Skip to content
Avanet

Sophos Email: detect and respond to account compromise

An account-compromise alert requires immediate investigation, but isn’t proof that an account has been taken over. Sophos Fusion (formerly Sophos Central) monitors outbound email activity from monitored users and can flag unusual behavior, such as a sudden high sending volume or patterns that differ from normal behavior. If sending continues while the account is flagged, alerts can repeat every 30 minutes.

Quick workflow: acknowledge the alert and assign an incident owner, record the mailbox and time, distinguish legitimate bulk sending from abuse, reset credentials and disable the account when suspicion is substantiated, investigate assigned endpoints, and restore access only after the checks pass. Never bypass a Sophos spam/virus-threshold block with a broad exception.

Prerequisites and ownership

Before configuration or an incident, establish the following:

  • The Business Email Compromise capability is available in the Sophos Fusion account, and relevant users are monitored by Sophos Email.
  • At least two suitable recipients, or a continuously monitored security channel, are approved. A mailbox that could itself be affected shouldn’t be the only route.
  • An incident owner, deputy, and escalation paths to identity, endpoint, and mail administrators are known.
  • The team is authorized to reset passwords and disable accounts at the responsible identity or mail provider. Those actions aren’t performed in the Sophos Email page described here.
  • The organization knows which devices are assigned to mailbox owners and who can initiate and assess an endpoint investigation.

Keep Account Compromise separate from impersonation and VIP protection. It reports suspicious behavior by a monitored sending account; it doesn’t manage VIP lists and doesn’t prove that an inbound message impersonated someone.

Configure notification recipients

  1. In Sophos Fusion, open Global Settings.
  2. Go to Products and Services > Email and select Business Email Compromise.
  3. Open the Account Compromise tab.
  4. In the User list, select the people who must handle alerts.
  5. Move them to Notify users.
  6. Select Save.

Selected people receive email when Sophos flags any monitored account as possibly compromised. The notification contains affected-user details, the alert reason, and recommended steps to secure the account. The recipient list is therefore an on-call distribution list, not the list of mailboxes being monitored.

After saving, have a second person compare the visible Notify users list with the approved distribution list. Confirm that addresses are valid, the destination is monitored, and internal filtering doesn’t discard Sophos Fusion mail. Use an approved channel-delivery test if your operating process supports one. Don’t create suspicious traffic or malware merely to trigger an account-compromise alert; this page doesn’t document a test-alert function.

Triage the alert without jumping to conclusions

Open a case for every initial alert and record at least:

  • affected user or mailbox;
  • receipt time, alert reason, and reported severity;
  • time and extent of unusual outbound sending;
  • known legitimate campaigns, applications, or bulk sends from the account;
  • assigned devices and responsible identity, mail, and endpoint administrators;
  • every repeat alert and its interval.

A repeat every 30 minutes means the user continues sending while flagged. It isn’t a separate independent confirmation or a promise that all activity is reported within that window. Keep the incident open until sending and cause have been checked.

Ask the user about unexpected behavior and suspicious links or files they may have interacted with. Compare the reported period with available outbound-message and provider logs. A planned newsletter may explain unusual volume; unknown recipients, spam, or malware support containment. Use the guide to antispam and outbound threats for threshold, outbound classification, and policy-action details.

Contain the account and endpoint

For plausible or confirmed abuse, proceed in this order:

  1. Stop ongoing sending. If immediate restriction is required, disable the account at the responsible identity or mail provider. Delete it only after ownership, retention, and recovery have been resolved.
  2. Reset the affected account’s password through the responsible identity service. Never retain the old password as a rollback value or reinstate it later.
  3. Investigate unexpected user activity and any links clicked or files opened. Give the endpoint team the findings and relevant time window.
  4. Fully investigate assigned devices. When a mailbox is detected sending outbound malware, Sophos Email can optionally start a full scan on assigned endpoints. Verify that a device was assigned and that a scan actually started and completed; availability isn’t evidence of completion.
  5. Notify relevant internal teams if suspicious messages may have reached recipients. Determine content and scope from available message and provider records, not assumptions.

When Sophos Email detects outbound malware, Sophos Fusion sends a notification and temporarily blocks the mailbox from sending. Block duration varies with the number of detected incidents. This is additional protection, not a substitute for password reset, investigation, or account disablement. No supported manual unblock step is documented here; escalate the specific case if the mailbox remains blocked after investigation.

Validate containment and recovery

Before restoring access, all these checks need a clear result:

  • The user received new credentials through a trusted route, and the old password no longer works.
  • Unusual sending has either been explained as legitimate or investigated and contained as an incident.
  • Every assigned device has an assessed investigation result. A merely started or pending scan isn’t enough.
  • No further suspicious outbound messages or 30-minute repeats occurred after containment. Absence of an alert alone doesn’t prove remediation.
  • A controlled harmless message to an internal and, where operationally required, external test recipient follows the intended mail path. Record time, sender, recipient, and result.
  • The incident owner and responsible identity, mail, and endpoint teams approve restoration.

If the account was disabled, re-enable it at the responsible provider only now. Resume with a small amount of normal mail, not a newsletter or queued bulk send. If another alert appears, stop sending again and treat recovery as failed.

Rollback and escalation

To reverse an incorrect recipient configuration, restore the recorded starting state under Account Compromise: remove unintended entries from Notify users, add approved recipients, and select Save. During an active incident, rollback must never remove the last working alert route.

Don’t roll back containment indiscriminately. An account disabled in error can be re-enabled after documented review and approval; a password reset is never reversed by restoring the old password. Don’t bypass a Sophos temporary sending block through routing changes, allow rules, or disabled outbound inspection.

Escalate when an alert has no reachable owner, the user denies the activity, spam or malware sending continues, the endpoint scan doesn’t start or has no assessable result, or the mailbox remains blocked after remediation. For Sophos Support, collect alert text and timestamps, affected mailbox, incident count, available message identifiers, sending period, device assignment, and scan status. Submit passwords, message bodies, or other sensitive data only through approved support channels.