Signs your business has been hacked aren’t always dramatic. Most business compromises don’t announce themselves with a flashing warning screen, they show up as small, easy-to-dismiss oddities: a login you don’t recognize, a file that looks slightly different, an employee mentioning a weird email. Businesses are often compromised for days or weeks before anyone notices, and the earlier a breach is caught, the less damage it does. This guide walks through the practical warning signs to watch for, what to do if you spot them, and how to reduce the odds of it happening in the first place.
One important note before we start: spotting one of these signs doesn’t automatically mean you’ve been breached. Software glitches, expired passwords, and simple human error can look similar. What matters is paying attention when something feels off and checking it out rather than assuming it’s nothing.
10 Signs Your Business Has Been Hacked
1. Unexpected Password Changes or Locked Accounts
If you or an employee suddenly can’t log into an account with the correct password, or receive a “your password was changed” notification you didn’t request, someone else may have taken control of that account. Next step: try to recover the account immediately through the provider’s official recovery process, and check whether the same login credentials are reused anywhere else if so, change those too.
2. Suspicious Login Activity
Many business tools (Microsoft 365, Google Workspace, banking portals) log login locations and times. A login from an unfamiliar country, an odd hour, or a device you don’t recognize is worth investigating even if the login was ultimately successful with a correct password. Next step: review login logs regularly and enable login alerts wherever the option exists.
3. Unusual Emails Sent From Employee Accounts
If customers, vendors, or coworkers report receiving strange emails “from” you or your staff, often asking for money, gift cards, or login details — an email account may be compromised and being used to impersonate its owner. Next step: change that account’s password immediately, enable multi-factor authentication, and notify anyone who may have received the suspicious messages.
4. Files Disappearing, Changing, or Becoming Encrypted
Files that suddenly won’t open, have unfamiliar extensions, or are simply missing can indicate ransomware or unauthorized access. If a ransom note appears demanding payment for a decryption key, this is a confirmed ransomware event. Next step: disconnect the affected device from the network immediately and do not attempt to pay or negotiate before consulting a professional.
5. Unexpected Software or Applications Appearing
New programs, browser extensions, or scheduled tasks that no one on your team installed are a common sign of malware, which attackers often use to maintain access after an initial breach. Next step: don’t run or open the unfamiliar program, have it inspected by IT before removing it, since removal alone doesn’t tell you how it got there.
6. Slow Systems or Unusual Network Activity
A sudden, unexplained slowdown across multiple devices, or a spike in outbound network traffic when no one is doing anything unusual, can indicate malware running in the background or data being exfiltrated. Next step: have your IT provider check network traffic logs rather than just restarting the affected machines.
7. Strange Pop-Ups or Browser Behavior
Fake virus warnings, browser homepages that changed without your input, or new toolbars nobody installed are classic signs of adware or malware. Next step: avoid clicking anything in the pop-up itself, including “close” buttons that may trigger a download, close the browser via the taskbar instead and run a legitimate security scan.
8. Unauthorized Financial Transactions
Payments, wire transfers, or purchases you don’t recognize on business bank or credit accounts are a serious red flag, particularly if they follow a phishing email or a compromised email thread with a vendor. Next step: contact your bank immediately to freeze the account and dispute the transaction, and separately investigate how the fraud was initiated.
9. Customers or Employees Reporting Suspicious Messages
If people outside your IT team start telling you they received odd emails, texts, or calls that reference real details about your business, take it seriously, this is often the first external sign that something inside your systems has been compromised. Next step: ask for a screenshot or forward of the message, and treat it as a possible indicator until ruled out.
10. Security Tools Being Disabled or Alerts Being Triggered
If antivirus software, firewalls, or monitoring tools are unexpectedly turned off, or you start receiving security alerts you didn’t trigger yourself, an attacker may be actively trying to disable your defenses to avoid detection. Next step: treat this as an active incident, not routine IT maintenance, and contact a cybersecurity professional right away.
What To Do If You Think Your Business Has Been Hacked
- Isolate affected devices — disconnect from the network (Wi-Fi or ethernet) rather than shutting them down, to preserve evidence.
