If It Already Happened

Act Quickly — and in the Right Order

Token-based attacks are different from password theft in one critical way: changing a password does not automatically revoke existing tokens or app consent. An attacker can continue to access a mailbox for days or weeks after a password reset if the token is not explicitly revoked.

Immediate Steps — Do These First
1

Revoke all sessions for the affected account

Microsoft 365: Microsoft Entra admin center → Users → select the user → Revoke sessions. This invalidates all existing tokens immediately.

Google Workspace: Google Admin console → Users → select the user → Reset sign-in cookies (under More options).

This is the most important action. Do it before anything else.

2

Revoke any malicious app consent

Microsoft 365: Microsoft Entra admin center → Applications → Enterprise applications. Find the suspicious app and delete it, or revoke its permissions from the affected user's account.

Google Workspace: Google Admin console → Security → API controls → Manage Third-Party App Access. Find the app and remove access.

If you cannot identify the app yet, proceed to audit steps below and return to this.

3

Reset the affected user's password

Microsoft 365: Microsoft Entra admin center → Users → Reset password. Choose a strong temporary password and require the user to change it on next sign-in.

Google Workspace: Google Admin console → Users → Reset password.

Audit — Find Out What the Attacker Accessed

Once immediate access is revoked, investigate what the attacker did while they had access. Check these areas in order:

When Is a Password Reset Enough?

Password reset alone is NOT enough when:

  • The attacker used device code phishing (they have a token, not a password)
  • The attacker authorized an OAuth app (the token belongs to the app, not the user session)
  • You have not yet revoked sessions and app consent

Password reset IS sufficient when:

  • The attacker only had the password (traditional phishing, no token)
  • Sessions have already been revoked
  • No app consent was granted
Who to Notify

Church leadership

Immediately after confirming a compromise. Leadership needs to know so they can be alert to follow-up social engineering (e.g., an attacker impersonating the compromised account to request wire transfers).

Staff and volunteers

As soon as possible. Warn them that emails appearing to come from the compromised account during the incident window may not be genuine. Tell them not to click links or take financial action based on those messages.

Donors and members

If you determine their contact information or giving history was exported during the compromise, notify them promptly. Be transparent about what happened and what you are doing to fix it.

Your state attorney general

Many US states require notification if personal information (names + financial or contact data) was exposed in a breach. Check your state's data breach notification law.

Law enforcement

If financial loss occurred or if you want the attack on record for insurance purposes, file a report with the FTC (reportfraud.ftc.gov) and your local FBI field office (ic3.gov).

Need more help?

Our emergency response guide covers broader cyberattack scenarios including ransomware, account lockout, and when to call in outside help.

Go to Emergency Response Guide