What to Do If You Think You Have Been Hacked

Discovering unusual activity on a business computer or network can be concerning. However, immediately deleting files, shutting down systems, or attempting to investigate without preserving evidence can make the situation more difficult to understand.

If a compromise is suspected, the immediate objective should be to contain the potential incident while preserving useful information.

A suspicious event does not always mean that a system has been hacked. The safest response is to slow down, establish what actually happened, protect important accounts, and preserve evidence before making significant changes.

Incident response process A four-stage process showing how to respond to suspected hacking: verify, contain, preserve, and recover. Verify Establish what actually happened Contain Limit further communication Preserve Protect logs and useful evidence Recover Fix the cause before restoring
A measured response helps contain a potential compromise without unnecessarily destroying information that may explain what happened.

Incident response checklist

10 things to do if you suspect a compromise

The right response depends on the circumstances, but these steps provide a practical starting point for protecting systems and preserving useful information.

  1. Initial assessment

    Do not assume the first explanation is correct

    A slow computer, unexpected popup, failed login, or unusual network connection does not automatically mean that a system has been compromised.

    Potential explanations include:

    • Software failures
    • Misconfigured services
    • Automated Internet scanning
    • Legitimate administrative activity
    • Malware
    • Credential compromise
    • Unauthorized access
    Recommended action

    Record the original symptoms and establish what actually occurred before making major changes to the system.

  2. Containment

    Disconnect an affected computer from the network

    If there is strong evidence that a particular computer is compromised, disconnecting it from the network can prevent further communication with other systems.

    Depending on the circumstances, this can mean:

    • Disconnecting Ethernet
    • Disabling Wi-Fi
    • Moving the system to an isolated network
    Preserve information first

    Avoid immediately deleting suspicious files or reinstalling the operating system if an investigation may be necessary.

  3. Account protection

    Do not continue using a potentially compromised account

    If the suspected incident involves an account, use a known-clean device to change the password.

    Prioritize:

    • Email
    • Administrator accounts
    • VPN accounts
    • Cloud services
    • Financial accounts
    • Domain administration
    • Password managers

    If the same password was reused elsewhere, change those credentials as well. Enable multi-factor authentication wherever possible.

    Use a known-clean device

    Changing credentials from a potentially compromised computer may expose the new credentials.

  4. Evidence preservation

    Preserve logs

    Logs may contain information about what happened. Do not assume that logs will remain available indefinitely because some systems rotate logs quickly.

    Potentially useful sources include:

    • Firewall logs
    • VPN logs
    • Windows Event Logs
    • Linux authentication logs
    • DNS logs
    • Web server logs
    • Cloud authentication logs
    • Endpoint security logs
    • Email security logs
    Recommended action

    Preserve relevant logs before they are overwritten and record where each log source came from.

  5. Investigation

    Identify the earliest known suspicious activity

    Establishing a timeline is often more useful than immediately trying to determine exactly who was responsible.

    Determine:

    • When the unusual activity was first observed
    • Which account or device was involved
    • Which IP addresses were involved
    • Which services were accessed
    • Whether authentication succeeded
    • Whether additional accounts were created
    • Whether files were modified
    • Whether other systems show related activity
    Recommended action

    Record times in a consistent time zone and preserve the original timestamps from the relevant systems.

  6. Scope assessment

    Check other systems

    A compromised workstation does not necessarily mean that the entire network has been compromised. However, related systems should be reviewed for indicators of additional activity.

    Review for:

    • Authentication failures
    • Successful logins
    • New administrator accounts
    • Unexpected processes
    • New scheduled tasks
    • Unusual outbound connections
    • Unexpected DNS requests
    • Modified configuration files
    Recommended action

    Use centralized logging where available to compare activity across multiple systems.

  7. Communication

    Do not communicate with an attacker

    If ransomware, extortion, or an active intrusion is suspected, avoid communicating with the attacker unless there is a specific incident-response reason to do so.

    Do not:

    • Follow unknown instructions
    • Install software provided by the attacker
    • Provide credentials
    • Provide remote access
    • Delete evidence
    • Attempt retaliation
    Recommended action

    Preserve messages, demands, filenames, contact details, and other evidence without following unverified instructions.

  8. Specialist assistance

    Consider professional incident response

    A significant compromise may require specialized investigation, containment, evidence preservation, and recovery assistance.

    Professional assistance may be appropriate when:

    • Sensitive information may have been accessed
    • Administrator credentials were compromised
    • Multiple systems are affected
    • Ransomware is involved
    • Financial systems may be affected
    • The attacker appears to have maintained persistent access
    • The organization cannot determine what happened
    Recommended action

    Request assistance early when the potential impact is significant or the organization lacks the resources to investigate safely.

  9. Recovery

    Restore carefully

    Reinstalling an affected computer may remove malware, but it does not necessarily answer how the compromise occurred.

    Before restoring systems, determine whether:

    • The initial vulnerability remains
    • Credentials remain compromised
    • Other systems were affected
    • Backups are trustworthy
    • Persistence mechanisms were established
    Important consideration

    If the original cause is not addressed, the same compromise can potentially happen again after restoration.

  10. Documentation

    Document everything

    Create an incident timeline containing the relevant facts, decisions, evidence, and actions taken.

    Record:

    • Date and time
    • System
    • Account
    • Source IP
    • Event
    • Action taken
    • Evidence collected
    • Person responsible
    Why this matters

    Documentation can become important for internal investigations, insurance requirements, legal matters, regulatory obligations, and future security improvements.

Investigation record

Build a simple incident timeline

A timeline helps separate confirmed facts from assumptions and shows how the incident developed.

01

First observation

Record what was noticed

Note the date, time, device, account, symptoms, and person who first reported the unusual activity.

02

Evidence review

Connect the event to available logs

Compare authentication, firewall, DNS, endpoint, cloud, and system events where available.

03

Containment

Record actions taken

Document disconnected systems, disabled accounts, changed credentials, preserved logs, and other response actions.

04

Recovery

Record what was restored and why

Note restored systems, verified backups, remaining risks, and improvements required before normal operations resume.

The goal of incident response

Contain the problem without losing the evidence

A suspicious event should be handled carefully. The priority is to limit further damage, protect important accounts and systems, preserve useful information, and determine whether additional systems or data may have been affected.

Once the immediate situation is under control, the organization can address the original weakness and improve monitoring, access controls, backups, and response procedures.

Security monitoring

Suspect unusual activity?

A managed security monitoring service can help identify suspicious authentication activity, network connections, intrusion attempts, and other security events before they become difficult-to-understand incidents.

Request a Security Assessment