Act Quickly — and in the Right Order
Token-based attacks are different from password theft in one critical way: changing a password does not automatically revoke existing tokens or app consent. An attacker can continue to access a mailbox for days or weeks after a password reset if the token is not explicitly revoked.
Revoke all sessions for the affected account
Microsoft 365: Microsoft Entra admin center → Users → select the user → Revoke sessions. This invalidates all existing tokens immediately.
Google Workspace: Google Admin console → Users → select the user → Reset sign-in cookies (under More options).
This is the most important action. Do it before anything else.
Revoke any malicious app consent
Microsoft 365: Microsoft Entra admin center → Applications → Enterprise applications. Find the suspicious app and delete it, or revoke its permissions from the affected user's account.
Google Workspace: Google Admin console → Security → API controls → Manage Third-Party App Access. Find the app and remove access.
If you cannot identify the app yet, proceed to audit steps below and return to this.
Reset the affected user's password
Microsoft 365: Microsoft Entra admin center → Users → Reset password. Choose a strong temporary password and require the user to change it on next sign-in.
Google Workspace: Google Admin console → Users → Reset password.
Once immediate access is revoked, investigate what the attacker did while they had access. Check these areas in order:
Password reset alone is NOT enough when:
- The attacker used device code phishing (they have a token, not a password)
- The attacker authorized an OAuth app (the token belongs to the app, not the user session)
- You have not yet revoked sessions and app consent
Password reset IS sufficient when:
- The attacker only had the password (traditional phishing, no token)
- Sessions have already been revoked
- No app consent was granted
Church leadership
Immediately after confirming a compromise. Leadership needs to know so they can be alert to follow-up social engineering (e.g., an attacker impersonating the compromised account to request wire transfers).
Staff and volunteers
As soon as possible. Warn them that emails appearing to come from the compromised account during the incident window may not be genuine. Tell them not to click links or take financial action based on those messages.
Donors and members
If you determine their contact information or giving history was exported during the compromise, notify them promptly. Be transparent about what happened and what you are doing to fix it.
Your state attorney general
Many US states require notification if personal information (names + financial or contact data) was exposed in a breach. Check your state's data breach notification law.
Law enforcement
If financial loss occurred or if you want the attack on record for insurance purposes, file a report with the FTC (reportfraud.ftc.gov) and your local FBI field office (ic3.gov).
Need more help?
Our emergency response guide covers broader cyberattack scenarios including ransomware, account lockout, and when to call in outside help.
Go to Emergency Response Guide