top of page

My Small Business Was Hacked. What Should I Do Right Now?

  • Writer: Shay
    Shay
  • Aug 26
  • 16 min read
My small business was hacked, what should I do right now? Immediate cybersecurity response steps for small businesses.
What should you do if your small business is hacked? Practical first steps for responding to a compromised computer, Microsoft 365 account, Business Email Compromise, phishing, ransomware or financial fraud.

If you think your small business was hacked, you probably have a lot of questions about what you should do next. Maybe an employee's computer is behaving strangely. The mouse is moving without anyone touching it. A computer keeps rebooting. Someone received a Microsoft 365 security notification they do not recognize. Customers are receiving emails nobody remembers sending. An employee's MFA suddenly stopped working. Accounting discovers that a vendor's banking information was changed. Maybe an employee clicked a phishing link and now nobody is sure what happened next.


At that point, most business owners are not interested in a cybersecurity lecture. They need realistic answers about what to do next.


The exact response depends on what happened. A compromised computer is different from a compromised Microsoft 365 account. Business Email Compromise involving a fraudulent payment creates different immediate priorities from ransomware. A stolen laptop creates different questions from an attacker actively controlling a computer.

There is no single button that fixes all of those situations. There are, however, some important things a small business can do to limit additional damage, preserve useful information and get the right people involved.


If Your Small Business Was Hacked, Contact Your IT Provider First

If you have an IT provider, internal IT person or cybersecurity contact, this is the time to use them. Tell them exactly what you observed rather than trying to diagnose the problem yourself.

“The mouse started moving by itself at approximately 2:15 PM” is useful information. “I think we were hacked” does not provide nearly as much to start with.


Tell IT what happened, when you first noticed it, which person and device are involved, whether anything unusual happened beforehand and what actions have already been taken. If an employee clicked a link, downloaded something, entered a password, approved an MFA request or responded to a suspicious email, tell IT that too.


If your business has an Incident Response Plan for Small Business, follow the escalation process already established in it. Employees should know who to contact, who the backup contact is and what to do if an incident occurs after normal business hours.


If your business has never established those answers, my Small Business Incident Response Checklist provides a quick readiness check and a free fillable workbook to help document emergency contacts, escalation procedures, IT responsibilities, Microsoft 365 administrative access, Business Email Compromise and financial fraud procedures, cyber insurance information, recovery priorities and other details that should already be established before an incident occurs.


Should I Disconnect the Computer From the Network?

If you believe a computer is actively compromised, separating it from the network may help contain the problem while preserving the machine for investigation.


That could mean disconnecting the Ethernet cable or removing the device from WiFi. What happens next should depend on the circumstances and the person investigating the incident.


This is where I do not like universal instructions that tell every business owner to immediately start shutting down, wiping or rebuilding computers. There may be information in memory, logs, running processes, active connections or other areas that can help determine what happened.


The appropriate response depends on what is occurring and whether qualified technical help is available. If you can reach the person responsible for your IT, get them involved as quickly as possible and follow the instructions for your particular situation.


Should I Shut the Computer Down?

Not necessarily.

Disconnecting a device from the network and shutting it down are two different decisions. Depending on the incident, powering a computer off can cause information that exists only while the system is running to be lost.


There are also situations where shutting a computer down may be the decision made by the person responding to the incident. That is exactly what I did in the real client incident I discuss below.


The point is not that you should always leave the computer running or always shut it down. The point is that the response should fit the incident.


Do Not Start Cleaning Everything Up

When an owner realizes something may be compromised, the natural reaction is to start fixing things. That can sometimes make the investigation harder.

Before someone understands the scope of the incident, avoid randomly deleting suspicious files, wiping computers, clearing logs, removing accounts, factory resetting equipment or making dozens of undocumented configuration changes.

This does not mean nothing should be changed. Containment may require immediate technical action. The difference is that those actions should be deliberate and documented.

Write down what was done, who did it and when.


Should I Change My Password From the Computer I Think Was Hacked?

If you reasonably suspect that a computer itself has been compromised, I would not use that same computer to start signing into other sensitive accounts and changing passwords.

