Insights

Would Your Business Know It Had Been Hacked?

Ten warning signs that could reveal a hidden cyberattack, and the practical steps small businesses can take to detect and respond sooner.

A Plainsight Security consultant showing a business owner the warning signs that their business has been hacked.

Some cyberattacks are impossible to miss. Files become encrypted, systems stop working and a ransom note appears on the screen.

Others are deliberately quiet.

An attacker may spend days or weeks reading emails, searching cloud storage, learning how payments are authorised or creating alternative ways to access the business. There may be no obvious disruption while this is happening.

The absence of a ransom note does not mean the business is secure. The more important question is: if somebody gained access today, how and when would you notice?

Why attackers try to remain hidden

An attacker who reveals their presence immediately may lose access before achieving their objective. Remaining undetected gives them time to understand how the organisation operates and identify the most valuable opportunity.

An attacker might use continued access to:

  • Monitor an invoice conversation before changing the bank details
  • Read emails so they can imitate a director or supplier convincingly
  • Search cloud storage for commercially sensitive information
  • Identify users with administrative access
  • Learn how payments are requested and approved
  • Obtain passwords and other credentials
  • Use one compromised account to target other employees
  • Create additional routes back into the business
  • Wait until backups or security controls have been weakened

The longer the compromise remains undetected, the more opportunity the attacker has to explore the environment, steal information and cause damage.

Ten warning signs your business may have been compromised

No single warning sign proves that a cyberattack has taken place. However, unexplained or unusual activity should be investigated, particularly when several indicators appear together.

1. Unexpected multi-factor authentication prompts

An unexpected multi-factor authentication prompt can mean that somebody already has the correct password and is attempting to complete the sign-in process.

Warning signs include:

  • Repeated approval prompts that the user did not initiate
  • Requests arriving outside normal working hours
  • Prompts showing an unfamiliar location
  • Telephone calls asking someone to approve a request
  • An authentication prompt appearing after a suspicious email or website visit

Attackers sometimes use a technique known as MFA fatigue. They repeatedly send authentication requests in the hope that the user will eventually approve one to make the notifications stop.

Employees should never approve an unexpected request. They should reject it and report it immediately.

2. New or unexpected inbox rules

An attacker with access to an email account may create inbox rules to hide their activity or monitor important conversations.

These rules can be used to:

  • Forward emails to an external address
  • Delete security alerts
  • Hide replies from suppliers or customers
  • Move financial conversations into obscure folders
  • Mark selected messages as read
  • Conceal password-reset notifications
  • Redirect messages containing words such as “invoice” or “payment”

When an email compromise is suspected, check mailbox forwarding, inbox rules, shared-mailbox access, delegates and any applications with permission to read email.

Do not assume the account is secure simply because its password has been changed. A forwarding rule or malicious application permission may continue operating after the reset.

3. Unfamiliar sign-ins

Sign-in records can provide some of the earliest evidence that an account has been compromised.

Potential indicators include:

  • Access from unexpected countries or regions
  • Sign-ins from unfamiliar IP addresses
  • Activity at unusual times
  • New devices or browsers
  • Apparently impossible travel between distant locations
  • Use of older authentication methods
  • Numerous failed attempts followed by a successful login

An unfamiliar location is not conclusive by itself. Mobile networks, corporate VPNs and cloud services can make a legitimate user appear to be somewhere else.

The activity should be assessed in context. Consider whether the device is recognised, whether the timing makes sense, what authentication method was used and what the account did after signing in.

4. Disabled or malfunctioning security tools

Attackers may try to disable the systems that could detect or obstruct them.

Targets can include:

  • Antivirus or endpoint protection
  • Local firewalls
  • Security logging
  • Backup agents
  • Email filtering
  • Browser protections
  • Security notifications
  • Automatic updates

Warning signs could include a device unexpectedly reporting that protection is inactive, a computer disappearing from a management console or a security policy being changed without authorisation.

Security tools can fail for innocent reasons. Software faults, expired licences and configuration problems can all cause loss of protection. However, an unexplained failure should not be dismissed until the cause has been established.

5. New administrator accounts or permission changes

Attackers often seek administrative privileges because they provide wider access and make it easier to disable controls or create persistent access.

Look for:

  • New administrator accounts
  • Existing users unexpectedly receiving additional privileges
  • New Microsoft 365 Global Administrators
  • Users added to local administrator groups
  • Changes to security groups
  • New mailbox delegates
  • Unfamiliar MFA methods
  • Newly registered applications
  • Service accounts receiving excessive permissions

Privileged access should be reviewed regularly rather than only during an incident. Every administrator account should have an identified owner and a legitimate business purpose.

