I Have Been Hacked: What Do I Do? 10 Urgent Steps
I Have Been Hacked: What Do I Do? 10 Urgent Steps
I have been hacked—what do I do? If you have approved an unexpected MFA request, entered your Microsoft 365 details into a fake website, discovered emails being sent in your name, or found a ransomware note on your corporate network, act immediately. The first few minutes can determine whether the incident remains limited to one account or spreads across your business.
Do not panic, but do not keep using the affected account or device as normal. Disconnect affected systems, contact your IT or cyber security provider through a trusted method, reset compromised credentials from a known-clean device, revoke active sessions, preserve evidence and begin a structured investigation.
I Have Been Hacked: What Do I Do First?
1. Stop and disconnect the affected device
If a computer is displaying a ransomware note, files are rapidly changing, or you suspect malware is active, disconnect its network cable and turn off Wi-Fi and Bluetooth. Disconnect it from any VPN as well. This can help stop malware, encryption or unauthorised access from spreading to servers, shared drives, backups and other devices.
For a corporate incident, do not reconnect the device to “see if it is fixed”. If you cannot quickly isolate an actively encrypting device from the network, record the visible details and power it down. Your incident response team may give different instructions when preserving live forensic evidence is important, so obtain professional advice as soon as possible.
2. Contact IT support through a trusted channel
Do not reply to the suspicious email, call a telephone number in the ransom note, or use contact details supplied by the suspected attacker. Contact your internal IT team, managed service provider, cyber insurer or incident response provider using a number you already know or have independently verified.
If you need urgent technical assistance, contact a trusted provider offering business IT support and helpdesk services. For a broader security review, containment plan or recovery strategy, speak with experienced IT consultants in Perth.
3. Preserve evidence and record what happened
Take a photograph or screenshot of warnings and ransom notes if it is safe to do so. Record the time, affected usernames and devices, unusual messages, links clicked, information entered, MFA prompts approved, files opened and actions already taken. Keep suspicious emails in their original form so headers and links can be examined.
Do not immediately wipe the computer, delete logs, remove suspicious mailbox rules or destroy the ransom note before evidence has been captured. These details can help determine how the attacker entered, what they accessed, whether data left the organisation and which systems need to be rebuilt.
4. Reset passwords immediately from a clean device
Reset the affected password immediately, but use a different device that is known to be clean. Start with the compromised email or administrator account, followed by banking, cloud storage, remote access, payroll and other critical services. Use a new, long and unique passphrase for every account. Never reuse a password that may have been exposed.
If the same password was used elsewhere, treat every account using it as compromised. A password manager can help create and securely store unique credentials. Do not send a new password through the mailbox that may still be controlled by the attacker.
5. Revoke sessions, tokens and suspicious MFA methods
A password change is important, but it may not immediately remove an attacker who already holds a valid browser session or authentication token. An administrator should block or disable the affected account where appropriate, revoke active sign-in sessions, invalidate refresh tokens and review registered MFA methods, devices and passkeys.
For Microsoft 365, review Entra sign-in and audit logs, risky sign-ins, authentication methods, user consent to applications and recent administrative role changes. Microsoft provides current technical guidance on how to revoke user access in Microsoft Entra ID.
I Signed In Through an Email and Approved MFA, but It Was Not Legitimate
This can be an adversary-in-the-middle phishing attack. The fake website may relay your sign-in to the real service in real time. When you enter your password and approve MFA, the attacker may capture the resulting authenticated session. This means MFA worked as designed, but the approval was given to a fraudulent sign-in.
What to do after approving a fraudulent MFA request
- Contact your IT administrator immediately using a trusted channel.
- From a clean device, reset the password for the affected account.
- Have an administrator revoke all active sessions and refresh tokens.
- Review and remove unfamiliar MFA methods, devices, passkeys and app passwords.
- Check sign-in logs for unfamiliar IP addresses, locations, devices and applications.
- Review mailbox forwarding, inbox rules, deleted items and application consent.
- Check SharePoint, OneDrive, Teams and other connected services for access or downloads.
