Updated 3 min read
Ransomware or a Hacked Email Account? What to Do in the First Hour
The short answer
Disconnect the affected computers from the network but leave them switched on, call your cyber insurance company before anything else, and don't contact the attackers or pay. From a clean device, change the hacked account's password, sign it out everywhere and check for forwarding rules. Then get experienced help to contain it and restore from backup.
It usually starts small. Someone can’t open a file and the name has changed to something strange. A client calls to ask why you emailed them a link to “review an invoice”. A screen shows a message demanding payment.
Whatever you’re looking at, the first hour matters more than any hour after it. Here’s what to do, in order.
1. Disconnect, but don’t switch off
Unplug the network cable from any computer that looks affected and turn off its Wi-Fi. If several machines are showing the problem, or you don’t know how far it has spread, unplug the office from the internet at the router or firewall.
Leave the computers on. Turning them off can destroy evidence that shows how the attackers got in and what they touched, and that evidence decides a lot later on, including what your insurer covers and who you have to notify.
2. Call your cyber insurance company
If you have cyber insurance, call the claims line before you call anyone else, us included. Many policies require you to report quickly and to use the insurer’s approved response firms and attorneys. Starting work without them can put your cover at risk. If you’re not sure whether you have cyber cover, check your business policy or call your broker.
3. Don’t contact the attackers, and don’t pay yet
The ransom note is designed to rush you. Paying doesn’t guarantee your files come back, and it doesn’t stop the attackers from publishing or selling what they took. That decision belongs to later, with your insurer and your attorney, and good backups often take it off the table.
4. If it’s an email account, lock it down from a clean device
Hacked email is one of the most common ways an incident starts, and the damage usually comes after the break-in: the attacker reads mail quietly, then sends invoices or payment changes to your clients from your real address. From a phone or computer you trust:
- Change the password and turn on multi-factor authentication (MFA) if it isn’t on.
- Sign the account out of every session, so the attacker’s open session ends too.
- Look for forwarding rules and inbox rules that send or hide mail. Attackers set these up to keep watching after the password changes.
- Warn clients and vendors not to act on recent payment instructions from you without calling first.
5. Write down what you know
Note when it started, who noticed, what they saw and what’s been done since. Take photos of any ransom message. Keep any suspicious emails rather than deleting them. It feels like paperwork in a crisis, but it saves hours later.
6. Get experienced help to contain it and recover
After those first steps, the work is to find how the attackers got in, make sure they’re out, check what was taken, rebuild what’s damaged and restore your data from backups that weren’t touched. Then close the door they used, so it doesn’t happen again.
New clients often come to us in the middle of exactly this, most often after a phishing email or a stolen password. We contain it, clean up, bring the office back online and then put the security in place so it doesn’t recur. If it’s happening now, call (714) 450-9330. Our own team answers, after hours too.
Who you may need to tell
Depending on what was taken, you may have legal duties to report it:
- Medical and dental practices: HIPAA’s breach notification rule sets out who to notify and by when.
- Tax and accounting firms: the FTC Safeguards Rule has its own notification requirement; our guide to the rule covers it.
- Everyone: California law requires notifying affected people in many cases, and when a notice goes to more than 500 California residents, a sample copy goes to the Attorney General too. You can report the crime to the FBI at ic3.gov. CISA’s ransomware guide covers the response in more depth, and the FTC’s Data Breach Response: A Guide for Business walks through securing systems and telling the people affected.
Your attorney should make the call on what applies to you.
Before it happens
Incidents like these usually come through the same few gaps: no MFA on email, backups that were never tested or sat on the same network, and computers that weren’t kept up to date. Our guide to monitoring, patching and backups explains how those get closed, and our managed security page covers how we watch for attacks around the clock.
This guide is general information, not legal advice. For questions about your specific obligations, talk to your attorney or compliance advisor.


