Been Hacked How Do I Fix It? In Scotland
Been Hacked is a practical guide for people and small businesses in Scotland who need calm, plain-English help after a suspected hack. The first priority is to stop further damage, preserve useful evidence and avoid rushed decisions that make recovery harder.
Start by disconnecting affected devices from the internet if you can do so safely, but do not wipe phones, laptops or mailboxes before important evidence has been captured. Change passwords from a separate trusted device, enable multi-factor authentication where possible and check whether email forwarding rules, payment details or administrator accounts have been changed.
For Microsoft 365, Google Workspace, domain names and social accounts, look for unusual sign-ins, new inbox rules, unfamiliar recovery details and messages sent without your knowledge. If money, client data or business systems are involved, keep a written timeline of what happened, who noticed it, what was clicked and which accounts may be affected.
IT Life-Raft can help turn the incident into a clear recovery plan: secure the accounts, review devices, check backups, reduce repeat risk and explain the next steps without jargon. The aim is not to panic; it is to regain control, protect evidence and make the business safer than it was before the incident.
Useful next steps include reviewing Microsoft 365 security settings, checking endpoint protection, confirming backup coverage, tightening administrator access and training staff to spot follow-up scams. A good recovery also includes prevention, because attackers often try again once they know an account or business has been vulnerable.
More detail
A plain-English hacked-account checklist for Scottish individuals and small businesses who need calm first steps before resetting passwords, deleting messages or paying anyone suspicious.
This guidance is written for a stressful moment: strange logins, missing emails, locked files, changed bank details, unexpected MFA prompts, or customers receiving messages you did not send.
Step 1: slow the incident down
- Disconnect affected computers or phones from the internet if you suspect malware or remote control.
- Do not pay a ransom or send money because a message tells you to.
- Do not delete emails, chat messages, invoices or security alerts — they may be evidence.
- If bank payments may be involved, contact your bank using a trusted number.
Step 2: protect the accounts that matter most
For many small businesses, the most urgent accounts are email, Microsoft 365, banking, website admin, accounting software and social media. Change passwords from a clean device, enable multi-factor authentication, check forwarding rules and review recent sign-ins.
Common hacked-account signs in Scotland
- Microsoft 365 or email login alerts you do not recognise.
- Invoices or payment details being changed.
- Customers receiving strange emails from your address.
- Files being renamed, encrypted or missing.
- New mailbox forwarding rules or unknown admin users.
What IT Life-Raft can help with
- Microsoft 365 account checks and emergency lock-down.
- Email compromise investigation and mailbox rule review.
- Device isolation and practical next steps.
- Backup and recovery planning after an incident.
- Plain-English advice before you reset or delete the wrong thing.
Local note for Scotland
Relevant for Scottish small businesses dealing with suspicious logins, invoice fraud, ransomware warnings, compromised Microsoft 365 accounts or customer-data concerns.
Useful official reporting routes
- Report cyber crime and fraud through Action Fraud where appropriate.
- Forward suspicious emails to the UK NCSC Suspicious Email Reporting Service.
- If personal data may be involved, keep notes so you can decide whether ICO guidance applies.
FAQ
Should I turn everything off?
If you think malware or remote access is active, disconnect the affected device from the internet. Avoid wiping or reinstalling until useful evidence has been captured.
Should I change my Microsoft 365 password first?
Change it from a clean device, then check MFA, sign-in history, mailbox rules, app passwords and admin users. A password change alone may not be enough.
Can you help if I am in Scotland?
Yes. IT Life-Raft can provide remote first-response guidance and practical next steps for hacked accounts, Microsoft 365 issues, email compromise and small-business cyber incidents.
Been Hacked next steps
Been Hacked should be reviewed in a practical way: check the current setup, confirm who owns each system and decide which improvements reduce the most risk. IT Life-Raft uses Been Hacked guidance to turn technical concerns into clear actions for small businesses.
If Been Hacked is already on your mind, the useful next step is to document what is working, what is fragile and what would cause disruption if it failed. That makes the improvement plan easier to prioritise and easier for staff to follow.
