Contain
Disconnect a suspicious device if malware is possible. Pause payments, stop remote-access sessions and avoid using the compromised account for recovery work.
+44 (0)1743 668200If your email, Microsoft 365, website, social-media account, online banking, domain name or device has been compromised in Cambridge, start with containment before changing passwords or deleting evidence.
For Cambridge households and small businesses, one compromised mailbox, Microsoft 365 account, domain login or website admin account can quickly become a wider incident. Attackers may reset other services, intercept invoices, alter DNS or message customers while pretending to be you.
Use a clean device to coordinate recovery. Keep screenshots, email headers, sign-in alerts, payment requests and recovery messages. If you run a business, tell the people who approve invoices or supplier changes which route is safe to use.
Disconnect a suspicious device if malware is possible. Pause payments, stop remote-access sessions and avoid using the compromised account for recovery work.
From a clean device, reset priority passwords, remove unknown sessions, check recovery details and strengthen MFA on email, banking, websites and social accounts.
Check what may have been accessed, restore safe access, verify backups and tighten working practices so the attacker cannot simply return.
Cambridge businesses often work across Cambridgeshire and nearby areas such as Ely, Huntingdon, Newmarket. A hacked inbox can make fake invoice or bank-detail changes look like normal business conversation.
That matters for technology, research, professional services, healthcare suppliers and charities. Check whether the attacker created forwarding rules, changed recovery details, added OAuth apps, used remote-access tools or accessed cloud files.
If your website or domain is affected, secure the registrar and DNS first so recovery emails, website traffic and email routing cannot be redirected. If Microsoft 365 is affected, review administrator roles and mailbox access before assuming a password reset is enough.
For money at risk, contact your bank immediately using a known number. For fraud reporting in England and Wales, use Report Fraud. For independent cyber guidance, use the NCSC guidance for small organisations.
If you think an account, device, website or business email has been compromised, call before making rushed changes. A calm first call can help protect evidence, reduce damage and prioritise the accounts that matter most.
Call +44 (0)1743 668200 for practical next steps.
Stop using the affected account or device for recovery work. Preserve login alerts, payment messages, emails and screenshots, then use a separate trusted device to secure banking, email and Microsoft 365 first.
Yes. We can help review sign-ins, mailbox rules, forwarding, delegated access, MFA methods, administrator accounts and recovery settings so the attacker is not still able to monitor or regain access.
No. This Cambridge recovery page covers Cambridge and nearby areas including Ely, Huntingdon, Newmarket, Royston, St Neots.
Usually not. Secure the account, domain, hosting or device route first. Rushed wiping or rebuilding can remove useful evidence and may leave the original access route open.
Tell us what happened, what is affected and whether money, customer data or business systems may be at risk.