guides

We've been hacked: what to do in the first hour

The short answer: Stop it spreading, keep the evidence, change passwords from a clean device, write down what you have seen, and get help. Don't wipe or reinstall anything yet, and don't pay anyone before you have taken advice.

Finding out you've been hacked is horrible. Your stomach drops, and the urge is to do something, anything, straight away. That urge is right, but what you do in the first hour matters. Done well, it limits the damage and keeps the evidence that shows how they got in. Done in a panic, it can wipe that evidence or let the attacker back in.

Here is what to do, in order.

The first five steps

  1. Disconnect or lock it down

    Unplug affected computers from the network or turn off their Wi-Fi, but leave them switched on if you can: what is in memory can show what happened. For accounts such as email or your website admin, lock or suspend them.

  2. Don't delete anything

    Don't wipe, reinstall or tidy up yet. Logs, emails and strange files are the evidence of how they got in and what they touched.

  3. Change passwords from a clean device

    Use a phone or computer you trust that hasn't been affected. Start with email, then admin and banking accounts. Turn on two-step login (a code from your phone as well as a password) wherever you can.

  4. Write down what you've seen, and when

    What you noticed, what time, and anything you've done since. Screenshots help. Times matter more than you would think.

  5. Call me

    Call or WhatsApp me on 07736 637990. If you have cyber insurance, call their helpline too: some policies need you to tell them first.

What not to do

  • Don't wipe or reinstall anything yet. It feels like the fastest fix, but it destroys the evidence of how they got in. If you don't know how they got in, they can come straight back.
  • Don't change passwords from the affected computer. If it has malware on it (harmful software), the new passwords can be captured as you type them.
  • Don't email about it from an account that might be compromised. The attacker may be reading it. Use a phone call or a different account.
  • Don't pay a ransom or an "unlock" fee before taking advice. Paying doesn't guarantee you get your data back, and it marks you as someone who pays.
  • Don't keep it to yourself. The sooner the right people know, the more options you have.

How to tell what has been affected

You don't need to know everything in the first hour, but a rough picture helps whoever is helping you. Ask:

  • Which accounts or systems look wrong? Email, website, server, banking, a particular laptop.
  • What did you notice first, and when? Strange emails sent from your account, a defaced website, files you can't open, logins from places you don't recognise.
  • Is personal data involved? Customer names, email addresses, payment details or staff records. This decides whether you need to tell the ICO.

The signs I see most often:

  • Users or keys you didn't add. A new admin account on the website, an unknown user on the server, or an SSH key (a file that lets someone log in without a password) nobody recognises.
  • Odd files in the website's folders. PHP files hidden in an uploads or cache folder, often with recent dates. These are usually "web shells", which give the attacker a back door.
  • The server is slow and the bill is up. Someone is running a cryptocurrency miner on it, using all the processing power.
  • Your server is sending spam. Bounce messages for emails you never sent, or your server's address appearing on email blocklists.
  • An email from a "security researcher". Usually they've run an automated scan and want paying for a list of minor issues. It's rarely proof of a hack, but don't reply in a hurry, and get someone to check what they found.

Who you need to tell

  • Your insurer, if you have cyber insurance. Many policies come with an incident helpline, and some need you to call them before anything else.
  • The ICO, if personal data was involved and it could put people at risk. You have 72 hours from finding out, weekends included. See do I need to report a data breach to the ICO?
  • The police. In England, Wales and Northern Ireland, report cyber crime to Report Fraud (it used to be called Action Fraud), online or on 0300 123 2040. In Scotland, call Police Scotland on 101.
  • Your bank, straight away, if payment details or banking logins may have been taken.
  • Your customers, if their data was involved and the risk to them is high. It is worth getting advice on the wording first.

When to call someone

Call for help if any of these are true:

  • You don't know how they got in.
  • A server, website or shared system is involved, not just one person's laptop.
  • Personal data might have been taken.
  • Files have been encrypted and you are being asked for money.
  • You are not sure the attacker has gone.

That covers most hacks. Getting an experienced person involved in the first hour usually means less damage, a faster clean-up and a clearer answer for the ICO, your insurer and your customers.

Sources

emergency

Need help right now?

Help when you've been hacked: contain it, find out what happened, clean up and write it up.