The response may require changing credentials, but those changes should be made from a trusted device as part of the containment and recovery process. If the affected computer has malware, unauthorized remote access or another compromise, continuing to enter credentials into it can create additional risk.


This is another reason to contact IT before making a series of changes on your own. We need to consider both the compromised account and the device being used to access it.


A Real Compromise I Responded To

A few months ago, a client contacted me because one of their computers had been behaving strangely. The machine had been randomly rebooting during the day, and there had already been some unusual email behavior.

Then the employee noticed the mouse moving on its own.


They called me. I happened to be on another client call and could not answer immediately, so they texted me. I responded and connected to the computer to investigate.

Once I confirmed that I was dealing with a compromised machine, I had them disconnect the network cable and shut the computer down. I then moved into the Microsoft 365 side of the response, including revoking access and MFA methods for the affected user and blocking sign in.


Once I finished the other client call, I drove to their office and picked up the affected computer so I could continue investigating it.


I ultimately removed the compromised hard drive rather than putting it back into production. I installed a new drive, rebuilt and configured the computer, and drove the working machine back to the client the following morning.


The original drive was preserved. I placed it in a bag and documented the date and time it was removed along with my name, business information and signature so the client retained the original media if it was needed later.


I also documented the incident timeline, including when the client called, when they texted, when I accessed the device, what I discovered and the actions that followed.


I am careful about how I describe that work. I was preserving the original media and documenting my technical response. I was not representing that work as a formal digital forensic examination or making legal determinations about evidence handling.


That is one reason I put so much emphasis on documentation during an incident. Once several people become involved and hours or days have passed, reconstructing everything from memory becomes much harder.


What Should I Document While This Is Happening?

Start a timeline as soon as you reasonably can.

Document what was actually observed, not what you assume happened. Record when unusual activity was first noticed, who noticed it, which device or account was involved, who was contacted and what actions were taken.

Depending on the incident, useful information can include:

  • Date and time the problem was first noticed

  • Name of the employee who noticed it

  • What the employee actually observed

  • Affected user or account

  • Computer or device involved

  • Security alerts or notifications

  • Suspicious emails

  • Unusual MFA prompts

  • Screenshots or photographs

  • People contacted

  • Accounts blocked or changed

  • Devices disconnected from the network

  • Technical actions taken

  • Financial transactions involved

  • Relevant ticket or case numbers

If something is unknown, write unknown.

You do not need to fill the timeline with theories. You are creating a factual record that can help IT and, depending on the situation, an insurer, attorney, forensic specialist, law enforcement agency or another qualified professional understand what occurred.


The free workbook included with my Small Business Incident Response Checklist also includes an Incident Timeline and Action Log specifically for documenting this information while an incident is happening.


What if an Employee Clicked a Phishing Link?

Do not automatically assume that clicking the link means the entire business has been compromised, but do not ignore it either.

What happened after the click matters.


Did the employee simply open a webpage and close it? Did they enter their Microsoft 365 password? Did they approve an MFA prompt? Did they download or open a file? Did they grant an application permission? Did they enter banking, payroll or other sensitive information?


Those are very different situations and can require different responses.


Have the employee stop what they are doing and report exactly what happened. If possible, preserve the original email or message rather than deleting it. Tell IT what information was entered and whether anything was downloaded or approved.

The employee should not be embarrassed into hiding part of what happened. From my perspective, I would rather know exactly what was clicked and entered so I can investigate the right things.


What if My Microsoft 365 Account Was Hacked?

A Microsoft 365 compromise needs more investigation than simply changing the user's password.


Depending on what happened and the tools and licensing available in the environment, I may need to investigate sign in activity, authentication methods, active access, mailbox activity, forwarding, Inbox rules, security alerts, applications and other activity associated with the identity.


Microsoft's current compromised account guidance includes revoking active sessions, reviewing registered MFA methods, reviewing application consent, examining forwarding and checking Inbox rules, including hidden rules. Microsoft also identifies rules that move messages into folders such as Notes, Junk Email or RSS Subscriptions as possible signs of compromise.


That is why I look beyond the obvious places in a mailbox. An attacker may be trying to hide messages from the person who normally uses the account.


