Email Account Compromise Investigation: How to Investigate Unauthorized Email Access and Preserve Evidence
An email account can contain years of sensitive information.
Personal conversations. Business records. Financial documents. Password-reset messages. Customer information. Cryptocurrency notifications. Cloud-service alerts. Contacts. Invoices. Account verification links.
That makes an email account extremely valuable to an attacker.
Sometimes the first warning is an unfamiliar login notification.
Other times, messages disappear, password-reset emails appear unexpectedly, contacts receive emails you never sent, forwarding rules are changed, or you suddenly lose access to the mailbox.
And sometimes there is almost no visible warning at all.
If someone has gained unauthorized access to an email account, changing the password is an important security step—but it may not explain what happened.
How did the account become compromised?
When did unauthorized access begin?
What emails were accessed?
Were messages deleted or forwarded?
Were other accounts compromised through the mailbox?
Did the attacker change security or recovery settings?
Could unauthorized access still exist?
An email account compromise investigation examines available digital evidence to reconstruct suspicious activity, determine the potential scope of unauthorized access and preserve information that may help establish what happened.
What Is Email Account Compromise?
Email account compromise occurs when someone gains unauthorized access to another person’s or organization’s email account.
The attacker may simply monitor incoming messages.
Or they may actively use the mailbox to:
- Send messages
- Delete emails
- Search for sensitive information
- Reset passwords
- Impersonate the account owner
- Create forwarding rules
- Change security settings
- Target contacts
- Intercept invoices
- Access connected services
- Obtain financial information
- Identify cryptocurrency accounts
- Conduct additional fraud
For businesses, a compromised mailbox can also become the starting point for business email compromise, invoice fraud, payment diversion and impersonation.
The visible email problem may therefore represent only one part of a larger incident.
How Do Email Accounts Get Compromised?
There is no single method.
Phishing
An attacker may send a convincing message directing the recipient to a fraudulent login page.
The page may imitate a familiar email provider or business service.
If credentials are entered, they can potentially be captured by the attacker.
Stolen or Reused Passwords
Credentials exposed in an unrelated data breach may be tested against other services.
If a person reused the same password for email, an attacker may be able to access the mailbox without compromising the email provider itself.
Credential-Stealing Malware
Malware on a computer or mobile device may capture passwords, browser information, cookies or other authentication data.
In these situations, changing the email password without addressing the affected device may not solve the entire problem.
Session Theft
Passwords are not the only potential target.
In some incidents, attackers attempt to obtain authenticated browser sessions or tokens that may provide access without repeatedly entering the victim’s password.
Compromised Recovery Accounts
An email account can sometimes be accessed through its recovery mechanisms.
If an attacker controls the recovery email address or telephone number, they may attempt to reset credentials.
Social Engineering
Attackers can also manipulate users, employees or service providers into providing credentials, approving authentication requests or changing account information.
Determining which method was involved should be based on available evidence rather than assumptions.
Signs Your Email Account May Have Been Compromised
Possible warning signs include:
- Login alerts from unfamiliar devices
- Unexpected password-reset messages
- Password changes you did not make
- Unknown recovery email addresses
- Unknown recovery phone numbers
- Messages appearing as read when you did not open them
- Missing or deleted emails
- Emails in your Sent folder that you did not send
- Contacts receiving unusual messages from your address
- New forwarding rules
- Unknown filters
- Unexpected authentication changes
- Security alerts being deleted
- Unfamiliar devices appearing in the account
- Being unexpectedly logged out
- Other accounts being reset shortly afterward
- Unexplained financial or cryptocurrency activity
A sophisticated attacker may deliberately avoid making obvious changes.
The absence of suspicious messages in the Sent folder does not necessarily prove that the mailbox was never accessed.
Why Email Compromise Can Become Much Bigger Than Email
Your mailbox is often the security gateway to your digital life.
Think about what happens when you forget a password.
Many services send a reset link to your email address.
An attacker with mailbox access may therefore search for evidence of accounts associated with:
Banks
Cryptocurrency exchanges
Social media
Cloud storage
Business systems
Shopping accounts
Payment services
Website administration
Insurance
Investment accounts
Customer portals
They may then attempt to reset credentials for those services.
This means an investigation should consider whether the email compromise led to secondary account takeovers.
Our broader Account Takeover Investigation guide addresses that type of unauthorized account access.