- Avoid deleting anything — files, emails, or logs that look suspicious may be needed to understand how the breach happened.
- Change compromised credentials safely — from a separate, known-clean device, not the potentially compromised one.
- Contact IT or cybersecurity professionals — early involvement limits how far an incident spreads.
- Review accounts and logs — look for other accounts or systems that may have been accessed using the same compromised credentials.
- Check your backups — confirm you have a clean, recent, restorable copy of your data before making further changes.
- Assess whether customer or employee data may be affected — this determines what notification obligations may apply.
- Consider legal and regulatory notification requirements — data breach laws vary by state and industry, so this is worth a professional review rather than a guess.
How Businesses Get Hacked in the First Place
- Phishing — deceptive emails or messages designed to trick someone into clicking a link or entering credentials.
- Weak or reused passwords — a password compromised on one site can unlock accounts elsewhere if reused.
- Stolen credentials — usernames and passwords leaked in unrelated breaches are frequently reused against other targets.
- Unpatched software — known vulnerabilities in outdated systems are an easy, automated target for attackers.
- Malware and ransomware — malicious software delivered through email attachments, downloads, or compromised websites.
- Compromised third-party accounts — a vendor or contractor with access to your systems can become an entry point if their own security is weak.
- Remote access vulnerabilities — poorly secured remote desktop or VPN access is a common target for automated scanning attacks.
How To Prevent a Business Hack
- Multi-factor authentication (MFA) on email, financial accounts, and remote access.
- Strong, unique password policies supported by a password manager.
- Regular employee cybersecurity training focused on phishing recognition.
- Consistent patching and software update schedules.
- Endpoint protection across all business devices, not just servers.
- Secure, tested backups that are verified to actually restore data.
- Network security measures like firewalls and segmentation.
- Access controls based on least privilege, employees get only the access they need.
- Ongoing security monitoring rather than a one-time setup.
- Periodic cybersecurity assessments to catch gaps before an attacker does.
When To Call a Cybersecurity Professional
If you’re seeing any combination of the warning signs above, or simply aren’t confident your current setup would catch a breach in progress, that’s a reasonable moment to bring in outside expertise. A cybersecurity professional can investigate suspicious activity with the right tools, help determine the scope of an incident, and, just as importantly, assess whether your defenses are strong enough to catch the next attempt before it succeeds.
PDS Consulting provides cybersecurity monitoring and management and managed detection and response (MDR) for businesses across East Tennessee, giving you a team actively watching for exactly these warning signs rather than discovering them after the fact. If you suspect something is wrong, or simply want a clear picture of where your business stands, a conversation with our team costs nothing and could save you from a much more expensive problem later.
Frequently Asked Questions
What is the fastest way to tell if my business has been hacked?
Look for a cluster of unusual signs happening together, unexpected logins, files you didn’t touch changing or disappearing, employees receiving strange emails “from” your company, or security tools suddenly disabled. One odd event alone might be nothing; two or three together in a short window is a strong signal worth investigating immediately.
Should I turn off my computers if I think I've been hacked?
Disconnect affected devices from the network (unplug the ethernet cable or turn off Wi-Fi) rather than shutting them down completely. Powering off can erase evidence in memory that a security professional needs to figure out what happened and how to stop it from happening again.
How do I know if it's ransomware or something else?
Ransomware is usually unmistakable, files become inaccessible, extensions change, and a ransom note appears demanding payment for a decryption key. Other types of compromise, like a stolen password or a quiet data breach, are often far less obvious and may only show up as unusual login activity or unexplained account changes.
Do I have to report a business hack to anyone?
It depends on your industry, location, and what data was affected. Many states require notification if customer personal data was exposed, and certain industries (healthcare, finance) have additional regulatory reporting requirements. When in doubt, a cybersecurity professional or attorney can help you determine your specific obligations.
Can a small business really be a target, or is this mostly a big-company problem?
Small businesses are frequently targeted specifically because attackers assume they have weaker defenses and no dedicated security team watching for threats. Many attacks are automated and don’t discriminate by company size — they simply look for whichever door is unlocked.



