01 / LIMIT
Urgent cyber help in Dorset
Been Hacked Fix Dorset
Practical cyber incident support for people and small businesses across Dorset. Start with containment, protect accounts and payments, then build a clear recovery plan.
What to check in Dorset
Recognise the signs before making changes.
Small businesses, charities, professional firms and owner-managed organisations can be disrupted by one compromised mailbox or reused password. Treat password-reset messages you did not request, files becoming unavailable or renamed and customers receiving messages you did not send as reasons to investigate promptly.
An incident may begin with a convincing phone call, a fake Microsoft sign-in page, a supplier invoice, stolen browser credentials or an unpatched device. Write down what each person saw and the time it happened. A reliable timeline is more useful than guessing how the attacker got in.
02 / CLEAN ROUTE
Use a trusted device
Use a separate phone or computer to contact your bank, IT provider and account services. Type known addresses yourself and avoid links in the message that caused concern.03 / ACCOUNTS
Secure the control points
Start with email, Microsoft 365 or Google Workspace, banking, domain names and website administration. Reset unique passwords, review recovery details, remove unknown sessions and enable MFA.04 / EVIDENCE
Preserve a clear record
Keep screenshots, full email headers, telephone numbers, URLs, bank messages and login alerts. Record every password reset, device isolation and call so recovery work is not duplicated.A recovery plan for Dorset
Check people, accounts, devices and backups together.
For organisations operating in and around Dorset, an account compromise rarely stays inside one inbox. Attackers may study previous conversations, imitate trusted contacts or wait until a real payment is due. Review sent items, deleted items, forwarding rules, delegated access, administrator roles and recent sign-in locations.
Ask staff to report unusual prompts without blame. Tell them which channel to use if normal email cannot be trusted. Check laptops, phones and shared computers for unfamiliar browser extensions or remote tools. Confirm backups exist, are separate from the affected system and can be restored before deleting or rebuilding anything.
Businesses serving Devon, Durham, East Sussex as well as Dorset should also check shared suppliers and accounts used across locations. The goal is to regain control, understand the likely exposure and reduce the chance of a follow-up attempt.
Email and identity
Review sign-ins, MFA methods, inbox rules, recovery addresses, application permissions and administrator accounts. Sign out unknown sessions after evidence has been recorded.
Money movement
Contact the bank using a trusted number. Independently verify recent or pending supplier-detail changes. Do not rely on the same email thread that may be compromised.
Devices and backups
Check endpoint alerts, update status and remote-access software. Keep affected equipment isolated until it is safe to reconnect, and test recovery rather than assuming a backup works.
Customers and staff
Prepare a short factual message if other people may receive fraudulent emails or if personal data is at risk. Avoid speculation while the incident scope is still being established.
Report fraud in Dorset
Use official routes and known contact details.
If money has moved, call the bank immediately and ask its fraud team whether a transfer can be stopped or recalled. Report through Action Fraud. For prevention and recovery guidance, use NCSC guidance for organisations. If personal data may have been exposed, assess whether the relevant regulator and affected people must be notified.
Keep reference numbers and record who was contacted. Reporting does not replace technical containment: secure accounts and devices at the same time, using a clean route the suspected attacker cannot monitor.
Questions from Dorset
Frequently asked questions.
These answers are a calm starting point. A live incident can involve legal, insurance, banking and data-protection duties, so get specialist advice where the circumstances require it.
What should I do first if I have been hacked in Dorset?
Disconnect an affected device from the internet if it is safe, stop approving payments, preserve messages and screenshots, then use a separate trusted device to secure your most important accounts.
Who should I report online fraud to in Dorset?
Contact your bank immediately when money may be at risk. Use Action Fraud for the appropriate official reporting route, and call emergency services if there is an immediate danger.
Can IT Life-Raft help a small business in Dorset remotely?
Yes. Initial containment, account checks and recovery planning can often begin remotely. Where a device or network needs hands-on investigation, we will explain the safest practical route.
Should I wipe the affected laptop or phone?
Not before evidence and recovery options have been assessed. Wiping too early can remove useful logs, messages and other information needed to understand what happened.
Local support from IT Life-Raft
Get calm, practical help in Dorset.
Tell us what happened, which accounts or devices are affected and whether money or customer data may be at risk. We will help you separate urgent containment from the recovery work that can follow.
Send the flare
IT Life-Raft