Skip to main content

Updated 3 min read

Ransomware or a Hacked Email Account? What to Do in the First Hour

The short answer

Disconnect the affected computers from the network but leave them switched on, call your cyber insurance company before anything else, and don't contact the attackers or pay. From a clean device, change the hacked account's password, sign it out everywhere and check for forwarding rules. Then get experienced help to contain it and restore from backup.

It usually starts small. Someone can’t open a file and the name has changed to something strange. A client calls to ask why you emailed them a link to “review an invoice”. A screen shows a message demanding payment.

Whatever you’re looking at, the first hour matters more than any hour after it. Here’s what to do, in order.

1. Disconnect, but don’t switch off

Unplug the network cable from any computer that looks affected and turn off its Wi-Fi. If several machines are showing the problem, or you don’t know how far it has spread, unplug the office from the internet at the router or firewall.

Leave the computers on. Turning them off can destroy evidence that shows how the attackers got in and what they touched, and that evidence decides a lot later on, including what your insurer covers and who you have to notify.

2. Call your cyber insurance company

If you have cyber insurance, call the claims line before you call anyone else, us included. Many policies require you to report quickly and to use the insurer’s approved response firms and attorneys. Starting work without them can put your cover at risk. If you’re not sure whether you have cyber cover, check your business policy or call your broker.

3. Don’t contact the attackers, and don’t pay yet

The ransom note is designed to rush you. Paying doesn’t guarantee your files come back, and it doesn’t stop the attackers from publishing or selling what they took. That decision belongs to later, with your insurer and your attorney, and good backups often take it off the table.

4. If it’s an email account, lock it down from a clean device

Hacked email is one of the most common ways an incident starts, and the damage usually comes after the break-in: the attacker reads mail quietly, then sends invoices or payment changes to your clients from your real address. From a phone or computer you trust:

  • Change the password and turn on multi-factor authentication (MFA) if it isn’t on.
  • Sign the account out of every session, so the attacker’s open session ends too.
  • Look for forwarding rules and inbox rules that send or hide mail. Attackers set these up to keep watching after the password changes.
  • Warn clients and vendors not to act on recent payment instructions from you without calling first.

5. Write down what you know

Note when it started, who noticed, what they saw and what’s been done since. Take photos of any ransom message. Keep any suspicious emails rather than deleting them. It feels like paperwork in a crisis, but it saves hours later.

6. Get experienced help to contain it and recover

After those first steps, the work is to find how the attackers got in, make sure they’re out, check what was taken, rebuild what’s damaged and restore your data from backups that weren’t touched. Then close the door they used, so it doesn’t happen again.

New clients often come to us in the middle of exactly this, most often after a phishing email or a stolen password. We contain it, clean up, bring the office back online and then put the security in place so it doesn’t recur. If it’s happening now, call (714) 450-9330. Our own team answers, after hours too.

Who you may need to tell

Depending on what was taken, you may have legal duties to report it:

Your attorney should make the call on what applies to you.

Before it happens

Incidents like these usually come through the same few gaps: no MFA on email, backups that were never tested or sat on the same network, and computers that weren’t kept up to date. Our guide to monitoring, patching and backups explains how those get closed, and our managed security page covers how we watch for attacks around the clock.

This guide is general information, not legal advice. For questions about your specific obligations, talk to your attorney or compliance advisor.

Sources

  1. Data Breach Response: A Guide for Business (FTC)
  2. Data Security Breach Reporting (California Attorney General)
  3. HIPAA Breach Notification Rule (HHS)
  4. #StopRansomware Guide (CISA)
  5. FBI Internet Crime Complaint Center (IC3)

Frequently asked questions

Should we pay the ransom?
Don't decide in the first hour, and don't contact the attackers yourself. Paying doesn't guarantee your files come back or that the data they took stays private, and it can raise legal issues. Talk to your insurer and your attorney first; often clean backups make the question irrelevant.
Should we turn the computers off?
Disconnect them from the network instead: unplug the network cable and turn off Wi-Fi. A computer left on keeps evidence that helps work out what happened. If you can't disconnect a machine any other way, shutting it down is better than leaving it connected.
Do we have to report it?
Often, yes. Medical practices have HIPAA breach notification rules, tax and accounting firms may have to notify the FTC, and California law requires telling affected people in many cases. The details depend on what was taken, so involve your attorney early. You can also report the crime to the FBI through ic3.gov.
We're not your client. Can you still help?
Yes. Many of the offices we look after first called us in the middle of an incident. Call (714) 450-9330 and tell us what you're seeing; our own team answers, after hours too.