The purpose is to understand what happened, what the attacker may have accessed or changed and whether another method of access or persistence needs to be addressed.

This is also why I do not immediately assume every strange email means the Microsoft 365 account itself was compromised. A sender can be spoofed. A lookalike domain can be used. A vendor's account could be compromised instead.

We investigate before deciding what happened.


What if I Cannot Log Into Microsoft 365 Anymore?

If your normal password no longer works, your MFA information has changed or you believe someone else has taken control of the account, tell whoever is handling the incident immediately.


Do not spend hours repeatedly experimenting with account recovery while making undocumented changes.


If another authorized administrator exists, that account may provide a way to begin investigating and containing the affected identity. If properly configured emergency administrative access exists, it may provide another recovery path.


If the compromised identity was the only administrative access the business had and nobody can regain appropriate control of the tenant, Microsoft support and account recovery procedures may need to become part of the response.


The situation is even more important if the locked out account has administrative privileges.


What if the Compromised Microsoft 365 Account Is an Administrator?

Tell the person investigating the incident immediately.

A compromised account with administrative privileges can create a different level of exposure from a normal user account because the potential access depends on the administrative role assigned to that identity. The investigation may need to look beyond the user's mailbox and determine whether administrative changes occurred elsewhere in the Microsoft 365 environment.


This becomes especially difficult when a business owner uses the same identity for everyday email and Microsoft 365 administration and the attacker changes the password or MFA methods. If that was the business's only administrative path into the tenant, recovery can become much more complicated.


If properly secured emergency administrative access already exists, the person handling the incident may have another authorized way to begin containment and investigation.

This is not the moment when I want to lecture a business owner about how Microsoft 365 should have been configured. The immediate priority is regaining appropriate control, containing the incident and understanding what happened.

Afterward, privileged access should absolutely be part of the review.


For the Microsoft 365 environments I manage, I generally do not want an everyday mailbox used for normal email, web browsing and business activity to also be the account routinely used for privileged administration. I also want properly configured emergency administrative access available before it is needed.


These are some of the things I evaluate during a Microsoft 365 Audit and Tenant Security Review. A security review is not just about finding settings that could be stronger. It can identify architectural issues that determine what options are available when an actual incident occurs.


Is Changing the Password Enough?

Do not assume so.

Changing a compromised password can be an important containment step, but an investigation may also need to consider existing sessions, authentication methods, mailbox rules, forwarding, applications, administrative changes and other ways the attacker could have accessed or altered the environment.


Microsoft's current guidance specifically includes revoking active sessions as part of responding to a compromised Microsoft 365 account. It also calls for reviewing MFA methods, application consent, administrative roles, forwarding and mailbox rules.

What needs to be reviewed depends on what was compromised.


That is why “we changed the password” should not automatically be interpreted as “the incident is over.”


What if Customers Are Receiving Emails I Did Not Send?

That needs to be investigated, but it does not automatically prove that someone logged into your mailbox.


Your account may actually have been compromised. Someone could be spoofing your email address. An attacker may have registered a domain that looks very similar to yours.


Another company involved in an email conversation may be compromised.

The technical investigation needs to establish which scenario actually occurred.

That distinction becomes particularly important when money is involved.


What if This Is Business Email Compromise?

Business Email Compromise, commonly called BEC, deserves immediate attention because a cyber incident can quickly become a financial incident.


BEC can involve fraudulent vendor invoices, fake changes to banking information, executive impersonation, payroll changes, gift card requests or messages designed to convince someone to send money or sensitive information.


Sometimes the attacker has actually compromised an email account. Sometimes a legitimate address is spoofed. Sometimes the attacker uses a lookalike domain. The FBI also warns that attackers can use malware or compromised email conversations to make fraudulent payment requests more convincing.

Again, investigate rather than assume.


What if We Caught the Fraudulent Payment Request Before Sending Money?

That is obviously a much better outcome than discovering the fraud after money has moved, but I would not simply delete the message and forget about it.


Preserve the suspicious email and report it to whoever handles IT or security for the business. Verify the supposed request through a trusted method using contact information you already know rather than replying to the suspicious message or calling a phone number contained in it.


Then determine whether there is a reason to investigate further.

