If You Think Your Account Has Been Compromised

Do these three things now, in this order. Explanations are further down.

  1. Change your password. Go to mysignins.microsoft.com/security-info/password/change and change it. Use a different device if you can. If you cannot get in, use Reset your password, or call us.
  2. Call us. Phone us on (03) 6211 8100 rather than email. If your mailbox is compromised, an attacker may be reading or deleting your mail, and email may not reach us.
  3. Tell us what happened. Whatever you know. In particular:
    • Did you enter your passphrase into a website?
    • Did you approve a multifactor prompt? This one matters most.
    • Did you open an attachment or install anything?
    • Roughly when?

What we will do

  • Sign your account out everywhere and block the attacker's access
  • Check what was accessed, sent or changed
  • Look at whether anyone else was targeted
  • Tell you what we find, and what to do next

Most of this happens within minutes of your call.

Signs your account may be compromised

  • A multifactor prompt you did not trigger
  • Sent items you did not send, or replies to messages you never wrote
  • Emails disappearing from your inbox, or new rules moving mail to folders you did not create
  • Colleagues mentioning an odd message from you
  • Being signed out repeatedly, or your passphrase suddenly not working
  • Sign-in alerts from an unfamiliar location or device
  • Files appearing, disappearing or being shared without your knowledge

Any one of these on its own is worth a phone call.

Please do not investigate it yourself

It is a natural instinct, but changing settings, deleting suspicious rules or clearing your sent items destroys the evidence we need to work out what happened and how far it went.

Change your passphrase, call us, and leave the rest.

Checking your own account

If you want to look before you call, you can see your recent sign-ins at mysignins.microsoft.com. Unfamiliar locations or devices are worth reporting.

Do not let checking delay the phone call.

If personal information may have been exposed

If a compromise involved residents or colleagues personal information (e.g. mailbox contents, application records, staff details) tell us and tell your manager straight away, and say so explicitly.

This may need to be assessed as a data breach under privacy law, and that assessment has a deadline. It is not your job to make that judgement, but it is important you flag the possibility rather than assume someone else will.

You are not in trouble

Accounts get compromised. It happens to careful people, and modern phishing is genuinely convincing. Nobody is going to be disciplined for reporting this.

What causes real damage is the hours between something happening and someone mentioning it. Please make the call.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.