Klassroom Notes

The First Hour After You've Been Hacked

What you do in the first hour matters more than anything you do in the following month.

The First Hour After You've Been Hacked

The moment you realize

Someone tells you they got a strange email from your address. A vendor says your invoice had different bank details. A login stops working. A customer asks why your website is showing something odd.

Whatever the trigger, there's a moment where the possibility becomes real. What you do in the following hour matters more than anything you do in the following month, and the instinct most people have - poke at it for a while and hope it's nothing - is the wrong one.

Stop the bleeding first

Before you investigate anything, cut off access.

  1. Change the password on your primary email account, from a device you trust, and sign out of all sessions. Email is the reset path for every other account you own, so it comes first even if the problem appears to be somewhere else.
  2. Turn on two-factor authentication on that account if it wasn't already, and check whether an unfamiliar phone number or app is already enrolled. Remove anything you don't recognize.
  3. Then the money. Bank, payment processor, payroll, anything that moves funds. New passwords, and check recent activity and any changed payee details.
  4. Then everything important that shares that password, which is usually more accounts than people expect.

Use a different device than the one you suspect. If a computer might be compromised, doing your password resets on it hands the new passwords straight over.

Look for what they left behind

Attackers don't just get in; they arrange to stay in. Check for the quiet changes:

  • Email forwarding rules and filters. The classic move is a rule that silently forwards a copy of everything to an outside address, or one that files messages containing the word "invoice" straight into the trash so you don't see the replies.
  • Recovery phone numbers and backup email addresses on your major accounts.
  • Extra users, extra API keys, extra app passwords. On your website, your email system, your accounting software.
  • Active sessions and connected apps. Revoke anything unfamiliar.

Look at all of these even after you've changed passwords, because a forwarding rule survives a password change perfectly well.

Tell people, sooner than feels comfortable

This is the step owners avoid, and it's the one that limits the damage.

  • Your bank and your payment processor, immediately, if there's any chance financial details were exposed.
  • Anyone who might receive a fraudulent message from you. A short, plain note - "my email was compromised, please verify anything unusual by phone before acting on it" - stops the second wave, which is usually where the real money is lost.
  • Your customers, if their information may have been exposed. Most states, California included, require notification when personal information is involved, and the timelines are not generous. Talk to an attorney about your specific obligation rather than guessing.
  • Your insurer, if you carry a cyber policy. Many require prompt notice, and many provide a response team you've already paid for.

Also file a report with the FBI's Internet Crime Complaint Center. It's free, and for wire fraud specifically, fast reporting occasionally recovers funds.

Write down what happened, while it's fresh

Dates, times, what you saw, what you changed, who you told. You'll need it for the bank, for insurance, possibly for a legal notification, and for figuring out afterward how it started.

Then, once things are stable, do the boring prevention: two-factor everywhere, unique passwords in a password manager, and a hard rule that any change to payment details gets verified by a phone call to a number you already had.

The bottom line

Cut access first, email before everything else. Then hunt for forwarding rules and added users, because those are how an intruder stays after you've changed the locks. Then tell the people who need to know, earlier than is comfortable.

The businesses that come through this well aren't the ones that were never targeted. They're the ones that moved in the first hour instead of hoping.

Want help applying this to your business?

The Small Business Efficiency Checkup covers this and more - a practical review of your systems, tools, and workflows with a plain-English action plan.

Learn About the Efficiency Checkup Book a Free 15-Minute Consultation

Get practical notes on small business operations in your inbox.

Practical notes on running a small business more efficiently - tools, workflows, and the occasional observation from 30 years of systems work. Short, useful, and infrequent.