- Warn relevant staff that follow-up phishing or payment fraud may occur.
Do not rely only on the geographic location shown in a sign-in log. Attackers use VPN services, residential proxies and compromised devices, and the recorded location may be inaccurate. Investigators should correlate the time, IP address, device, browser, authentication details, session identifiers and subsequent activity.
Someone Is Sending Email Pretending to Be Me
There are two common possibilities: your email account has been compromised, or an attacker is spoofing your name or address without signing in to your mailbox. Both require action, but the investigation and remediation are different.
Signs your mailbox may be compromised
- Unrecognised successful sign-ins or MFA registrations appear in your logs.
- Messages you did not write appear in Sent Items, Deleted Items or message trace.
- New forwarding settings or hidden inbox rules send, move or delete email.
- Contacts report replies coming from your genuine mailbox or an existing conversation.
- Email, SharePoint or OneDrive content has been accessed or downloaded unexpectedly.
- Your password or security information changed without your approval.
If these indicators are present, disable the account if appropriate, reset its password, revoke sessions and investigate the full period of suspected access. Microsoft’s guidance for a compromised Microsoft 365 email account includes reviewing forwarding, hidden inbox rules, application consent, authentication methods, sign-in logs and messages sent by the user.
Signs it may be email spoofing or impersonation
If the message came from a lookalike domain, a free email account, or an unrelated address displaying your name, the attacker may never have entered your mailbox. Ask your IT team to examine the full message headers and authentication results. Your organisation should correctly configure SPF, DKIM and DMARC, monitor similar domain registrations and educate recipients to verify changes to payment details through a known telephone number.
Send a concise warning to affected contacts through a trusted channel. Tell them not to open the message, click links, download attachments, send information or approve payments. If fraudulent payment instructions were sent, contact your bank and the recipient’s bank immediately. Time is critical when attempting to stop or recall a transfer.
Our Corporate Network Has a Ransomware Note and Our Data Is Encrypted
A ransomware note should be treated as a business-wide cyber incident, not simply a problem with one computer. Modern ransomware incidents can involve credential theft, lateral movement, deleted backups, data exfiltration and extortion before files are encrypted.
Immediate ransomware containment
- Record the ransom note, file extensions, affected systems and the time discovered.
- Isolate affected endpoints, servers and network segments from wired, wireless, VPN and internet connectivity.
- Protect backup infrastructure, hypervisors, storage, identity systems and privileged accounts.
- Disable suspected accounts and remote access paths, then revoke active sessions.
- Activate the incident response plan and contact cyber insurance before incurring major costs or making commitments.
- Preserve firewall, VPN, endpoint, server, cloud, identity and email logs.
- Engage qualified incident response, forensic, legal and communications advisers.
- Assess whether personal, confidential, financial or regulated data was accessed or stolen.
Do not connect backup repositories to an infected network or begin restoring systems until the intrusion path has been contained. Otherwise, clean systems and backups may be encrypted again. Recovery should use backups that have been checked, isolated and confirmed as unaffected. Critical identity, security and management systems should be recovered in a controlled order before normal business services.
Should we pay the ransom?
The Australian Cyber Security Centre advises victims never to pay a ransom. Payment does not guarantee that files will be restored or stolen data deleted, and it may expose the organisation to further targeting. Ransomware decisions can also involve legal, sanctions, insurance and governance risks. Obtain specialist legal, incident response and law-enforcement advice rather than contacting or negotiating with the attacker yourself.
Follow the Australian Cyber Security Centre’s Ransomware Emergency Response Guide and call the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371) for assistance.
Who Should I Notify After I Have Been Hacked?
ReportCyber and the Australian Cyber Security Centre
Australian individuals and businesses can report cybercrime and cyber security incidents through ReportCyber. Reporting can assist law enforcement and national cyber security agencies in identifying and disrupting criminal activity.
Your bank, insurer and affected contacts
Contact your bank immediately if banking credentials, invoices, payment instructions or financial data may be affected. Notify your cyber insurer in accordance with the policy, as the insurer may require approval before you engage particular advisers or incur response costs. Warn customers, suppliers and staff if they may receive fraudulent messages or payment requests.
