Home/Services/Account Takeover Recovery
security service

Account Takeover Recovery

Locked out or hijacked? Fast account takeover recovery for Microsoft 365, Google and SaaS: revoke the attacker, find what they touched, and shut them out.

Manual, expert-ledEvidence-based findingsFree remediation retest

Account takeover recovery is about regaining control quickly and, just as important, making sure the attacker is fully out and cannot walk straight back in. If you have lost access to a Microsoft 365 mailbox, an admin console, or a customer account is being used by someone who is not you, the priority is to break the attacker’s session now and work out what they touched before you relax.

Regaining control comes first

When an account is taken over, resetting the password feels like the fix. On its own, it usually is not. A determined attacker will already have a live session token, a second way in through a malicious app grant, or a quietly added backup authentication method. Change only the password and they keep their access while you believe you have closed it.

So the real first move is to kill every active session, force credentials to change, and reset the multi-factor setup, then check for the hidden doors. Done in the right order, this locks the attacker out for good rather than briefly inconveniencing them.

Revoke every active session and refresh token to break the attacker’s access
Reset and re-enrol multi-factor, removing any method the attacker added
Audit OAuth app consents and revoke malicious third-party grants
Remove hidden inbox rules and mail forwarding set up to spy or steal
Forensic review of sign-in and audit logs to see what they reached
Conditional-access and passkey hardening so it does not recur

How account takeover recovery works

We run the response in five phases so nothing is missed in the rush to regain access. Account takeover recovery services that stop at a password reset leave the back doors open, which is why so many victims get retaken within days. Order and thoroughness are what make it stick.

24/7
rapid response, any hour
100%
manual log review, not a scanner dump
Free
hardening review after recovery

Triage

We confirm which accounts are affected, whether the compromise is limited to one user or has spread across the tenant, and whether an admin account is involved. An attacker who reaches an administrator is a different problem from one stuck in a single mailbox, and triage tells us which we are facing.

Contain

We break the attacker’s access immediately: revoke active sessions and tokens, force a password change, and disable the account if needed. Where the compromise is spreading, we move fast to protect the accounts not yet hit. Containment here is the moment control shifts back to you.

Eradicate

Then we remove everything the attacker planted to keep their access: extra authentication methods, malicious OAuth grants, rogue inbox rules, and any new accounts they created. This is the step self-led recoveries usually miss, and it is exactly the step that decides whether the takeover is truly over.

Recover

With the account secured, we restore it to a trustworthy state, re-enrol legitimate authentication, and check that no data or configuration was left tampered with. Where mailboxes or files were altered, we help you understand and repair the damage.

Harden

Finally we close the weakness that allowed the takeover and strengthen the obvious neighbours, so the same method fails next time. For most tenants that means better conditional access, phishing-resistant authentication, and tighter control over app consents.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

How they got in, even with MFA

The painful question after a takeover is usually “but I had multi-factor authentication”. You probably did, and it probably was bypassed by one of a handful of well-worn techniques. Understanding which one matters, because it decides how you stop a repeat.

Stolen session cookies

Information-stealer malware on a device grabs the browser cookies that represent an already-authenticated session. With that token, an attacker is logged in without ever needing your password or your second factor. This is one of the most common routes we see, and it is why revoking sessions, not just changing passwords, is central to recovery.

Adversary-in-the-middle phishing

Toolkits of the Evilginx type sit between you and the real login page, relaying your password and your one-time code in real time and capturing the resulting session. Basic MFA, especially codes and push prompts, does not stop this. Phishing-resistant methods like passkeys and FIDO2 hardware keys do, which is why we push you toward them in hardening.

Credential stuffing and reuse

If a password was reused from a site that was breached, attackers simply try it against your accounts at scale. When it works and MFA is weak or absent, they are in. This is dull and extremely effective, and it is why password reuse remains one of the biggest practical risks to any organisation.

Malicious app consent

Sometimes the attacker never steals the password at all. They trick a user into approving an OAuth application that grants ongoing access to mail and files. The consent persists even after a password change, which is why an app-consent audit is a non-negotiable part of the cleanup.

Reading the sign-in and audit logs

Across all of these, the truth is in the logs. In Microsoft environments we work through the Entra sign-in and audit logs and the Unified Audit Log to see where the attacker connected from, what they accessed, and what they changed. Those records tell you the real scope, and they are the evidence you will need if the incident becomes reportable.

Recovering Microsoft 365 and Entra accounts

A large share of the takeovers we handle involve Microsoft 365 and Entra ID, so it is worth being specific. Microsoft account takeover recovery has its own checklist, because attackers abuse the platform’s own features to persist.

The Microsoft-specific cleanup

Beyond revoking sessions and resetting credentials, we hunt for the tricks attackers use inside a tenant: inbox rules that auto-delete or forward mail to hide their activity, mailbox delegation quietly added, enterprise app registrations granting standing access, and new global admin accounts. Each is a way back in that survives a password reset, and each has to be found and removed.

