CompFlorida | Business Technology

I Think My Business May Be Compromised — What To Do Now

Practical guidance, implementation and accountability for organizations that need reliable technology and a clear next step.

If you think your business may have been hacked, compromised, infected with ransomware, had an email account taken over, or exposed customer data, use this page as a first-response checklist.

Do not panic and do not make random changes. Your first priorities are to limit damage, preserve evidence, understand what happened, protect critical accounts, and keep the business operating safely.

I think my business was compromised — what should I do right now?

  1. Disconnect affected devices from the network when appropriate. If a workstation or server appears actively compromised, isolate it from wired, Wi-Fi and VPN access. Do not automatically power it off unless there is an immediate safety or operational reason.
  2. Call your IT/security response contact. If you have an MSP, internal IT team, security provider or cyber insurer, activate them immediately.
  3. Preserve evidence. Keep logs, suspicious emails, screenshots, timestamps, ransom notes, alerts and affected devices. Write down what was observed and every action taken.
  4. Protect privileged accounts. From a known-clean device, review administrator, email, cloud, banking and remote-access accounts. Reset credentials when appropriate and preserve evidence first where compromise is suspected.
  5. Check MFA and active sessions. A password change alone may not terminate an attacker’s existing session. Review active sessions, forwarding rules, recovery methods, API tokens and MFA changes.
  6. Stop financial damage. If payments, payroll, ACH, wire transfers, credit cards or banking may be affected, contact the financial institution immediately using a known-good phone number.
  7. Determine what is affected. Identify systems, accounts, locations, vendors and data involved. Do not assume one compromised computer is the full scope.
  8. Do not notify customers publicly until facts are understood. Notification obligations vary. Coordinate with legal counsel, insurers, regulators and law enforcement as appropriate.

FTC guidance is consistent with this approach: move quickly to secure operations, mobilize a response team, preserve forensic evidence, investigate scope, address vulnerabilities and determine notification obligations.

What kind of compromise do you suspect?

Business email compromised

Unexpected forwarding rules, sent messages you did not send, password-reset notices, new MFA methods, invoice fraud or customers receiving fake payment instructions.

Check: active sessions, forwarding rules, recovery email/phone, OAuth apps, delegates, MFA and administrator activity.

Ransomware or encrypted files

Files renamed or encrypted, ransom notes, inaccessible servers, backup failures or widespread endpoint alerts.

Check: network isolation, backups, identity systems, lateral movement, remote access and whether backups are still trustworthy.

Banking or payment fraud

Unauthorized ACH/wire activity, changed payment instructions, fraudulent invoices, merchant-account anomalies or payroll changes.

Check: bank first, then email/identity compromise, payment system access and affected counterparties.

Website or ecommerce compromise

Unknown admin users, malicious redirects, injected pages, checkout changes, unusual plugins or search results showing spam pages.

Check: hosting/admin accounts, plugins/apps, DNS, payment integrations, logs and backups.

Cloud / SaaS account takeover

Unknown logins, deleted files, new admins, unexpected integrations, API keys, mailbox rules or data exports.

Check: identity provider, sessions, tokens, audit logs, administrators and connected apps.

Lost or stolen computer/phone

A device containing business email, files, credentials or customer data is missing.

Check: device encryption, remote management, active sessions, stored credentials and whether remote lock/wipe is appropriate.

Vendor or service-provider breach

A software, MSP, payroll, payment, telecom or cloud vendor reports a compromise that may involve your organization.

Check: what access they had, whether credentials/tokens should be revoked, what data they held and whether their access path reached your environment.

Unknown suspicious activity

Slow systems, security alerts, unknown software, repeated MFA prompts, disabled tools, odd network traffic or users reporting unusual behavior.

Check: endpoint, identity, firewall, DNS, email and cloud logs before assuming the cause.

What not to do

  • Do not immediately wipe or reimage systems. You may destroy evidence needed to understand the intrusion.
  • Do not rely on password changes alone. Attackers may have active sessions, tokens, forwarding rules or persistence elsewhere.
  • Do not restore backups until you know they are clean. Restoring into a still-compromised environment can recreate the problem.
  • Do not communicate sensitive response details through a suspected compromised email account.
  • Do not pay a ransom just because a timer is displayed. Payment does not guarantee recovery and introduces legal, financial and operational considerations.
  • Do not assume “the antivirus cleaned it” means the incident is over. Determine scope and entry point.
  • Do not make public statements or customer notifications based on guesses. Establish facts and coordinate the response.

