Your Business Was Just Hacked. Here Is What to Do in the First Hour.
The instinct is to fix it fast: reboot the computer, delete the bad email, change every password. Almost all of that makes things worse. The first hour is about stopping the spread and preserving what you will need, not cleaning up. Here is the order that actually helps.
By The CyberBadger Team, Incident response, Hamilton and Burlington, ON·
The first rule: stop, do not clean up
The natural response to a breach is to make it disappear. Reboot the machine, delete the bad email, run an antivirus scan, change every password. Nearly every one of those instincts destroys something you are going to need. Rebooting wipes the memory that holds the running malware and, with ransomware, the encryption keys that might get your files back. Deleting the phishing email throws away the evidence of how they got in. The first hour is triage, not repair.
A calmer way to think about it: right now you are a witness at a scene, not the cleanup crew. Your job in the first hour is to contain the spread and preserve what happened, so the root cause can be found and the door can be shut. Slow down for sixty seconds and it will save you days.
Isolate the machine, but leave it powered on
Unplug the affected computer from the network, or turn off its Wi-Fi. That stops malware spreading to other machines and cuts an attacker's live connection. But leave it powered on. Shutting it down erases the memory, which often holds the running malware, the attacker's network connections, and, with ransomware, keys that only exist while the machine is on.
There is one exception. If you can see files being actively encrypted in front of you, right now, powering the machine down can stop the spread and limit the loss. If you are not sure, isolate it from the network, leave it on, and get help. Whatever you do, do not reboot it to try to clean it.
Preserve the evidence before you change anything
Take photos with your phone of whatever is on screen: ransom notes, error messages, suspicious emails, changed invoices. Write down the times you first noticed each thing. Do not delete the ransom note, the phishing email, or anything else, however much you want it gone. It is all evidence, and you may need it to recover, to file a police report, and to support an insurance claim.
If you are about to remove something an attacker set up, a mailbox forwarding rule, an unfamiliar connected app, a new admin user, screenshot it first, then remove it. Once it is gone, the record of what they did is gone with it.
Assume your email is being read, and change channels
If any account was compromised, treat your email and chat as if the attacker is reading them, because they may be. Coordinate your response by phone or a personal account, not the mailbox that may be hacked. Attackers who watch you respond move faster, and payment-redirect fraud often runs entirely through a mailbox the owner still believes is private. Tell your team out of band to hold any payment or login request until you say otherwise.
If money moved, the clock is already running
For a fraudulent wire, e-transfer, or a payment sent to changed banking details, call your bank's fraud line immediately, using the number on your card or the bank's own website, never a number from the suspicious email. Ask them to try to stop or recall the payment. Recovery is possible but time-sensitive, and the window is measured in hours, not days, so this comes before almost everything else.
Then report the fraud to the Canadian Anti-Fraud Centre and your local police (Canadian Anti-Fraud Centre). Speed does not guarantee the money comes back, but it is what gives you a chance.
If an email or account was taken over
In a cloud incident the attacker's foothold is usually an identity, not a device, so the containment happens in the account, not the computer. From a different, clean device: reset the password, sign out of all sessions (a password change on its own does not kick out a stolen login), turn on app-based multi-factor authentication, and remove any forwarding rules, connected apps, or extra users you do not recognize.
Do the same for the email account those other logins are tied to, because it is the master key that resets everything else. Once things are stable, it is worth checking whether your domain is easy to impersonate in the first place, our SPF and DMARC checker and a free BadgerScan run will show you where you stand.
If it is ransomware
Do not pay, and do not reply to the attacker. Authorities advise against paying: it does not guarantee your files come back, it funds more attacks, and it marks you as someone who pays (CISA). Preserve the ransom note and one encrypted file, isolate the affected machines, and get help before you rebuild anything.
How they got in usually matters more than the encryption itself, and modern ransomware very often steals a copy of your data before it locks it, so paying would not undo the exposure. Recovery from clean, offline backups is frequently possible, which is one more reason not to rush into paying.
