What Are The First Signs That A Business Has Been Hacked?
The first signs that a business has been hacked are not always obvious. A cyber attack may cause a dramatic disruption, but it can also begin simply with an unfamiliar login notification, a locked account or an employee noticing unusual activity on their computer.
Common warning signs include unexpected login attempts, unfamiliar emails being sent from business accounts, unusual computer behaviour, missing or altered files, locked accounts, unexpected software and unexplained network activity.
Recognising these signs quickly can give a business a better chance of limiting the damage.
Unusual login notifications
One of the clearest warning signs is a login that you or your employees do not recognise. Businesses should pay attention to notifications showing successful or unsuccessful login attempts from unfamiliar locations, devices or times.
An employee who normally works in the UK, for example, may reasonably question a login from a location they have never visited.
A single unusual login does not necessarily prove that an account has been compromised. However, repeated or unexplained authentication attempts should be investigated.
Emails you didn’t send
Has a customer received an unusual email apparently sent from someone in your organisation? Or are employees discovering messages in their Sent folders that they did not write? This can indicate that an email account has been compromised.
Attackers may use compromised accounts to send phishing messages to customers, suppliers or colleagues because an email from a genuine business account can appear more convincing than a message from an unknown sender.
Employees should report unexpected messages promptly rather than simply deleting them.
Computers behaving strangely
A sudden change in the behaviour of a computer can also be a warning sign. This could include applications opening unexpectedly, unfamiliar programs appearing, unusual pop-ups, security software being disabled or a device becoming unusually slow.
There are many possible causes for poor computer performance, so these symptoms do not automatically mean a device has been hacked. However, unexpected changes should be investigated, particularly if several devices begin behaving unusually at around the same time.
Files have been changed, deleted or encrypted
Unexpected changes to business files are another important warning sign. You may notice documents being renamed, files disappearing or important information becoming inaccessible.
In a ransomware attack, files may be encrypted so that employees can no longer open them. Businesses should have reliable backups so that important data can potentially be recovered without relying solely on the compromised systems.
If files suddenly become inaccessible or appear to have been encrypted, avoid making unnecessary changes to affected devices and contact your IT or cyber security service provider immediately.
Accounts suddenly stop working
An employee discovering that their password no longer works can be another warning sign, particularly if they did not change it themselves.
An attacker who gains access to an account may change its password or other security settings to prevent the legitimate user from regaining access.
However, forgotten passwords, expired credentials and ordinary administrative changes can cause the same problem. The important point is to establish why the change occurred rather than assuming it is routine.
Your security tools raise an alert
Modern security software can sometimes identify suspicious behaviour before an employee notices anything unusual.
An endpoint security platform, firewall or other security system may generate alerts about malware, suspicious processes, unusual network traffic or attempted access.
These alerts should not automatically be ignored simply because the affected computer appears to be working normally. Some attacks are designed to remain unnoticed.
What should you do if you think your business has been hacked?
If you suspect a cyber attack, report it immediately to whoever manages your business IT and cyber security.
Depending on the circumstances, appropriate steps may include isolating an affected device from the network, securing compromised accounts, preserving relevant evidence, checking other systems for signs of compromise and beginning recovery procedures.
Do not assume that deleting a suspicious file or restarting a computer has solved the problem. Some attacks involve multiple devices or accounts, meaning the original issue may be more extensive than the first warning sign suggests.
It is also important to have a clear incident response process before an attack happens. Employees should know who to contact, what information to provide and what they should avoid doing if they suspect something is wrong.
If something does not look right, don’t wait for the situation to become more obvious. A strange login, unexpected email, locked account or unusual computer behaviour may be the first indication that something needs investigating.