Checking what left the mailbox

We use message trace and the audit logs to understand whether mail was read, exported or forwarded, and whether the attacker used the mailbox to launch further attacks on your contacts. A hijacked mailbox is often the launchpad for invoice fraud against your suppliers, so this scoping protects more than just you.

GDPR and your notification duties

An account takeover is not only an access problem. If the attacker reached personal data, whether staff records in a mailbox or a store of customer accounts, you may have a reportable breach on your hands.

When a takeover is a notifiable breach

Under Article 33 of the GDPR, if a compromise is likely to result in a risk to people’s rights, you must notify your supervisory authority within 72 hours of becoming aware. An attacker sitting in a mailbox full of personal data, or inside a system holding customer records, can meet that threshold. Our scoping of exactly what was accessed gives your legal counsel the facts they need to make the call.

Customer account takeovers

Where your customers’ accounts were taken over, the people affected are your users, and Article 34 may require you to inform them directly without undue delay. We help you understand the scale of the compromise so those notifications are accurate rather than alarmist or evasive.

Preserving the evidence

Sign-in and audit logs age out, sometimes within weeks. Preserving them early is part of both a clean investigation and a defensible position with your regulator, so we capture what matters before it rolls off.

Pricing

Account takeover recovery cost depends on scope: a single hijacked mailbox is a contained job, while a tenant-wide compromise with multiple accounts and an admin involved is a larger investigation. Here is the shape of a typical European engagement.

Package What’s included Response time Price
Rapid response Lock out the attacker on a single account, reset credentials and MFA, remove inbox rules and app grants, and confirm what was accessed Same day, 24/7 from €900
Tenant-wide recovery Multiple compromised accounts or an admin breach: full session revocation, app-consent audit, log forensics across the tenant, and cleanup Immediate start; by scope from €180/hr
Asset cleanup Cleaning a specific compromised system or connected service tied to the takeover, with the entry point closed Days by scope from €450
IR retainer Pre-agreed SLA, faster engagement, a discounted hourly rate, and a team that already knows your identity setup Fastest, pre-onboarded from €800/month
Custom / large estate Complex tenant, many accounts, or federated identity across multiple platforms, scoped after a call On scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a hardening review included. Start emergency response

FAQ

How did they get into my account if I had MFA?
Usually by stealing a live session cookie with info-stealer malware, by using an adversary-in-the-middle phishing kit that relays your code in real time, or by getting you to approve a malicious app that keeps access without your password. Basic MFA does not stop all of these. That is why recovery revokes sessions and audits app consents, and why we steer you toward passkeys.
How do I know what the attacker accessed?
Through the logs. In Microsoft environments we work through the Entra sign-in and audit logs, the Unified Audit Log and message trace to see where the attacker connected from, what mail or files they touched, and whether they forwarded or exported anything. That gives you an evidence-based scope rather than a guess, which matters for both cleanup and any GDPR notification.
How much does account takeover recovery cost?
Locking out and cleaning a single account starts from €900, and a tenant-wide investigation is scoped by depth, typically from €180 per hour of specialist work. You get a fixed price after a free scoping call. Retainer clients pay a discounted rate and get faster engagement because we already know their identity setup.
Can you recover a compromised Microsoft 365 or Entra account?
Yes, this is a large part of what we do. Microsoft account takeover recovery means more than a password reset: we revoke sessions, reset MFA, remove malicious inbox rules and mailbox delegation, audit enterprise app grants, and check for rogue admin accounts. Those platform-specific back doors are exactly what a password change leaves untouched.
Do I need to report this under GDPR?
Possibly. If the attacker reached personal data and there is a risk to the people it concerns, Article 33 requires notifying your supervisory authority within 72 hours of awareness, and customer-account takeovers may trigger Article 34 notice to those users. We scope exactly what was accessed so your legal counsel can decide on facts, not assumptions.
How do you stop it happening again?
By closing the specific route used and hardening the identity platform: phishing-resistant authentication like passkeys or FIDO2 keys, conditional-access policies that limit where and how sign-ins are allowed, tighter control over app consents, and, where info-stealers were involved, cleaning the affected device. Every recovery ends with a hardening review aimed at exactly that.
How fast can you lock them out?
Our rapid-response line runs 24/7 and we can revoke sessions and secure a compromised account the same day, often within the hour. Speed matters because an active attacker in a mailbox may be sending fraudulent mail or exfiltrating data right now. Retainer clients get the fastest engagement.
The attacker sent emails from my account. What now?
We check exactly what was sent and to whom, so you can warn affected contacts, and we look for the inbox rules attackers use to hide their tracks and to run invoice fraud against your suppliers. A hijacked mailbox is often a launchpad for further attacks, so scoping the outbound activity protects your customers and partners as well as you.

Related services

Who needs this

Businesses and teams across Europe facing a hijacked account: a locked-out Microsoft 365 or Google mailbox, an admin console in someone else’s hands, customer accounts being taken over at scale, or emails going out that you never sent. If an attacker is active in your account now, contact our 24/7 rapid-response line.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Account Takeover Recovery"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.