Tell your insurer, then report it
If you carry cyber insurance, notify your broker or the insurer's breach line early, often within 24 to 72 hours, and before you hire anyone permanently or wipe anything. Many policies require you to use their approved responders, and working outside that can affect your coverage. What is covered is your insurer's decision, so confirm the requirements with your broker first.
If personal information about customers or staff was exposed, Canadian privacy law may require you to report the breach to the Office of the Privacy Commissioner and notify the people affected where there is a real risk of significant harm, and to keep records (priv.gc.ca). Whether your situation meets that test is a legal question for your counsel; keep good records and flag it early either way.
The mistake that costs businesses the most
The most expensive error we see is not a technical one. It is spending the first hour on the wrong thing: unplugging and staring at the one computer you have already isolated, while the attacker is still inside your cloud email and your customers are being messaged from your own account. If the incident lives in Microsoft 365, Google Workspace, your accounting software, or your social accounts, the urgent work is in those accounts, and most of it can be done remotely, right now. The physical computer is evidence; it can be examined later.
That is the whole reason to get a second set of eyes early, even for fifteen minutes. A calm outside read of what is actually happening, versus what feels most alarming, is often the difference between a bad afternoon and a bad month.
When to call for help, and what it should cost
You do not need to have it figured out before you call. A good responder starts by confirming what is actually happening, tells you the next few steps, and agrees a fixed price with you before any paid work begins, so there are no surprises while you are already stressed. Be wary of anyone who quotes an open-ended hourly meter for an emergency, or who promises to recover your data or guarantees an outcome; honest responders describe the work, not the result.
If you would rather have local people handle it, CyberBadger does emergency incident response for small businesses across Canada, out of Hamilton and Burlington and mostly remotely. If you are in the middle of something right now, start here.
In the middle of an incident right now?
Call and tell us what is happening. We will tell you the first steps to take and agree a fixed price with you before any paid work begins. Local to Hamilton and Burlington, remote across Canada.
Run a free security scanFrequently asked questions
My business was just hacked. What should I do first?
Do not reboot the machine or delete anything. Unplug the affected computer from the network but leave it powered on, take photos of what you see, and if any money moved, call your bank's fraud line right away. The first hour is about containing the spread and preserving evidence, not cleaning up. Then get help to work out how they got in.
Should I turn off a computer that has ransomware?
Usually no. Isolate it from the network but leave it powered on, because shutting it down wipes memory that can hold encryption keys and evidence. The one exception is if you can see files being actively encrypted right now, where powering off can limit the loss. When you are unsure, isolate it and leave it on, then get help before rebuilding.
Someone hacked our email and is messaging our customers. What do I do?
Treat the mailbox as if the attacker is reading it and switch to phone or a personal account. From a clean device, reset the password, sign out of all sessions, turn on app-based multi-factor authentication, and remove any forwarding rules or connected apps you do not recognize. Warn your customers through a channel you control not to act on any payment request without verifying it by phone.
We were tricked into wiring money to a scammer. Can we get it back?
Sometimes, if you move fast. Call your bank's fraud line immediately, using the number on your card rather than any number from the email, and ask them to try to stop or recall the payment. The recovery window is hours, not days. Report it to the Canadian Anti-Fraud Centre. There is no guarantee, but speed is what gives you a chance.
Do I have to report a data breach in Canada?
Possibly. Under Canadian privacy law, a breach of security safeguards must be reported to the Office of the Privacy Commissioner, and affected individuals notified, where there is a real risk of significant harm, with records kept. Whether your situation meets that test is a legal question for your counsel, so flag it early and keep good records.
Should I pay the ransom?
Authorities advise against it. Paying does not guarantee you get your files back, it funds more attacks, and it marks you as someone who pays. Preserve the ransom note and get help before deciding anything. Recovery from clean backups is often possible, and modern ransomware frequently steals data too, so paying would not undo the exposure.
How much does incident response cost for a small business?
It varies with severity. A responsible firm confirms what is happening first and agrees a fixed price with you before any paid work, so you know the cost up front instead of facing an open-ended hourly meter while you are panicking. Ask for the price before you agree to anything, and be cautious of anyone who guarantees they will recover your data.