What To Do When You've Been Hacked
When a cyberattack strikes, panic costs you critical time. Use this step-by-step incident response plan to contain the breach, preserve evidence, and recover.
Table of Contents
Stay Calm and Think Before You Act
Discovering you have been hacked triggers a panic response. The urge to immediately change everything, disconnect everything, or delete everything is understandable — and often counterproductive. Some of those actions destroy forensic evidence. Others alert the attacker that they have been detected, causing them to act faster.
This guide gives you a structured response. The phases are: Detect → Contain → Eradicate → Recover → Learn.
Phase 1: Detect — Confirm the Incident
Before responding, confirm what actually happened. Not every anomaly is a breach.
Signs that suggest genuine compromise:
- An email about a login from an unfamiliar location or device you did not recognize
- Password reset emails you did not request
- Friends or colleagues receiving messages from you that you did not send
- Unexpected charges on financial accounts
- Files encrypted with a ransom note
- Antivirus detection of known malware
- Your accounts locked out and you cannot reset via email (because email was also compromised)
If possible, screenshot and save evidence. Note the time and what you observed. This helps you reconstruct what happened and is needed for insurance claims, legal action, or IT support.
Phase 2: Contain — Stop the Bleeding
Isolate Compromised Devices
If you suspect malware on a device, disconnect it from the network (turn off Wi-Fi and unplug ethernet) but do not turn it off. Shutting down can destroy volatile memory evidence and, in some ransomware cases, complete the encryption. Isolate it physically.
If a corporate device is compromised, notify your IT/security team immediately. Do not attempt remediation yourself on a work device.
Revoke Access From Compromised Sessions
For account compromises (email, social media, banking):
- From a clean, uncompromised device (a phone you trust, or a different computer), log into your account
- Go to security settings and look for "active sessions" or "devices"
- Sign out all other sessions
- Change your password immediately
- Review connected third-party apps and revoke any you do not recognize
Alert Your Financial Institution
If financial accounts are involved, call your bank or credit card company. They can freeze the card, dispute fraudulent transactions, and issue new account numbers faster than any online process. Have your account numbers ready.
Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) if personal information was exposed. A freeze prevents new credit accounts from being opened in your name.
Phase 3: Eradicate — Remove the Attacker
Change Credentials in the Right Order
Sequence matters. Change credentials starting with the most critical accounts and working outward:
- Email first — email is the master key. Whoever controls your email can reset everything else.
- Password manager — so new passwords you create are protected
- Financial accounts — banking, investment, payment apps
- Other important accounts — work accounts, healthcare portals, identity-linked accounts
Use your password manager to generate unique, long passwords for each account. Do not reuse any password that was previously compromised.
Enable MFA Everywhere
While changing passwords, enable two-factor authentication on every account that supports it. Use an authenticator app (not SMS where possible) for your most critical accounts. SMS is vulnerable to SIM-swapping attacks.
Clean or Rebuild Compromised Devices
If a device has confirmed malware:
- Mobile phones: factory reset is usually sufficient for most malware. Enable FRP (Factory Reset Protection) and restore from a backup taken before the incident.
- Computers: for commodity malware (adware, ransomware that did not spread), a scan with Malwarebytes followed by removal may work. For sophisticated malware or rootkits, reinstall the operating system from clean media. Do not trust a compromised system even after antivirus removal.
- Back up important files first, then scan the backup before restoring it.
Phase 4: Recover — Restore Safely
Restore From Clean Backups
If you have backups (you should), verify they predate the compromise before restoring. Some ransomware lurks for weeks before triggering, so a "recent" backup may already be infected.
Monitor for Continued Activity
After changing credentials and cleaning devices, watch for signs that the attacker still has access:
- Login alerts from unfamiliar locations
- Email rules you did not create (attackers often set forwarding rules)
- Apps or browser extensions you did not install
- Recurring unauthorized charges
Set up login notifications on every important account if you have not already.
Notify Affected Parties
If your compromise exposed other people's data (a business breach, for example), you likely have legal notification obligations. Check applicable laws (GDPR, state breach notification laws, HIPAA). Notify affected individuals promptly — late notification causes more harm and carries higher legal risk.
Phase 5: Learn — Prevent the Next Incident
Every incident reveals a gap. After stabilizing:
- Determine how the attacker got in: phishing? Reused password? Unpatched software? Exposed service?
- Address that specific gap
- Review what data was exposed and what your risk is going forward
- Update your backup strategy if it failed you
- Consider whether professional incident response help is warranted for business incidents
When to Call for Help
Not every incident should be handled alone:
- Ransomware on a business network: call a professional incident response firm before paying any ransom
- Identity theft: the FTC's IdentityTheft.gov provides a personalized recovery plan
- Suspected stalkerware on your device: the Coalition Against Stalkerware offers resources and support
- Nation-state targeting: contact CISA (in the US) or your national cybersecurity agency
Having a plan before you need it makes all the difference. Document your critical account credentials in a password manager today, enable MFA on your email and financial accounts, and keep offline backups — so that when (not if) an incident occurs, your recovery options are already in place.