I've Been Hacked, What's Next?
Brook Hart lays out the steps to take immediately after discovering a hack, from alerting financial institutions and updating passwords to locking credit cards, freezing credit, and addressing a compromised device. He emphasizes that speed matters and recommends having a cybersecurity playbook ready before an incident ever occurs.
Brook Hart lays out the steps to take immediately after discovering a hack, from alerting financial institutions and updating passwords to locking credit cards, freezing credit, and addressing a compromised device. He emphasizes that speed matters and recommends having a cybersecurity playbook ready before an incident ever occurs.
Key takeaways
- Alerting financial institutions immediately after a suspected hack lets them apply extra security restrictions before money can be moved.
- Updating passwords on breached and linked accounts, locking credit cards, and freezing credit are early steps to limit further damage.
- Filing a police report may not resolve the situation directly but can help investigators identify patterns across cases.
- Having a cybersecurity plan in place before an incident happens makes it easier to respond quickly instead of reacting out of fear or panic.
Hello and welcome to this month's edition of The Big Question. Inevitably, you or someone close to you is going to be a victim of cybercrime. At that point, worrying about the woulda, coulda, shoulda's does us no good. At that point, it's about working to limit the damage and head off the bad actors as best we can. Which leads us to this month's big question. I've been hacked. What's next?
Let me paint the picture for you. You're not focused, you're moving fast, shifting from task to task at work, or maybe even at home late at night. You check your email quickly, clicking on a link from one of your oldest friends, which oddly enough, happens to request your password to download the message, or any one of these go-to tricks that scammers use. Suddenly, you realize, "Wait a minute, that didn't look quite right." Something's off. At that point, frankly, it's likely too late. The criminals, more likely than not, now have access to your information, your password, your computer, or even your phone in real time. What you do next is going to determine how bad this gets. The faster you move, the more you increase your chances of heading them off before they do significant, lasting damage.
So, what's to be done? First, alert any and all financial institutions with whom you have a relationship. To be clear, 99 times out of 100, this is exactly what these bad actors are interested in: money. Now, these financial institutions all have heightened layers of security and restrictions that they can implement during times like this. Request that they enact this immediately. There's no sense in waiting to see what may or may not happen. Just act. Act right away. Will it make it harder to do things within your account, trade, move money, and so forth? Yes, but that's the point. These aren't permanent restrictions in place forever, but they are restrictions that need to be enforced immediately, today. Make it difficult, if it's impossible, for anyone that isn't you to move money or to take any action within your accounts.
Secondly, update all passwords associated with any breached accounts. And once you've done that, work your way through all your accounts that are linked to any type of sensitive information and update those passwords as well. Now, as it relates to your credit cards, lock them. This generally allows you to keep any ongoing subscriptions in place, and it allows you to execute digital wallet transactions like tap-to-pay, for example, from your phone in person, but it stops the use of your card otherwise, specifically online. You're also going to want to freeze your credit if it's not already frozen. Once these bad actors have key information about you, they may try opening up various lines of credit before maxing them out as quickly as they can. By freezing your credit, you ideally head this off before it even gets off the ground.
And if or when applicable, reach out to your local police department to file a police report. Now, this last step, if we're honest with one another, not likely to be much help. It's like finding a needle in a haystack. But why I would still recommend this is that your report may help the police stop the criminals from hurting the next person. It may provide them one more piece of the puzzle, getting them one step closer to establishing a recurring pattern to then better inform others of a scam.
And lastly, once you've got the bulk of this in place, you need to address the device that was the source of the initial breach. For example, if it was your computer, you're either going to want to buy a new computer, depending on the age of it, perhaps it was already approaching that time already, or have your current one completely wiped by a team of professionals. Whether it's the Geek Squad or a team at Apple, until you've been certified clean by experts, I would be hesitant to use your computer at all, as there may still be some malware lurking in the background waiting for the next opportunity to strike.
Now, in a moment like this, it's going to be difficult to remember all of this. Realistically, what you're likely to be feeling is fear, pain, anger, embarrassment, and more. For that reason, we'd recommend downloading our cybersecurity playbook, available in the show notes. Print it out, keep it nearby, and have it ready to access if you ever find yourself or a family member in this situation. Ideally, you never use it, but at least you know where to start if that day comes. Thanks for joining me everyone. Until next month.
More from our team
Turn insight into a plan
The first conversation is 30 minutes, no preparation needed.