| Reset & Revoke |
Reset the password AND revoke all active sessions and refresh tokens. A reset alone does not kick the attacker out. |
Attackers persist through stolen session tokens long after a password change. |
| Kill Mailbox Rules |
Review and disable inbox rules: forwarding, auto-delete, and "move to RSS Feeds" style hiding rules. |
Rules silently divert the victim's mail so the fraud stays invisible. |
| Re-enroll MFA |
Remove registered MFA methods the attacker may have added, then re-enroll the legitimate user. |
Attacker-registered authenticators survive password resets. |
| Review OAuth Grants |
Check for newly consented applications on the account and revoke anything unrecognized. |
Malicious app consents give persistent mailbox access with no login required. |
| Block Known Bad |
Block sender domains, lookalike domains, and indicators from the phish that started it. |
The same lure is usually running against the rest of your organization. |