An account that nobody recognises should be treated seriously, especially if it was created outside normal working hours or used to change security settings.

6. Unexplained file changes or encryption

Ransomware does not always affect the entire organisation at once. Encryption may initially be limited to one computer or shared folder.

Possible warning signs include:

  • Files that will no longer open
  • Unfamiliar file extensions
  • Large numbers of files being modified at the same time
  • Ransom notes appearing in folders
  • Missing directories
  • Unusually high storage or network activity
  • Backups being deleted
  • Shared drives becoming unavailable
  • Documents being replaced or corrupted

If active encryption is suspected, isolate the affected device from wired and wireless networks immediately. Early containment may prevent the malware from reaching shared storage, other computers or backup systems.

Do not immediately wipe or rebuild the device. It may contain evidence needed to establish how the attack happened and determine whether other systems are affected.

7. Unusual payments or changes to bank details

Some compromises are designed specifically to redirect money.

Financial warning signs include:

  • A supplier unexpectedly changing its payment details
  • A director requesting an urgent and confidential payment
  • Duplicate or unfamiliar invoices
  • Payments requested outside the normal approval process
  • Changes to employee payroll details
  • Small test transactions
  • Customers receiving alternative bank instructions
  • Requests that discourage telephone verification

An attacker may send the request from a genuine compromised mailbox. Checking the visible sender address is therefore not enough.

Changes to payment details should be verified using a trusted telephone number already held on file, not one contained in the email requesting the change.

Urgency, confidentiality and pressure to bypass normal checks are particularly important warning signs.

8. Customers or suppliers receive strange messages

A business may first learn that it has been compromised from somebody outside the organisation.

Customers or suppliers might report:

  • Unexpected invoices
  • Unusual file-sharing links
  • Requests to change bank details
  • Messages written in an unfamiliar style
  • Phishing emails sent from a genuine company account
  • Unexpected password-protected attachments
  • Conversations that the employee does not remember having

External reports should not be dismissed simply because the suspicious message appears in the employee’s sent items. An attacker using the genuine account may be able to send messages, reply within existing conversations and delete evidence afterwards.

Give customers, suppliers and employees a clear way to report suspicious communications. A report received quickly may prevent other recipients from acting on the same fraudulent message.

9. Missing, disabled or altered logs

Security logs can help establish:

  • Which accounts were accessed
  • Where sign-ins originated
  • What settings were changed
  • Which files were opened
  • How long the attacker may have been present
  • Whether access is continuing

Warning signs include:

  • Unexpected gaps in logging
  • Audit settings being disabled
  • Log-retention periods being reduced
  • Security events being deleted
  • Devices suddenly stopping communication with monitoring systems
  • System time settings being changed

Missing logs do not automatically prove that an attacker has interfered with them. Storage problems, licensing changes and configuration faults can also affect logging.

However, an unexplained loss of visibility is a security concern in its own right. Without suitable logs, the business may be unable to determine what happened or whether the attacker still has access.

10. Suspicious remote-access activity

Attackers may use remote access to control systems while appearing similar to a legitimate employee or IT provider.

Possible warning signs include:

  • Unexpected Remote Desktop sessions
  • New remote-management software
  • Access outside normal working hours
  • Connections from unfamiliar locations
  • Unexplained mouse or keyboard movement
  • New VPN accounts
  • Remote-management tools running unexpected commands
  • Remote sessions connecting to several devices
  • Remote-access alerts being disabled
  • Existing support tools being used by unfamiliar operators

Legitimate remote monitoring and management software can be particularly attractive to attackers. It may already be trusted by the organisation and allowed through its security controls.

Every approved remote-access tool should have an identified owner, a legitimate purpose and appropriate access restrictions.

Individual warning signs may have innocent explanations

Many indicators of compromise also have legitimate causes.

For example:

  • Business travel can generate an unfamiliar sign-in
  • An IT provider may create an administrator account
  • A software update may temporarily disable protection
  • A legitimate application may create an inbox rule
  • A failed backup agent may stop sending logs
  • A support engineer may connect outside normal hours

The level of concern increases when:

  • Nobody can explain the activity
  • Several warning signs appear together
  • The activity occurs outside normal working patterns
  • The affected account has administrative access
  • Financial, customer or employee information is involved
  • Security controls were changed at the same time
  • Similar activity appears across several accounts or devices

The answer is not to treat every unusual event as a confirmed attack. It is to investigate it rather than dismissing it without explanation.

