Illustration of a laptop with a warning shield and alert icons representing signs a business has been hacked

9 Signs Your Business Has Been Hacked (And What to Check First)

Table of Contents

If something on your business systems feels off, a locked account, a strange email your customers mention, a laptop that has slowed to a crawl, it is worth taking seriously rather than waiting to see if it happens again. This guide is for UK business owners and office managers without a dedicated IT team who need to work out, quickly, whether what they are seeing points to a genuine compromise. It sets out the nine most common warning signs, what each one usually means, and exactly what to check before you decide whether to call for help.

Quick answer: The clearest signs your business has been hacked are unfamiliar login alerts, staff locked out of accounts they haven’t changed, customers receiving emails from you that you didn’t send, unauthorised payments leaving your accounts, and devices that suddenly run slowly or behave strangely. One sign on its own is often nothing. Two or more appearing together, especially login alerts combined with unusual email activity, is a strong reason to stop, isolate the affected device or account, and get it checked straight away.

In this guide: the nine warning signs to watch for, a short diagnostic sequence for checking each one, guidance on when a single sign is worth worrying about, and what to do first if you think your business has genuinely been compromised.

Why these signs get missed

The National Cyber Security Centre (NCSC) notes that cyber attacks against businesses often start quietly, with small, easy to dismiss changes rather than an obvious break-in. A slightly slower laptop gets blamed on age. An odd email gets marked as spam and forgotten. A login alert gets closed without a second look because everyone is busy. Individually, none of these feel urgent. Together, they are usually how a compromise is first noticed, which is why it helps to know what to look for and to take more than one sign seriously when they appear close together.

9 signs your business may have been hacked

Not every sign below means you have definitely been compromised. Several have innocent explanations. What matters is checking rather than assuming, particularly if you notice more than one at the same time.

  • A login alert or sign-in notification you don’t recogniseMicrosoft 365, Google Workspace and most banking and accounting platforms send an alert when an account is accessed from a new device or location. A notification you didn’t trigger is one of the clearest signs of unauthorised access.Check: review the account’s recent sign-in activity and look for locations, devices or times that don’t match how your business actually works.
  • Staff locked out of accounts they haven’t changedAttackers who gain control of an account will often change the password to lock the real owner out and buy themselves time before anyone notices.Check: confirm with the staff member that they genuinely haven’t reset it, then use your admin console to check when and from where the password was last changed.
  • Customers or contacts receiving emails from you that you didn’t sendThis is one of the most common signs of business email compromise. If a customer mentions a strange invoice, payment request or link “from you” that you never sent, treat it as a serious indicator, not a one-off mistake.Check: look in your sent folder and email rules for anything unfamiliar, and check for new auto-forwarding rules you didn’t set up.
  • Unauthorised payments leaving your business accountThe NCSC lists this as one of the core signs of a live compromise. Even a small unrecognised payment can indicate that banking credentials or an approval process has been compromised.Check: review recent transactions and standing payments with your finance team or bookkeeper, and query anything unfamiliar immediately with your bank.
  • A device behaving slowly or unexpectedlyMalware and unauthorised background processes consume processing power, which can make a device that used to run normally suddenly feel sluggish, freeze, or restart on its own. This alone is common and often has an innocent cause, but combined with anything else on this list it is worth investigating.Check: look at what’s running in Task Manager or Activity Monitor for unfamiliar processes using unusually high CPU or network activity.
  • New user accounts, admin accounts, or software you didn’t set upAttackers who gain a foothold often create a second account for themselves so they can get back in even if the original compromised account is secured.Check: review the full user and admin account list in your email platform, accounting software and website admin, not just the ones you use day to day.
  • Antivirus or security software disabled without anyone doing it manuallyDisabling security tools is a common step attackers take to avoid detection once they have access to a device.Check: confirm your antivirus or endpoint protection is running and up to date on every device, and ask whether anyone in the business turned it off deliberately.
  • Files that won’t open, have been renamed, or carry an unfamiliar extensionThis is a strong indicator of ransomware, particularly if it affects multiple files at once or is accompanied by a ransom note.Check: do not try to open or rename the files yourself. Disconnect the affected device from the network and get it looked at before doing anything else.
  • An unexplained spike in data usage, network traffic, or your hosting billA compromised system is sometimes used to send spam, mine cryptocurrency, or move data out of your network, all of which show up as unusual outbound traffic or a jump in resource usage.Check: compare your current hosting, bandwidth or cloud usage against a normal month and ask your provider to flag anything unusual.