Who may need to be notified?

The right path depends on what happened, what data was involved, your industry and where affected people are located. The following are common U.S. response paths; this is not legal advice.

Your IT / cybersecurity provider

For containment, investigation, evidence preservation, remediation and recovery.

Cyber insurance carrier

Many policies require prompt notice and may specify approved legal counsel, forensic firms or negotiators.

Legal counsel

For breach-notification obligations, privilege, contracts, regulatory requirements and communications.

Bank / payment provider

Contact immediately if wire, ACH, payroll, card or merchant fraud may be occurring.

FBI Internet Crime Complaint Center (IC3)

Federal reporting mechanism for suspected internet-facilitated criminal activity.

Local FBI / law enforcement

The U.S. Department of Justice advises reporting internet-related crime to appropriate local, state or federal investigative authorities based on scope.

Regulators

Depending on industry and data type, healthcare, financial, state privacy or other regulators may have reporting requirements.

Affected customers / employees / partners

Notification requirements vary by state, data type and circumstances. Coordinate timing and content with counsel and law enforcement where appropriate.

Incident information checklist

Before calling for help, collect what you can without changing the affected systems unnecessarily.

  • Date and approximate time the problem was first noticed.
  • Who discovered it and what they observed.
  • Affected users, devices, servers, applications and locations.
  • Screenshots or photos of alerts, ransom notes and unusual messages.
  • Suspicious emails, sender addresses and message headers if available.
  • Known unauthorized transactions or changed payment instructions.
  • Recent password, MFA, administrator or vendor-access changes.
  • Recent software updates, remote-access changes or new vendors.
  • Whether backups exist and where they are stored.
  • Cyber insurance policy/contact information.
  • Names of your MSP, cloud provider, email provider, payment processor and other key vendors.
  • Any legal, regulatory or contractual requirements already known.

How CompFlorida can help

CompFlorida can help coordinate the operational side of an incident: identify technology dependencies, engage the appropriate IT/security/vendor resources, preserve an accurate timeline, review connectivity and infrastructure exposure, and help keep response ownership clear across multiple parties.

Need help now?

If you believe a business system, email account, server, network, payment workflow or cloud service may be compromised, start by documenting what you see and contacting the appropriate response resources.

Request Incident Coordination Help

Related CompFlorida resources

Technology Risk Center → Search common business technologies, vendor resources and known security risks.

Cybersecurity & Business Continuity → Review preventive controls, resilience and recovery planning.

Frequently asked questions

How do I know if my business has been hacked?

Common warning signs include unknown logins, repeated MFA prompts, email-forwarding rules you did not create, unexplained administrator accounts, disabled security tools, unusual payments, encrypted files, unexplained data transfers or customers receiving messages you did not send. One symptom alone does not prove compromise; investigate before assuming the cause.

Should I turn off a hacked computer?

Not automatically. FTC guidance recommends taking affected equipment offline to stop additional data loss but cautions against powering machines down before forensic review because useful evidence may be lost. The right action depends on the incident and operational risk.

Should I change passwords immediately?

Often yes, but do it deliberately from a known-clean device and consider active sessions, authentication tokens, MFA methods and recovery settings. If forensic investigation is needed, coordinate evidence preservation first.

Should I pay ransomware?

Payment does not guarantee recovery. Involve experienced incident-response resources, legal counsel, cyber insurance and law enforcement before making decisions about ransomware demands.

Do I have to notify customers?

Possibly. Requirements depend on the information involved, affected jurisdictions, your industry and other facts. All U.S. states and certain territories have breach-notification laws involving personal information, and sector-specific rules may also apply. Consult qualified legal counsel.

Last reviewed: September 21, 2026. This page provides general incident-response information for business owners and is not legal advice or a substitute for qualified forensic, legal, insurance or law-enforcement guidance.

Choose the appropriate next step

Move from a broad question to an accountable action.

Need help now?

Start with the current business impact, affected users and systems.

Request service →

A clearer technology decision starts here

Bring us the environment—not a polished specification.

We will help identify the operating problem, dependencies, responsible parties and next practical step.

Start the conversation