What Should You Do After Discovering Suspicious Email Access?
Securing the account is important, but preserve relevant information when possible.
Document what you discovered.
That can include:
- Login alerts
- Security notifications
- Unknown devices
- Changed recovery information
- Suspicious messages
- Password-reset emails
- Forwarding rules
- Filters
- Financial notifications
- Dates and timestamps
Take screenshots of important information where appropriate.
Also consider whether the email provider allows you to review or export security activity.
If you are dealing with a business account, relevant evidence may also exist in organizational security and administrative logs.
Do not assume that deleting suspicious messages removes the underlying access.
Investigating Login History
Authentication records can be one of the most useful evidence sources.
Depending on the email service and account configuration, records may show information such as:
- Login timestamps
- IP addresses
- Devices
- Browsers
- Approximate locations
- Authentication methods
- Failed login attempts
- Successful logins
- Security changes
Investigators can compare this information with the legitimate user’s activity.
For example, a login from unfamiliar infrastructure immediately before a forwarding rule was created may warrant further investigation.
But one unfamiliar IP address does not automatically identify an attacker.
VPNs, proxies, corporate networks, cloud infrastructure and mobile networks can complicate interpretation.
Hidden Email Forwarding Rules
Forwarding rules deserve particular attention.
An attacker who gains access to a mailbox may create a rule that automatically forwards certain messages to another address.
This can potentially allow continued monitoring even after the victim becomes suspicious.
Rules may target specific types of messages, such as:
- Financial communications
- Invoices
- Security notifications
- Password resets
- Cryptocurrency messages
- Customer communications
- Executive correspondence
Attackers may also use mailbox rules or filters to move certain messages into folders or delete them automatically.
This can make malicious activity less obvious.
An investigation should therefore examine more than the inbox and Sent folder.
Were Emails Deleted?
Deleted emails can sometimes become relevant evidence.
An attacker may remove:
- Security alerts
- Password-reset notifications
- Financial confirmations
- Messages they sent
- Authentication warnings
- Communications associated with fraud
Whether deleted material can be recovered depends on the service, retention policies, account configuration and how much time has passed.
This is another reason early evidence preservation matters.
Building an Email Compromise Timeline
A forensic timeline can help connect events that initially appear unrelated.
For example:
Phishing email received
↓
Credentials entered into fraudulent page
↓
Unknown login
↓
Mailbox forwarding rule created
↓
Security notification deleted
↓
Password reset requested for another service
↓
Secondary account compromised
↓
Unauthorized transaction
↓
Victim discovers suspicious activity
That sequence is only an example.
Real incidents should be reconstructed from the available evidence.
Investigators may correlate:
- Email timestamps
- Authentication history
- Security alerts
- Account-setting changes
- Device evidence
- Password resets
- Transaction records
- Communications
- Other account activity
The objective is to establish the most reliable chronology possible.
Was Your Email Used to Reset Other Accounts?
This is one of the most important questions following a serious mailbox compromise.
Investigators may search for:
- Password-reset emails
- New-device notifications
- Authentication codes
- Account verification messages
- Changes to financial accounts
- Cryptocurrency exchange notifications
- Social media security messages
- Cloud-account changes
If several accounts were compromised in sequence, the email account may have been the attacker’s starting point.
That changes the scope of the investigation considerably.
Instead of investigating one mailbox, the incident may become a broader digital account takeover investigation.
Business Email Compromise
For organizations, unauthorized mailbox access can create another serious risk: business email compromise, often abbreviated BEC.
The FBI describes BEC as a sophisticated scam targeting businesses and individuals who perform legitimate transfer-of-funds requests. Attackers may compromise or impersonate business email accounts to manipulate payments or financial transactions.
A compromised business mailbox can potentially be used to:
- Monitor invoices
- Study payment procedures
- Impersonate executives
- Contact customers
- Modify payment instructions
- Redirect wire transfers
- Target vendors
- Obtain confidential business information
This deserves its own dedicated investigation topic, and we will build a separate Business Email Compromise Investigation article later in this cluster.
Could the Attacker Still Have Access After You Change the Password?
Potentially.
Changing the password is important, but investigators may also consider whether the attacker changed or established:
- Recovery email addresses
- Recovery phone numbers
- Forwarding rules
- Mailbox delegates
- Connected applications
- App passwords
- Authentication methods
- Trusted devices
- Active sessions
- API access
- Other account permissions
The exact features differ between email providers.