What to check first

If you’ve spotted one of the signs above, this is roughly the order to work through before deciding whether to escalate. None of this replaces a proper investigation, it’s a first pass to help you judge how seriously to treat what you’ve noticed.

What you noticedWhat to check first
Unfamiliar login alertSign-in activity log for that account, plus whether MFA is enabled
Locked out accountPassword reset history in your admin console, and whether it matches a genuine reset
Strange emails “from you”Sent folder, email rules and auto-forwarding settings
Unrecognised paymentBank and accounting transaction history, and your payment approval process
Slow or erratic deviceRunning processes and antivirus status on that specific device

When one sign is enough to worry about

A single slow laptop is rarely a reason to panic. A single unrecognised payment, a login alert you can’t explain, or files you can no longer open are different. In our experience, the cases that turn into a serious incident are usually the ones where an early, isolated sign was noticed and then put down to a technical glitch rather than checked. As a general rule, treat any of the following as worth acting on immediately, on their own: an unauthorised payment, files that appear encrypted or renamed, or a login alert from a location or device nobody in the business recognises.

What to do next if you think you’ve been hacked

If your checks confirm something genuinely looks wrong, the priority is to contain it before you try to fix it.

  1. Isolate the affected device or account. Disconnect the device from your network, or suspend the affected account, rather than continuing to use it while you investigate.
  2. Change passwords from a different, unaffected device. Prioritise email, banking and any account with admin access, and enable multi-factor authentication if it isn’t already on.
  3. Tell your IT support provider or security team. Give them what you’ve found so far so they can confirm the scope of the compromise rather than starting from nothing.
  4. Follow a structured response from there. Our guide on what to do after a data breach covers containment, assessing what data was affected, and the ICO reporting process step by step if personal data may be involved.

Scope note: This guide helps you recognise the signs of a possible compromise and carry out a first check. It is not a substitute for a full forensic investigation. If you confirm unauthorised access, particularly to financial systems or personal data, treat it as a genuine incident and get it professionally investigated rather than relying on your own checks alone.

Frequently asked questions

Is a slow computer always a sign of hacking?

No. Ageing hardware, too many browser tabs, pending updates and low disk space are far more common causes of a slow device than malware. Treat a slow device as one data point rather than proof, and look for it alongside other signs such as unfamiliar processes running or antivirus being disabled.

What’s the first thing I should do if I think my business has been hacked?

Isolate the affected device or account rather than continuing to use it, change related passwords from a separate, unaffected device, and contact your IT support provider with what you’ve found. Avoid deleting anything or trying to fix it yourself first, since that can make an investigation harder.

Do I need to report a suspected hack to the ICO?

It depends on whether personal data has been affected and the level of risk to the people concerned. Our guide to what to do after a data breach covers the ICO reporting deadline and process in detail once you’ve confirmed what’s happened.

Recognising these signs early is one part of staying protected. It’s worth pairing this with wider prevention, including staff awareness of phishing attacks, understanding business email compromise, and running a periodic cyber security risk assessment so you know what normal looks like on your systems before anything goes wrong.

Think Your Business Has Been Compromised?

UK IT Services can investigate suspected compromise, confirm what happened, and secure your systems.

Talk to Our Cyber Security Team

Table of Contents