Been Hacked Fix UK
Been Hacked Fix is a practical guide for people and small businesses in UK who need calm, plain-English help after a suspected hack. The first priority is to stop further damage, preserve useful evidence and avoid rushed decisions that make recovery harder.
Start by disconnecting affected devices from the internet if you can do so safely, but do not wipe phones, laptops or mailboxes before important evidence has been captured. Change passwords from a separate trusted device, enable multi-factor authentication where possible and check whether email forwarding rules, payment details or administrator accounts have been changed.
For Microsoft 365, Google Workspace, domain names and social accounts, look for unusual sign-ins, new inbox rules, unfamiliar recovery details and messages sent without your knowledge. If money, client data or business systems are involved, keep a written timeline of what happened, who noticed it, what was clicked and which accounts may be affected.
IT Life-Raft can help turn the incident into a clear recovery plan: secure the accounts, review devices, check backups, reduce repeat risk and explain the next steps without jargon. The aim is not to panic; it is to regain control, protect evidence and make the business safer than it was before the incident.
Useful next steps include reviewing Microsoft 365 security settings, checking endpoint protection, confirming backup coverage, tightening administrator access and training staff to spot follow-up scams. A good recovery also includes prevention, because attackers often try again once they know an account or business has been vulnerable.
More detail
If you think you or your business has been hacked, act quickly and calmly. This guide gives you the first practical steps to limit damage, protect money movement, preserve evidence and get trusted support.
Step 1: Check the signs that something is wrong
A cyber incident is not always obvious at first. Treat the situation seriously if you notice any of these warning signs.
- Locked accounts or unexpected password changes. You suddenly cannot access email, Microsoft 365, banking, cloud systems or line-of-business software.
- Strange emails sent from your account. Customers, suppliers or colleagues report suspicious messages, links, invoices or attachments.
- Missing, renamed or encrypted files. Files disappear, change name, become unreadable or show ransom-style notes.
- Login alerts from unknown locations. You receive sign-in notifications from places, devices or times you do not recognise.
- Unusual financial activity. Payments are redirected, invoices are altered, bank activity looks wrong or a supplier asks for payment changes.
- Unexpected software or remote access tools. Apps appear that you did not install, or security tools have been disabled.
- Staff reporting odd behaviour. Emails vanish, files move, browsers open unexpectedly or devices behave unusually.
Step 2: Limit the damage first
- Disconnect affected devices from the internet. Unplug the network cable or turn off Wi-Fi. Do not wipe the device.
- Do not keep talking to suspicious callers. If someone claims to be from a bank, Microsoft, HMRC or IT support, end the call and use a known trusted number.
- Protect money movement. Warn anyone who can approve payments. Check bank activity and supplier payment changes using a trusted phone number.
- Preserve evidence. Take photos or screenshots of warnings, emails, bank messages and login alerts. Write down dates, times and affected accounts.
- Do not post about it publicly. Avoid giving attackers or scammers extra information.
- Locate backups. Check what backups exist, but do not overwrite, delete or reconnect affected systems until you have a plan.
- Do not pay ransom demands without advice. Payment does not guarantee recovery and can create further risk.
Step 3: Use a clean route to get help
If email may be compromised, do not rely on it for recovery decisions. Use a trusted phone number, a clean device and known contact details. IT Life-Raft can help you focus on containment, account recovery, evidence, backups and practical next steps.
Step 4: Secure accounts from a clean device
- Reset passwords for email, Microsoft 365, banking, cloud storage and important business systems.
- Enable multi-factor authentication where possible.
- Check email forwarding rules, mailbox delegates, recovery addresses and unknown devices.
- Review administrator accounts and remove anything you do not recognise.
- Check whether payment details, supplier records or customer messages have been altered.
Step 5: Review devices, backups and monitoring
Once the immediate risk is contained, affected devices may need checking, cleaning, rebuilding or replacing. Backups should be reviewed carefully before restoration. Business incidents may also need monitoring for further suspicious activity.
- Check whether email rules or recovery details were changed.
- Review endpoint protection, updates, firewall status and backups.
- Monitor bank accounts, email activity and Microsoft 365 sign-ins.
- Check whether exposed email addresses appear in known breach data using Have I Been Pwned.
- Move important accounts to unique passwords stored in a password manager.
Useful external resources after a suspected hack
These resources can help you check exposure, report fraud and understand whether personal data may be involved. Use them from a clean device where possible.
- Have I Been Pwned — check whether an email address appears in known breach data.
- Action Fraud — UK cybercrime and fraud reporting.
- Information Commissioner’s Office (ICO) — guidance where personal data may be involved.
- Report HMRC phishing and scam messages — UK Government reporting route for suspicious HMRC contact.
- KeePass — one option for storing unique passwords securely.
Need urgent help?
If this involves business email, invoices, Microsoft 365, bank payments or customer data, treat it as urgent. Contact IT Life-Raft using a trusted phone number or the urgent incident form so we can help you get calm, practical next steps.
Been Hacked Fix next steps
Been Hacked Fix should be reviewed in a practical way: check the current setup, confirm who owns each system and decide which improvements reduce the most risk. IT Life-Raft uses Been Hacked Fix guidance to turn technical concerns into clear actions for small businesses.
If Been Hacked Fix is already on your mind, the useful next step is to document what is working, what is fragile and what would cause disruption if it failed. That makes the improvement plan easier to prioritise and easier for staff to follow.
