First: breathe. Getting scammed or hacked happens to IT professionals, CEOs, and yes, security companies. Acting quickly matters far more than how it happened, and shame is exactly what attackers count on to keep victims quiet. You're going to work the list, and it's going to be okay.
Step 1: Cut the connection
- If a computer is behaving strangely or showing a ransom note, disconnect it from Wi-Fi / unplug the network cable. Don't power it off if ransomware is suspected, because investigators can sometimes recover keys from a running machine. Just isolate it.
- If you just typed your password into a fake site or gave a caller remote access, close the connection and move to a different, clean device for everything that follows.
Step 2: Lock down your accounts (from a clean device)
- Email first. It's the master key: whoever controls it can reset everything else. Change the password, then check for forwarding rules or recovery addresses the attacker may have added.
- Change passwords on any account that shares the exposed password, and on anything sensitive: banking, work, cloud storage.
- Turn on MFA everywhere as you go.
- Use each service's "sign out of all sessions" option to kick the attacker out of anything already open.
Step 3: If money or cards are involved
- Call your bank or card issuer immediately, using the number on the back of your card, never one from an email or the scammer. Fraud reversals are very time-sensitive; minutes matter with wire transfers.
- If you paid by gift card, call the card's issuer; if by wire, ask your bank to attempt a recall now.
- Freeze your credit at all three bureaus if personal information (SSN, DOB) was exposed. See the privacy guide.
Step 4: Clean up and verify
- Run a full antivirus scan; if anything serious turns up, or if a stranger had remote access, a full reset/reinstall from a known-good backup is the only way to be sure.
- Check your email rules, phone for unknown apps, and browser for unknown extensions.
- Keep evidence: screenshots, the scam email with headers, phone numbers, transaction IDs. You'll want them for reports.
Step 5: Report it
- FBI IC3 (ic3.gov) for online fraud and ransomware; identitytheft.gov for identity theft; the FTC (reportfraud.ftc.gov) for scams generally.
- Reporting to your workplace immediately isn't optional if a work account or device is involved, and a good employer will thank you, not punish you. Attackers move fast; early warning saves everyone.
- Warn anyone whose name the attacker might use next: your contacts, your vendors, your team.
Watch out for the second wave. Fraud victims routinely get contacted by fake "recovery services" or "bank investigators" offering to get the money back for a fee, or by "verifying" your details. That's the same attackers, or their friends, coming back for seconds. Only trust contacts you initiate.
When to call in help
If a business system is involved, if ransomware has hit, or if you're just not sure you got all of it, bring in professionals. That's genuinely what we're here for, judgment-free, at any hour: hello@logipex.net or call/text +1 (405) 754-4018.