Was the message simply spoofed? Was a lookalike domain involved? Did someone compromise your vendor's account? Did someone compromise your account? Does the message contain information suggesting the attacker had access to an existing conversation?


A failed fraud attempt can still reveal a security problem worth investigating.


We Already Sent the Money. What Do We Do Right Now?

Contact the financial institution immediately.

Do not wait for the technical investigation to finish before starting the financial response.

The FBI advises BEC victims to contact their financial institution immediately and request that it contact the financial institution where the transfer was sent. The FBI also directs victims to report Business Email Compromise through the Internet Crime Complaint Center, commonly called IC3.


At the same time, the technical investigation should continue.


Preserve the fraudulent emails, payment instructions, relevant communications, transaction information and other records associated with the event. Do not reply to the suspicious email to ask whether it was legitimate. Verify the request using trusted contact information that was already known to the business.


This is also where an established financial verification process can make an enormous difference. Changes to vendor banking information, payroll information or significant payment instructions should have an independent verification procedure appropriate for the business.


What if an Employee's Direct Deposit Was Changed?

Treat an unauthorized payroll change seriously.

The immediate financial response will depend on whether payroll has already been processed and which financial institutions or payroll providers are involved. The employee, payroll provider, financial institution and appropriate internal people may all need to be contacted quickly.


At the same time, investigate how the change happened.


Did someone compromise the employee's email? Was payroll impersonated? Did an attacker send a fraudulent request from a lookalike address? Was an internal payroll account accessed?


Do not assume the answer simply because you know the direct deposit information was changed.


What if There Is a Ransom Note on the Screen?

If you see a ransom note, encrypted files or multiple computers suddenly becoming inaccessible, treat the situation as a potentially broader incident rather than troubleshooting one computer.


Contact the person responsible for your IT or incident response immediately and explain exactly what you are seeing. If multiple computers, servers or shared files appear to be affected, tell them that immediately because it can change the containment strategy.


Avoid randomly wiping, rebuilding or reconnecting affected systems while the scope is being determined. Depending on the circumstances, cyber insurance, legal counsel, specialized incident response resources and law enforcement may also need to become involved.


Ransomware response can become significantly more complicated than recovering one workstation, particularly if servers, backups, identity systems or multiple endpoints are involved.


Should I Tell My Employees?

Employees may need to know something is happening, particularly if their actions could affect containment or recovery.


They may need instructions not to use a particular system, not to open certain messages, to report unusual MFA prompts, to use an alternate communication method or to stop accessing a shared resource while it is being investigated.

That does not mean every employee needs every technical detail.


Communication should be coordinated so employees know what they need to do without creating confusion or spreading unverified information about what happened.

If normal company email or Teams may be part of the compromise, your Small Business Incident Response Checklist also includes planning for an alternate communication method so the business is not trying to solve that problem during the incident.


Should I Call My Cyber Insurance Company?

Possibly, and your actual policy matters.

If you have cyber insurance, locate the policy and the carrier or broker's incident reporting information. Some policies may establish specific procedures for reporting incidents or engaging legal counsel, forensic investigators or other response providers.

Do not assume all cyber insurance policies work the same way.


This is one reason the free workbook included with my Small Business Incident Response Checklist includes space to document the carrier, broker, claims contact and policy information ahead of time. You do not want the first step during an emergency to be searching through old emails trying to remember who sold you the policy.


Do I Need a Forensic Investigator?

Not every suspicious email or infected computer requires a formal forensic investigation.

Some incidents can be handled through normal IT or cybersecurity investigation and remediation. Others may involve sensitive data, significant financial loss, regulatory requirements, cyber insurance, litigation concerns or a scope that requires specialized forensic expertise.


That decision may involve IT, management, legal counsel, the cyber insurance carrier and other qualified professionals depending on the situation.

The important part is recognizing when the incident has moved beyond ordinary troubleshooting.


Do I Have to Tell My Customers?

A cybersecurity incident does not automatically mean that every customer must immediately be notified.


The answer depends on what actually happened, what information was involved and which legal, regulatory, contractual and insurance requirements apply to the business.

