Urgent cyber help in Dumfries and Galloway

Been Hacked Fix Dumfries and Galloway

Practical cyber incident support for people and small businesses across Dumfries and Galloway. Start with containment, protect accounts and payments, then build a clear recovery plan.

15minutes: limit damageSafepreserve evidenceDumfries and Gallowayplain-English support

What to check in Dumfries and Galloway

Recognise the signs before making changes.

Businesses working across cities, rural communities, tourism, energy and professional services can be disrupted by one compromised mailbox or reused password. Treat unfamiliar administrator accounts, security software being switched off and payments or invoices being redirected as reasons to investigate promptly.

An incident may begin with a convincing phone call, a fake Microsoft sign-in page, a supplier invoice, stolen browser credentials or an unpatched device. Write down what each person saw and the time it happened. A reliable timeline is more useful than guessing how the attacker got in.

SignSafe first action
unfamiliar administrator accountsReview recent sign-ins from a clean device.
security software being switched offPreserve the rule or message before removing it.
payments or invoices being redirectedPause payment and verify using a known number.

01 / LIMIT

Limit the damage

Disconnect a device when malware is suspected, but do not wipe it. Stop remote-access sessions and suspicious calls. If business email is involved, warn anyone who approves invoices or changes supplier details.

02 / CLEAN ROUTE

Use a trusted device

Use a separate phone or computer to contact your bank, IT provider and account services. Type known addresses yourself and avoid links in the message that caused concern.

03 / ACCOUNTS

Secure the control points

Start with email, Microsoft 365 or Google Workspace, banking, domain names and website administration. Reset unique passwords, review recovery details, remove unknown sessions and enable MFA.

04 / EVIDENCE

Preserve a clear record

Keep screenshots, full email headers, telephone numbers, URLs, bank messages and login alerts. Record every password reset, device isolation and call so recovery work is not duplicated.

A recovery plan for Dumfries and Galloway

Check people, accounts, devices and backups together.

For organisations operating in and around Dumfries and Galloway, an account compromise rarely stays inside one inbox. Attackers may study previous conversations, imitate trusted contacts or wait until a real payment is due. Review sent items, deleted items, forwarding rules, delegated access, administrator roles and recent sign-in locations.

Ask staff to report unusual prompts without blame. Tell them which channel to use if normal email cannot be trusted. Check laptops, phones and shared computers for unfamiliar browser extensions or remote tools. Confirm backups exist, are separate from the affected system and can be restored before deleting or rebuilding anything.

Businesses serving Clackmannanshire, Dundee, East Lothian as well as Dumfries and Galloway should also check shared suppliers and accounts used across locations. The goal is to regain control, understand the likely exposure and reduce the chance of a follow-up attempt.

Email and identity

Review sign-ins, MFA methods, inbox rules, recovery addresses, application permissions and administrator accounts. Sign out unknown sessions after evidence has been recorded.

Money movement

Contact the bank using a trusted number. Independently verify recent or pending supplier-detail changes. Do not rely on the same email thread that may be compromised.

Devices and backups

Check endpoint alerts, update status and remote-access software. Keep affected equipment isolated until it is safe to reconnect, and test recovery rather than assuming a backup works.

Customers and staff

Prepare a short factual message if other people may receive fraudulent emails or if personal data is at risk. Avoid speculation while the incident scope is still being established.

Report fraud in Dumfries and Galloway

Use official routes and known contact details.

If money has moved, call the bank immediately and ask its fraud team whether a transfer can be stopped or recalled. Report through Police Scotland scams and fraud guidance. For prevention and recovery guidance, use NCSC guidance for organisations. If personal data may have been exposed, assess whether the relevant regulator and affected people must be notified.

Keep reference numbers and record who was contacted. Reporting does not replace technical containment: secure accounts and devices at the same time, using a clean route the suspected attacker cannot monitor.

Questions from Dumfries and Galloway

Frequently asked questions.

These answers are a calm starting point. A live incident can involve legal, insurance, banking and data-protection duties, so get specialist advice where the circumstances require it.

What should I do first if I have been hacked in Dumfries and Galloway?

Disconnect an affected device from the internet if it is safe, stop approving payments, preserve messages and screenshots, then use a separate trusted device to secure your most important accounts.

Who should I report online fraud to in Dumfries and Galloway?

Contact your bank immediately when money may be at risk. Use Police Scotland scams and fraud guidance for the appropriate official reporting route, and call emergency services if there is an immediate danger.

Can IT Life-Raft help a small business in Dumfries and Galloway remotely?

Yes. Initial containment, account checks and recovery planning can often begin remotely. Where a device or network needs hands-on investigation, we will explain the safest practical route.

Should I wipe the affected laptop or phone?

Not before evidence and recovery options have been assessed. Wiping too early can remove useful logs, messages and other information needed to understand what happened.

Local support from IT Life-Raft

Get calm, practical help in Dumfries and Galloway.

Tell us what happened, which accounts or devices are affected and whether money or customer data may be at risk. We will help you separate urgent containment from the recovery work that can follow.

Send the flare