Privacy and regulatory notifications
Australian organisations should promptly assess whether the incident is an eligible data breach under the Notifiable Data Breaches scheme or triggers other contractual, industry or regulatory reporting obligations. The Office of the Australian Information Commissioner explains when affected individuals and the OAIC may need to be notified. Obtain legal advice for your organisation’s specific circumstances.
How to Recover Safely After a Cyber Attack
Containment is only the beginning. A safe recovery should identify the initial access method, remove persistence, determine the scope of access and close the security gap before services return to production.
A practical recovery sequence
- Define the incident timeline and confirm affected identities, devices, data and services.
- Preserve relevant evidence and logs before retention periods expire.
- Remove malicious access, applications, forwarding rules, accounts and remote tools.
- Patch exploited vulnerabilities and secure exposed services.
- Reset privileged and service-account credentials using a controlled sequence.
- Rebuild compromised systems from trusted installation media where required.
- Scan and validate backups before restoration.
- Restore systems in stages while monitoring for renewed suspicious activity.
- Document decisions, notifications, costs, lessons and required control improvements.
How to Reduce the Risk of Being Hacked Again
- Use phishing-resistant MFA, such as passkeys or security keys, for administrators and high-risk users.
- Require unique passphrases and manage them through an approved password manager.
- Patch operating systems, firewalls, VPNs, applications, hypervisors and network storage promptly.
- Remove unnecessary internet-facing services and restrict remote administration.
- Apply least privilege and use separate accounts for administration.
- Configure SPF, DKIM and DMARC to reduce email domain abuse.
- Maintain isolated, immutable and regularly tested backups.
- Monitor identity, endpoint, email, firewall and cloud security events.
- Train staff to independently verify login requests, MFA prompts and payment changes.
- Maintain and rehearse an incident response and business continuity plan.
Frequently Asked Questions
What is the first thing I should do if I have been hacked?
Disconnect the affected device or account from further access, contact your IT or cyber security provider through a trusted channel, and preserve evidence. Change compromised passwords from a known-clean device and revoke active sessions.
I have been hacked—what do I do after approving MFA?
Reset the password from a clean device, revoke all active sessions and refresh tokens, remove unknown MFA methods, review sign-in and audit logs, and check mailbox rules, forwarding and application consent. An MFA phishing attack may leave the attacker with a valid authenticated session.
Does changing my password log a hacker out?
Not always. Existing browser sessions, refresh tokens, application passwords or connected applications may remain usable. An administrator should revoke sessions and tokens and remove suspicious authentication methods and application access.
How can I tell whether someone hacked my email or spoofed it?
Review full message headers, message trace, sign-in logs, audit logs, sent and deleted messages, forwarding settings and hidden inbox rules. Spoofing may use your display name or a lookalike domain without accessing your real mailbox.
Should I turn off a computer affected by ransomware?
First record the visible ransom note and isolate the device from all networks. If encryption is actively spreading and immediate network isolation is not possible, powering it down can help stop further damage. A corporate response team may instead preserve a live system for forensic purposes.
Should a business pay a ransomware demand?
The Australian Cyber Security Centre advises never paying a ransom because there is no guarantee of recovery or deletion of stolen data. Seek specialist incident response, legal, insurance and law-enforcement advice.
Do I need to report that I have been hacked?
You can report cyber incidents through ReportCyber. A business may also have privacy, customer, insurance, contractual, critical infrastructure or industry reporting obligations. Seek legal advice and consult the OAIC if personal information may be involved.
Need Urgent Help After Being Hacked?
If you are asking, “I have been hacked—what do I do now?”, the safest next step is to get experienced assistance before evidence is lost or the incident spreads. BIZ-LYNX Technology can help businesses contain compromised accounts, investigate suspicious email activity, respond to ransomware and plan a secure recovery.
Contact BIZ-LYNX Technology for urgent cyber security and incident response assistance.

