Account Takeover Recovery
Locked out or hijacked? Fast account takeover recovery for Microsoft 365, Google and SaaS: revoke the attacker, find what they touched, and shut them out.
Account takeover recovery is about regaining control quickly and, just as important, making sure the attacker is fully out and cannot walk straight back in. If you have lost access to a Microsoft 365 mailbox, an admin console, or a customer account is being used by someone who is not you, the priority is to break the attacker’s session now and work out what they touched before you relax.
Regaining control comes first
When an account is taken over, resetting the password feels like the fix. On its own, it usually is not. A determined attacker will already have a live session token, a second way in through a malicious app grant, or a quietly added backup authentication method. Change only the password and they keep their access while you believe you have closed it.
So the real first move is to kill every active session, force credentials to change, and reset the multi-factor setup, then check for the hidden doors. Done in the right order, this locks the attacker out for good rather than briefly inconveniencing them.
How account takeover recovery works
We run the response in five phases so nothing is missed in the rush to regain access. Account takeover recovery services that stop at a password reset leave the back doors open, which is why so many victims get retaken within days. Order and thoroughness are what make it stick.
Triage
We confirm which accounts are affected, whether the compromise is limited to one user or has spread across the tenant, and whether an admin account is involved. An attacker who reaches an administrator is a different problem from one stuck in a single mailbox, and triage tells us which we are facing.
Contain
We break the attacker’s access immediately: revoke active sessions and tokens, force a password change, and disable the account if needed. Where the compromise is spreading, we move fast to protect the accounts not yet hit. Containment here is the moment control shifts back to you.
Eradicate
Then we remove everything the attacker planted to keep their access: extra authentication methods, malicious OAuth grants, rogue inbox rules, and any new accounts they created. This is the step self-led recoveries usually miss, and it is exactly the step that decides whether the takeover is truly over.
Recover
With the account secured, we restore it to a trustworthy state, re-enrol legitimate authentication, and check that no data or configuration was left tampered with. Where mailboxes or files were altered, we help you understand and repair the damage.
Harden
Finally we close the weakness that allowed the takeover and strengthen the obvious neighbours, so the same method fails next time. For most tenants that means better conditional access, phishing-resistant authentication, and tighter control over app consents.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
How they got in, even with MFA
The painful question after a takeover is usually “but I had multi-factor authentication”. You probably did, and it probably was bypassed by one of a handful of well-worn techniques. Understanding which one matters, because it decides how you stop a repeat.
Stolen session cookies
Information-stealer malware on a device grabs the browser cookies that represent an already-authenticated session. With that token, an attacker is logged in without ever needing your password or your second factor. This is one of the most common routes we see, and it is why revoking sessions, not just changing passwords, is central to recovery.
Adversary-in-the-middle phishing
Toolkits of the Evilginx type sit between you and the real login page, relaying your password and your one-time code in real time and capturing the resulting session. Basic MFA, especially codes and push prompts, does not stop this. Phishing-resistant methods like passkeys and FIDO2 hardware keys do, which is why we push you toward them in hardening.
Credential stuffing and reuse
If a password was reused from a site that was breached, attackers simply try it against your accounts at scale. When it works and MFA is weak or absent, they are in. This is dull and extremely effective, and it is why password reuse remains one of the biggest practical risks to any organisation.
Malicious app consent
Sometimes the attacker never steals the password at all. They trick a user into approving an OAuth application that grants ongoing access to mail and files. The consent persists even after a password change, which is why an app-consent audit is a non-negotiable part of the cleanup.
Reading the sign-in and audit logs
Across all of these, the truth is in the logs. In Microsoft environments we work through the Entra sign-in and audit logs and the Unified Audit Log to see where the attacker connected from, what they accessed, and what they changed. Those records tell you the real scope, and they are the evidence you will need if the incident becomes reportable.
Recovering Microsoft 365 and Entra accounts
A large share of the takeovers we handle involve Microsoft 365 and Entra ID, so it is worth being specific. Microsoft account takeover recovery has its own checklist, because attackers abuse the platform’s own features to persist.
The Microsoft-specific cleanup
Beyond revoking sessions and resetting credentials, we hunt for the tricks attackers use inside a tenant: inbox rules that auto-delete or forward mail to hide their activity, mailbox delegation quietly added, enterprise app registrations granting standing access, and new global admin accounts. Each is a way back in that survives a password reset, and each has to be found and removed.
Checking what left the mailbox
We use message trace and the audit logs to understand whether mail was read, exported or forwarded, and whether the attacker used the mailbox to launch further attacks on your contacts. A hijacked mailbox is often the launchpad for invoice fraud against your suppliers, so this scoping protects more than just you.
GDPR and your notification duties
An account takeover is not only an access problem. If the attacker reached personal data, whether staff records in a mailbox or a store of customer accounts, you may have a reportable breach on your hands.
When a takeover is a notifiable breach
Under Article 33 of the GDPR, if a compromise is likely to result in a risk to people’s rights, you must notify your supervisory authority within 72 hours of becoming aware. An attacker sitting in a mailbox full of personal data, or inside a system holding customer records, can meet that threshold. Our scoping of exactly what was accessed gives your legal counsel the facts they need to make the call.
Customer account takeovers
Where your customers’ accounts were taken over, the people affected are your users, and Article 34 may require you to inform them directly without undue delay. We help you understand the scale of the compromise so those notifications are accurate rather than alarmist or evasive.
Preserving the evidence
Sign-in and audit logs age out, sometimes within weeks. Preserving them early is part of both a clean investigation and a defensible position with your regulator, so we capture what matters before it rolls off.
Pricing
Account takeover recovery cost depends on scope: a single hijacked mailbox is a contained job, while a tenant-wide compromise with multiple accounts and an admin involved is a larger investigation. Here is the shape of a typical European engagement.
| Package | What’s included | Response time | Price |
|---|---|---|---|
| Rapid response | Lock out the attacker on a single account, reset credentials and MFA, remove inbox rules and app grants, and confirm what was accessed | Same day, 24/7 | from €900 |
| Tenant-wide recovery | Multiple compromised accounts or an admin breach: full session revocation, app-consent audit, log forensics across the tenant, and cleanup | Immediate start; by scope | from €180/hr |
| Asset cleanup | Cleaning a specific compromised system or connected service tied to the takeover, with the entry point closed | Days by scope | from €450 |
| IR retainer | Pre-agreed SLA, faster engagement, a discounted hourly rate, and a team that already knows your identity setup | Fastest, pre-onboarded | from €800/month |
| Custom / large estate | Complex tenant, many accounts, or federated identity across multiple platforms, scoped after a call | On scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a hardening review included. Start emergency response
FAQ
How did they get into my account if I had MFA?
How do I know what the attacker accessed?
How much does account takeover recovery cost?
Can you recover a compromised Microsoft 365 or Entra account?
Do I need to report this under GDPR?
How do you stop it happening again?
How fast can you lock them out?
The attacker sent emails from my account. What now?
Related services
Businesses and teams across Europe facing a hijacked account: a locked-out Microsoft 365 or Google mailbox, an admin console in someone else’s hands, customer accounts being taken over at scale, or emails going out that you never sent. If an attacker is active in your account now, contact our 24/7 rapid-response line.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.