Strange sent emails, a password that stopped working, MFA prompts you didn’t trigger, or a ransom note on screen. Whatever the sign, the order you respond in matters more than speed. Do this, in this order.
The first 30 minutes
- Disconnect, don’t power off. Pull the network cable or turn off Wi-Fi on the affected machine. Leave it running – powering off can destroy the evidence we need to work out what happened.
- Tell us immediately. Message the helpdesk on WhatsApp (24/7) or raise a ticket from a different device. The earlier we’re in, the more we can contain.
- Change passwords from a clean device – a phone on mobile data is ideal, never the suspect machine. Email first (it resets everything else), then banking, then anything sharing that password.
- Check your email rules. Attackers add forwarding rules so they keep reading your mail after you change the password. In Outlook: Settings > Mail > Rules and Forwarding – delete anything you didn’t create.
- Turn on MFA on anything that doesn’t have it yet – see Adding MFA to your account.
What we do from there
We isolate the machine, audit sign-in history and OAuth grants, check what the attacker touched, clean or rebuild, and write up what happened and what changed so it can’t repeat. If it’s ransomware: don’t pay and don’t negotiate – we’ve recovered clients from ransomware without paying a penny, and tested backups beat ransoms every time.
One more thing: don’t feel embarrassed. The people who get hurt worst are the ones who wait two days hoping it goes away. Tell us early and it’s usually a bad afternoon, not a bad month.