change your password using Ctrl + Alt + Delete on your work computer. Do not reuse anything close to the old one.
  3. Stay at your desk if you can. We may need to walk through screens with you.
  4. Do not delete anything. Suspicious emails, odd sent items, strange rules — leave them. They tell us what happened and how far it went.

We will handle the rest: revoking active sessions so the attacker is kicked out everywhere, checking for forwarding rules, reviewing sign-in locations, and looking at whether anything was sent from your mailbox.

Signs worth reporting

Any one of these is enough reason to call:

  • An MFA approval request appeared on your phone when you were not signing in.
  • Email you did not send appears in your Sent Items — or your Sent Items looks suspiciously empty.
  • Colleagues or clients mention a message from you that you did not write.
  • Mailbox rules exist that you did not create, especially ones moving mail to Deleted Items, RSS Feeds, or Archive.
  • You entered your password on a page reached from an email link and then had second thoughts.
  • Microsoft emailed about a sign-in from a country you have never visited.
  • Files in OneDrive or SharePoint were renamed, deleted, or shared externally without your doing.

How to check your own mailbox rules

Useful to do while you wait for us, and harmless:

  1. Go to outlook.office.com and sign in.
  2. Click the gear icon, top right.
  3. Choose Mail › Rules.
  4. Look at every rule listed. If you did not create it, do not delete it — screenshot it and tell us. Attackers commonly add a rule with a blank or single-character name that forwards everything to an outside address.
  5. Also check Mail › Forwarding and confirm forwarding is off.

What we will ask you

  • Roughly when you noticed something wrong.
  • Whether you entered your password anywhere unusual, and on which site.
  • Whether you approved an MFA prompt.
  • What device you were on, and whether you were on the office network, home, or public Wi-Fi.
  • Whether anything sensitive — invoices, banking details, client data — was in the mailbox.

Please answer honestly, including if you clicked something you now regret. Nobody at Iconium Networks is going to give you a hard time about it; phishing pages are convincing on purpose, and knowing exactly what happened lets us contain it faster. Guessing costs us hours.

Why the “invoice” ones matter most

The most expensive incidents we see are not dramatic. Someone gets into a mailbox, watches quietly for a fortnight, then intercepts a genuine invoice thread and sends a version with different bank details. It reads perfectly, because it is a real conversation.

So if your role involves payments, and you suspect any compromise at all, tell your finance team to verify bank details by phone — using a number they already have, not one in the email — for anything in flight.

After it is contained

We will typically ask you to sign in again everywhere, re-register MFA, and re-enter your password on your phone. Your desk phone and printers are unaffected. If we found evidence anything was accessed, we will tell you plainly and put it in writing.


Suspect something is wrong? Call 440-991-9980 now, or email [email protected] if you are certain your mailbox is unaffected. Out of hours, still call — the voicemail and after-hours routing are monitored for exactly this. If it turns out to be nothing, that is a good outcome and we would much rather check.

Did this fix the problem?

If you followed these steps and it's still not working, get in touch and mention this article — Suspicious sign-in alert, or you think your account was compromised — so we can skip the basics.

Still stuck? Email support at [email protected] or call 440-991-9980 to open a ticket.