A realistic example: the quiet mailbox compromise

Consider a common business email compromise:

  1. An employee receives a convincing Microsoft 365 phishing email.
  2. They follow the link and enter their password into a fake login page.
  3. The attacker signs in and registers an additional MFA method.
  4. An external forwarding rule is created.
  5. Security messages are moved automatically into the deleted-items folder.
  6. The attacker monitors conversations with an important supplier.
  7. A genuine invoice is intercepted and replaced with new bank details.
  8. The altered payment request is sent from the employee’s real email account.
  9. The business pays the invoice into the attacker’s account.
  10. The incident is discovered only when the genuine supplier chases the unpaid invoice.

From the employee’s perspective, the mailbox may have continued working normally. There was no ransom note and no obvious malware alert.

Several warning signs could nevertheless have exposed the compromise earlier:

  • Unexpected MFA activity
  • An unfamiliar sign-in
  • A new forwarding rule
  • Changed authentication information
  • Unusual mailbox access
  • Altered payment instructions

The attack succeeded not because it was technically sophisticated, but because nobody noticed or investigated those changes.

Where should a small business look for evidence?

The appropriate checks will depend on the systems used by the organisation. Common sources of evidence include the following.

Microsoft 365 and other cloud services

Review:

  • Sign-in activity
  • Audit logs
  • MFA registrations
  • Mailbox forwarding
  • Inbox rules
  • Administrator roles
  • Application and OAuth permissions
  • Active sessions
  • External file sharing
  • Security and compliance alerts

Look beyond the first suspicious sign-in. Check what the account did afterwards, which services it accessed and whether any security settings were changed.

Computers and servers

Review:

  • Endpoint-security alerts
  • Newly installed software
  • Recently created accounts
  • Administrator-group membership
  • Unusual running processes
  • Remote-access activity
  • File modifications
  • Security-service status
  • Scheduled tasks and automatic start-up items

An isolated alert on one device may be part of a wider incident. Check whether the same file, process, address or account appears elsewhere.

Firewalls and remote access

Review:

  • VPN connections
  • Remote Desktop exposure
  • New firewall rules
  • Unexpected outbound connections
  • Administrative logins
  • Configuration changes
  • Connections outside normal hours
  • New or changed remote-access accounts

Internet-facing remote-access services should receive particular attention because they are common entry points for attackers.

Financial and payroll systems

Review:

  • New payees
  • Changed supplier details
  • Unusual payments
  • Changes to approval workflows
  • Recently created users
  • Payroll amendments
  • Failed and successful sign-in activity
  • Changes made outside normal working hours

If fraudulent activity is suspected, contact the bank or payment provider immediately. The chance of recovering funds can reduce rapidly with time.

What should employees report?

Employees are often the first people to notice that something is wrong. They should be encouraged to report:

  • Unexpected MFA prompts
  • Password-reset messages they did not request
  • Security warnings
  • Missing or moved emails
  • Messages in their sent folder that they did not write
  • Suspicious payment requests
  • Strange behaviour on their computer
  • Unexpected account lockouts
  • Calls requesting passwords or authentication codes
  • Customers questioning messages the employee did not send
  • Changes to settings they do not remember making

Employees should be thanked for reporting concerns promptly, even if they clicked a link or entered a password.

A blame-focused culture encourages people to conceal mistakes and delay asking for help. A quickly reported error can often be contained. The same event discovered several weeks later may have become a serious breach.

What should you do if something looks suspicious?

If you identify a possible warning sign:

  1. Do not ignore or dismiss it.
  2. Record what was observed and when.
  3. Preserve suspicious messages, screenshots and alerts.
  4. Contact the person responsible for IT or security.
  5. Isolate affected devices if malicious activity appears to be active.
  6. Disable compromised accounts or revoke sessions where appropriate.
  7. Reset exposed credentials from a known-clean device.
  8. Check for the same activity elsewhere.
  9. Protect unaffected accounts, systems and backups.
  10. Obtain specialist assistance if the scope is unclear.

Avoid deleting suspicious files, wiping computers or making large numbers of uncontrolled changes. These actions can destroy evidence and make the incident more difficult to investigate.

For a more detailed initial response sequence, see Cyber Incident Response for Small Businesses: Your First 60 Minutes.

How can businesses improve detection?

