Something is wrong. Maybe you clicked a link and immediately regretted it. Maybe your computer started acting strange. Maybe a client called to ask about an email you never sent. Whatever tipped you off, you’re now wondering if you’ve been hacked and what you’re supposed to do about it.
Here’s what to do.
Step One: Stop Using That Device#
If you think a specific computer or phone was compromised, stop using it. Don’t log into anything else from it. Disconnect it from your wifi or unplug the ethernet cable. If you have other devices on the same network, be aware they could be affected too.
One thing people don’t think about: laptop and desktop webcams can be accessed remotely by an attacker, and the indicator light isn’t always a reliable sign that the camera is off. Until the device is cleared, treat it like someone might be watching and listening through it. Cover the camera, and don’t have sensitive conversations near it.
The instinct is to keep working and figure it out later. That instinct is going to make this worse. The longer a compromised device stays connected, the more access an attacker has and the more damage they can do.
Step Two: Look for Warning Signs, Then Decide What to Do Next#
Before you start changing passwords, take a quick look at the obvious symptoms: emails in your sent folder you didn’t write, password reset messages you didn’t request, accounts you can no longer log into, files you can’t open, or any message demanding payment.
If you’re seeing any of those things, your first move is to search for exactly what you’re seeing. Copy the text of any ransom message or error word for word and search it. Look up the specific behavior your computer is exhibiting. There’s a good chance someone else has encountered the same thing and documented what it is and what to do. This costs you nothing and can tell you a lot about how serious your situation actually is.
If the search results point to something significant (active malware, ransomware, a known credential breach), call a security professional. And honestly, if you’re not sure what you’re looking at, that’s reason enough to call one. A false alarm costs you an hour. A missed real incident can cost you a lot more.
If you’re not seeing any warning signs and nothing looks obviously wrong, you may have gotten lucky. Move on to Step Three.
Step Three: Change Your Passwords, From a Different Device#
Use your phone, a different computer, anything that wasn’t connected to what you’re worried about. Change the passwords for:
- Your business email
- Any financial accounts (bank, payment processors, bookkeeping software)
- Anything you were logged into recently on the affected device
If you don’t have a password manager yet, this is the moment you will wish you did. You’re going to be changing a lot of passwords and you will want somewhere safe to put the new ones.
Turn on two-factor authentication on your email if it isn’t already on. Email is the master key to everything else. Whoever controls your inbox can reset almost any other password you have.
On email specifically: after you change the password, check your forwarding rules and recovery address. Attackers who get into an email account often add a forwarding rule or swap the recovery contact so they keep access even after a password reset. If anything looks unfamiliar, remove it.
For every account you’ve secured (email, financial tools, cloud storage, anything), go into the security settings and revoke access for all authorized devices and active sessions. Every one of them, even the ones you think you recognize. Then log back in only from devices you are certain are yours and are not the compromised machine. This is the step most people skip, and it’s how an attacker stays in an account after the password has been changed.
Step Four: Consider Who Needs to Know#
If you have client data, payment information, or anything that belongs to other people stored in your business systems, a breach may come with legal notification requirements. This varies by state and by what kind of data is involved, but ignoring it is not a defense. It’s worth a quick conversation with an attorney if you’re not sure.
Beyond legal requirements, you may also want to give a heads up to your bank, your accountant, or any vendors who have financial access to your accounts.
The Thing Most People Get Wrong#
The most damaging thing in small business incidents isn’t the initial compromise. It’s the delay. People wait days before telling anyone, keep using the affected device because they need it, and hope the problem goes away. It doesn’t go away. It gets more expensive.
If you’re not sure what you’re dealing with, the right call is to get someone on the phone who does this for a living. Not next week. Today.
That’s what I’m here for. If you think something happened and you’re not sure what to do next, get in touch and we’ll figure it out together.