Knowledge base

Think you have been hacked? Do this first

Isolate, reset, and report, in the right order.

Strange sent emails, a password that stopped working, MFA prompts you didn’t trigger, or a ransom note on screen. Whatever the sign, the order you respond in matters more than speed. Do this, in this order.

The first 30 minutes

  1. Disconnect, don’t power off. Pull the network cable or turn off Wi-Fi on the affected machine. Leave it running – powering off can destroy the evidence we need to work out what happened.
  2. Tell us immediately. Message the helpdesk on WhatsApp (24/7) or raise a ticket from a different device. The earlier we’re in, the more we can contain.
  3. Change passwords from a clean device – a phone on mobile data is ideal, never the suspect machine. Email first (it resets everything else), then banking, then anything sharing that password.
  4. Check your email rules. Attackers add forwarding rules so they keep reading your mail after you change the password. In Outlook: Settings > Mail > Rules and Forwarding – delete anything you didn’t create.
  5. Turn on MFA on anything that doesn’t have it yet – see Adding MFA to your account.

What we do from there

We isolate the machine, audit sign-in history and OAuth grants, check what the attacker touched, clean or rebuild, and write up what happened and what changed so it can’t repeat. If it’s ransomware: don’t pay and don’t negotiate – we’ve recovered clients from ransomware without paying a penny, and tested backups beat ransoms every time.

One more thing: don’t feel embarrassed. The people who get hurt worst are the ones who wait two days hoping it goes away. Tell us early and it’s usually a bad afternoon, not a bad month.

Was this helpful?
Still stuck? Log a ticket Browse more guides

Still stuck?

Raise a ticket and we’ll pick it up. Clear updates until it’s resolved.