Enable appropriate logging

Important systems should record authentication activity, administrative changes, security alerts and access to sensitive information.

Logging should cover cloud services as well as traditional computers and servers. For many small businesses, Microsoft 365, cloud storage and online financial platforms hold some of their most important information.

Retain logs for long enough

An incident discovered today may have started weeks or months ago. Logs retained for only a few days may not provide enough history to understand what happened.

Retention periods should reflect the organisation’s risks, technical capabilities and any regulatory or contractual requirements.

Centralise important alerts

Do not rely on somebody occasionally checking several different administrative portals.

Important alerts should reach an identified person or service capable of assessing them. There should also be a clear process for dealing with warnings outside normal working hours.

Monitor privileged accounts

Administrator accounts can make extensive changes, access sensitive information and weaken security controls. Their activity should therefore receive greater scrutiny.

Where possible, administrators should use separate accounts for routine work and privileged tasks.

Understand normal working patterns

It is easier to recognise unusual activity when the organisation understands what normal access looks like.

Consider:

  • Normal working hours
  • Countries and regions from which staff usually connect
  • Approved devices and browsers
  • Expected remote-access tools
  • Normal payment values
  • Typical file-sharing behaviour
  • Who is authorised to make administrative changes

Alerts can then be assessed against a realistic business baseline rather than in isolation.

Review cloud and email configurations

Regularly review:

  • Mailbox forwarding
  • Inbox rules
  • MFA registrations
  • Administrator roles
  • External file sharing
  • Application permissions
  • Active user accounts
  • Authentication settings

These checks can identify unwanted changes before they are used to cause visible damage.

Test security controls

Vulnerability scanning and penetration testing can identify weaknesses before an attacker exploits them.

Testing can also demonstrate potential attack paths and help determine whether existing security controls would prevent or detect suspicious activity. A control that generates an alert is only useful if the alert reaches the right person and leads to action.

Practise the response

Run a short tabletop exercise based on a realistic incident such as:

  • A compromised Microsoft 365 mailbox
  • A ransomware infection
  • A fraudulent supplier payment
  • A lost laptop
  • An IT provider reporting a breach

Ask who would receive the first alert, who would make decisions and how the organisation would communicate if its normal systems were unavailable.

Practical monthly detection checklist

  •  Review administrator accounts and privileges
  • Check mailbox forwarding and inbox rules
  • Review unusual or high-risk sign-ins
  • Confirm security tools are active and reporting
  • Investigate devices missing from management consoles
  • Review backup alerts and recent restore tests
  • Check for new remote-access tools and accounts
  • Examine significant security alerts
  • Confirm audit logging remains enabled
  • Review important application permissions
  • Ask staff whether they have seen unusual prompts or messages
  • Record and investigate anything that cannot be explained

Detection is not only a technical problem

Effective detection depends on a combination of:

  • Appropriate security technology
  • Useful and retained logs
  • Monitoring of important alerts
  • Employees who report unusual behaviour
  • Clearly assigned responsibility
  • An established escalation process
  • Independent security testing
  • Regular practice

Buying a security product does not guarantee that somebody will notice or act on its warnings.

A business may have antivirus software, cloud security alerts and detailed audit logs, but still fail to detect an attacker if nobody is responsible for reviewing them.

Would your business notice?

The most damaging cyber incidents are not necessarily those that use the most sophisticated initial attack. They are often the incidents that remain unnoticed for the longest.

Every small business should be able to answer:

  • What activity would generate a security alert?
  • Who receives that alert?
  • Who investigates it?
  • What happens outside normal working hours?
  • How long are important logs retained?
  • How would an employee report something suspicious?
  • When was the response process last tested?

If those questions cannot be answered, the organisation may not discover an attacker until customers, suppliers or the criminals themselves reveal what has happened.

Would your business detect an attacker before visible damage was done? Independent security testing can identify weaknesses, demonstrate potential attack paths and show where preventative and detective controls need to improve.

Portrait of Plainsight Security's lead tester

Written by

Mark Tomlinson

Our lead penetration tester, Mark Tomlinson, holds The Cyber Scheme Team Leader qualification in infrastructure penetration testing, an advanced certification recognised by the National Cyber Security Centre (NCSC) and used by professionals testing government systems and UK critical national infrastructure. Mark is also registered with the UK Cyber Security Council as a Principal Cyber Security Professional (PriCSP) specialising in Security Testing and holds an MSc in Computer Science with Cyber Security.

More about how we work
Talk to a tester

Put this into practice.

Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.

← All insights