Regulated industries can have additional requirements, and state or federal breach notification requirements may apply depending on the circumstances.


This is another place where IT and legal responsibilities need to remain distinct. IT can investigate the technical environment, document findings and explain what systems, accounts or data appear to have been affected. Determining the business's legal notification obligations may require appropriate legal or regulatory guidance.

Do not guess, but do not ignore the question either.


When Is It Safe to Use the Computer Again?

That depends on what was compromised and what the investigation found.

A computer should not simply be reconnected because an antivirus scan came back clean.

The investigation needs to establish enough about the incident to make an informed recovery decision. Depending on the circumstances, remediation could involve cleaning the system, rebuilding it, replacing storage, restoring from known good backups, replacing the device or taking other actions.


In the client incident I described earlier, I chose not to put the compromised drive back into production. I preserved it and rebuilt the client on a new drive.

That was the decision for that particular incident. It is not a universal rule for every compromised computer.


How Do I Know the Hacker Is Really Gone?

This is one of the hardest questions a business owner can ask, and it deserves a realistic answer.


You gain confidence by understanding the scope of the incident, identifying how access occurred when possible, closing the access that was discovered, reviewing related systems and identities, remediating affected devices or accounts, monitoring for additional suspicious activity and validating that the environment is behaving as expected.

There is not a single security product that can press a button and prove that every attacker is gone from every part of the business.


The level of investigation and validation should fit the severity and scope of the incident.


Once the Immediate Incident Is Over, Figure Out Why the Response Worked or Didn't

After the business is operating safely again, I want to look beyond the compromised account or computer.

Did the employee recognize that something was wrong? Did they know who to contact? Did the escalation process work? Could IT get into the systems it needed? Did we know who had administrative access? Could we find the cyber insurance information? Were useful logs available? Did anyone know who could authorize major response decisions? If money was involved, did employees know who could stop a payment or call the bank? Did we have a reliable timeline?


Those questions become the starting point for improving the business's Incident Response Plan for Small Business.


If you are not sure whether your business has those basics in place today, start with my Small Business Incident Response Checklist. It provides a shorter readiness review plus a free fillable and print friendly workbook you can use to document emergency contacts, IT responsibilities, Microsoft 365 access, BEC and financial fraud procedures, cyber insurance information, recovery priorities and an incident timeline.


If the incident exposed larger questions about your Microsoft 365 environment, administrative access, MFA, security monitoring or logging, that is also a good time to consider a Microsoft 365 Audit and Tenant Security Review. If the gaps extend beyond Microsoft 365 and nobody has a clear picture of the overall IT environment, an IT Baseline Assessment can provide a broader starting point.


The goal is not to build a cybersecurity plan that predicts every possible attack. It is to make sure that when an employee says, “Something is wrong with my computer,” your business already knows what happens next.


ADDITIONAL RESOURCES

Microsoft Learn: Respond to a Compromised Email Account in Microsoft 365

Microsoft's current guidance covers compromised Microsoft 365 identities, revoking active sessions, reviewing MFA methods, application consent, administrative roles, forwarding, Inbox rules and other areas that may need to be investigated following an account compromise.https://learn.microsoft.com/en-us/defender-office-365/responding-to-a-compromised-email-account


Microsoft Learn: Revoke User Access in Microsoft Entra ID

Microsoft provides current guidance for blocking sign ins and revoking access when an identity has been compromised or otherwise needs to be disabled quickly.https://learn.microsoft.com/en-us/entra/identity/users/users-revoke-access


Federal Bureau of Investigation: Business Email Compromise

The FBI explains common Business Email Compromise techniques, independent verification of payment requests, immediate financial institution contact following a fraudulent transfer and reporting through IC3.https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise


Federal Trade Commission: Data Breach Response, A Guide for Business

The FTC provides guidance on securing operations, investigating incidents, preserving evidence and determining the legal and notification considerations that may follow a data breach.https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business


Federal Trade Commission: Cybersecurity for Small Business

The FTC provides cybersecurity guidance specifically for small businesses, including incident response, ransomware, employee preparedness and recovery planning.https://www.ftc.gov/business-guidance/small-businesses/cybersecurity

Comments


bottom of page