The important point is that a password is only one part of modern account security.
Should the Computer or Phone Be Investigated Too?
Sometimes.
If evidence suggests that credentials were stolen from a device, the investigation may need to extend beyond the email account.
For example, investigators may need to consider whether a computer or mobile device contains evidence of:
- Credential-stealing malware
- Suspicious applications
- Malicious browser extensions
- Phishing activity
- Suspicious downloads
- Unauthorized remote access
This is where email compromise can overlap with computer forensics and mobile phone forensics.
Simply securing the mailbox may not resolve a compromised endpoint.
Can You Determine Who Accessed an Email Account?
Sometimes an investigation can uncover useful indicators.
Potential evidence may include:
- IP addresses
- Email addresses
- Telephone numbers
- Domains
- Device information
- Usernames
- Related accounts
- Hosting infrastructure
- Cryptocurrency addresses
- Repeated technical identifiers
But identifying an individual is more complicated.
An IP address may belong to a VPN, proxy, mobile carrier, cloud provider, public network or compromised computer.
Some records needed for further attribution may only be available to the email provider or other companies and may require appropriate legal process.
A credible investigator should therefore distinguish between identifying technical infrastructure and proving who the person behind it was.
What If Money or Cryptocurrency Was Stolen?
An email compromise can sometimes lead directly to financial loss.
If that happens, preserve the financial evidence as well.
This may include:
- Transaction confirmations
- Bank information
- Wire instructions
- Cryptocurrency wallet addresses
- Transaction hashes
- Exchange notifications
- Payment emails
- Messages from the attacker
- Dates and timestamps
If cryptocurrency was transferred, public blockchain data may provide another source of evidence that can be examined through blockchain transaction tracing.
However, tracing cryptocurrency and recovering cryptocurrency are not the same thing.
No legitimate investigator should guarantee that stolen funds will be recovered simply because transactions can be traced.
What Evidence Should Be Preserved?
Depending on the incident, relevant evidence may include:
- Authentication history
- Login notifications
- Security alerts
- Suspicious emails
- Message headers
- Forwarding rules
- Mailbox filters
- Account-setting changes
- Recovery information
- Device information
- Password-reset messages
- Transaction records
- Cryptocurrency addresses
- Relevant screenshots
- Communications with suspected attackers
- Administrative logs
NIST’s digital-forensics guidance emphasizes preserving and analyzing digital information systematically during incident response rather than treating individual artifacts in isolation.
When Should You Consider an Email Account Compromise Investigation?
Further investigation may be appropriate when:
- Someone accessed your email without permission
- You received suspicious login notifications
- Your password or recovery details changed
- Unknown forwarding rules appeared
- Messages were sent without your authorization
- Important emails disappeared
- Other accounts were compromised afterward
- Money or cryptocurrency was transferred
- Business communications were intercepted
- Someone impersonated you through your email
- You suspect malware or credential theft
- You need digital evidence preserved
- You need to understand the sequence of events
Early action can matter because security and authentication records may not be retained indefinitely.
How Cyb3rsect Approaches Email Account Compromise Investigations
Cyb3rsect approaches email compromise as a digital investigation rather than simply a password-reset problem.
Depending on the circumstances and available evidence, an investigation may examine authentication history, security notifications, account changes, suspicious messages, devices, forwarding rules, transaction records and connected accounts.
The objective is to reconstruct what happened and determine what the evidence can establish.
Important questions can include:
When did unauthorized activity begin?
How might access have been obtained?
What happened after access was gained?
Were security settings modified?
Were other accounts targeted?
Was financial activity involved?
What evidence remains available?
Where the evidence does not support a definitive conclusion, that limitation should be made clear.
An Email Compromise Shouldn’t Be Treated as Just a Password Problem
Your email account can be connected to dozens of other parts of your digital life.
That is what makes unauthorized email access particularly dangerous.
An attacker who controls a mailbox may be able to observe communications, impersonate the account owner, reset other passwords, intercept financial information or target additional accounts.
Recovering access is important.
Understanding what happened while access was compromised can be equally important.
If you suspect unauthorized access to an email account, preserve relevant login records, security notifications, forwarding rules, suspicious messages and other available evidence as early as possible.
Cyb3rsect provides digital investigation and forensic support for email account compromise, account takeover, unauthorized access and related cyber incidents.