What should I do if a cloud account may be compromised?¶
If a cloud account may be compromised, preserve evidence, assess ongoing harm and coordinate containment without destroying the records needed to understand what happened.
Evidential caution: that the first step is always to reset the password immediately.
What this means¶
A password reset may be necessary, but it can also revoke sessions, alter logs, trigger attacker behaviour or remove access needed to preserve evidence.
Where the account is actively causing harm, containment may need to proceed immediately.
Coordinate with the organisation, provider or specialist so that preservation and containment happen in the correct order where operationally possible.
Stolen sessions, refresh tokens, application passwords, API keys and delegated applications may remain active.
Document every action taken, who authorised it, the time and the effect observed.
Where immediate safeguarding or operational harm requires urgent action, record why containment took priority and what evidence could not be preserved first. A justified emergency response should still leave a clear audit trail.
What to check or do next¶
- Start by identifying the account, tenant, service, suspected time range and signs of compromise.
- Preserve recent login, session, token, application-consent, recovery, trusted-device, administrator and audit records.
- Record the current account state, including active sessions, forwarding rules, delegated access, connected applications and recovery settings.
- Check for persistence, such as new administrators, mailbox rules, file-sharing changes, recovery-method changes and trusted devices.
Evidential limits¶
Do not assume that changing the password ends every access route.
Operational takeaway
Treat suspected cloud compromise as both an evidential and containment problem, preserving sessions, tokens and configuration before or alongside proportionate action to secure the account.