The primary mailbox can reset WordPress, hosting, DNS and payment accounts. If an attacker controls it, every website password change is temporary and normal security notifications may be hidden by forwarding or deletion rules.
Secure the mailbox through the provider’s trusted recovery process before restoring dependent accounts.
Confirm mailbox compromise
Review provider security events, active sessions, app passwords, recovery addresses, MFA methods and forwarding rules. Record unknown identifiers and times before revocation.
Do not rely on the mailbox itself to approve its recovery. Use the provider’s identity-verification route and a clean device.
Avoid sharing message contents or recovery codes in the incident ticket.
Contain email access
Reset the mailbox password, revoke all sessions/app passwords, remove unknown recovery methods and enable phishing-resistant MFA where available.
Check delegated access, shared mailbox members, inbox rules, POP/IMAP clients and OAuth applications. An attacker can retain access without another normal login.
Record each removal and test legitimate mail clients afterward.
Preserve security notifications
Search deleted items, rules and provider logs for WordPress, hosting, registrar, Cloudflare and payment reset messages. Save message IDs/timestamps without forwarding active reset links.
Determine which connected accounts were reset and when. Do not click old links from the compromised mailbox.
Keep a timeline of changes across systems.
Establish an independent recovery channel
Use a second verified organisational contact or provider account that the compromised mailbox cannot reset. Record who controls it and remove temporary recovery delegates after the incident.
Do not forward new credentials to the old mailbox while its devices, OAuth apps and rules are still under review. Communicate changes through the incident lead.
If the domain’s entire email service is affected, coordinate DNS/MX changes carefully rather than improvising a consumer mailbox.
Restore WordPress ownership
After email is trusted, use normal reset or managed hosting/WP-CLI/database recovery for one verified administrator. Restore account email, set a unique password, enable MFA and revoke sessions/application passwords.
Do not create a hidden permanent administrator. Preserve unknown users and their metadata before removal.
Check pending admin-email change records.
Recover hosting and DNS
Rotate cPanel/Plesk, SFTP/SSH, registrar and CDN credentials; revoke unknown users/API tokens and verify billing/owner contacts.
Compare DNS and redirect rules with known-good records. If hosting access was reset through email, inspect all sites, databases, mail queues and cron.
Use individual managed accounts rather than a shared master password.
Review payment and business services
Check WooCommerce payment-provider users, payout/bank settings, API keys, webhooks, analytics/tag manager and backup storage. Follow provider-specific incident processes.
Do not assume WordPress was the only target. Email access may expose invoices, customer messages and password-reset history.
Escalate possible data exposure through the organisation’s authorised process.
Check devices and credential reuse
Follow the organisation’s authorised device-security process for computers and phones that accessed the mailbox. Resetting cloud sessions will not help if a device continues stealing new credentials.
Check whether the same password was used for WordPress, hosting or other mailboxes and rotate each to a unique value. Do not demand personal-device access without policy and consent.
Prevent recovery loops
Use dedicated organisational owner addresses, unique passwords and MFA. Separate everyday mail from high-value recovery accounts where operational policy supports it.
Set alerts to an independent channel for recovery-method, forwarding and privileged-account changes. Review third-party OAuth access regularly.
Do not send the only incident alert through the mailbox being monitored.
Verify sustained control
Test mailbox login, WordPress password reset, hosting/DNS access and business email from clean sessions. Confirm unknown rules/sessions do not return.
Monitor privileged changes and reset messages after reopening. Remove temporary recovery identities and record new owners without storing secrets.
Request emergency multi-account recovery when email repeatedly reverses website changes. Share provider event IDs and redacted timelines—never MFA codes, reset links, passwords or mailbox exports.