Contain
Disconnect a suspicious device if malware is possible. Pause payments, warn staff who approve invoices and stop using compromised accounts for recovery work.
01244 835402If your email, Microsoft 365, website, social-media account, online banking, domain name or device has been compromised in Chester, start with calm containment and a clean recovery route.
For Chester households and small businesses, the highest-risk systems are usually email, Microsoft 365, banking, domain registration, website administration and social media. If an attacker controls any of those, they may reset other services, intercept invoices or message customers while pretending to be you.
Do not rely on the affected mailbox or device to coordinate recovery. Use a separate trusted phone or computer, write down what happened, and keep copies of suspicious messages, sign-in alerts, payment requests and recovery emails.
Disconnect a suspicious device if malware is possible. Pause payments, warn staff who approve invoices and stop using compromised accounts for recovery work.
From a clean device, reset priority passwords, remove unknown sessions, check recovery details and strengthen MFA on email, banking, websites and social accounts.
Review what may have been accessed, restore safe access, check backups and put practical controls in place to reduce the risk of the attacker coming back.
Many Chester businesses work with customers, suppliers and professional contacts across Cheshire, North Wales, Wirral and the wider North West. One hacked mailbox can expose real conversations that make fake payment requests look believable.
Check whether the attacker created forwarding rules, changed recovery details, added OAuth apps, used remote-access tools or accessed cloud files. If payments, personal data or customer communications may be involved, keep a clear timeline of who was contacted and when.
If your website or domain is affected, secure the registrar and DNS first so recovery emails, website traffic and email routing cannot be redirected. If Microsoft 365 is affected, review admin roles and conditional-access or MFA changes before assuming a password reset is enough.
For money at risk, contact your bank immediately using a known number. For fraud reporting in England and Wales, use Report Fraud. For independent cyber guidance, use the NCSC guidance for small organisations.
If you think an account, device, website or business email has been compromised, call before making rushed changes. A calm first call can help protect evidence, reduce damage and prioritise the accounts that matter most.
Call 01244 835402 for practical next steps.
Stop using the affected account or device for anything important. Preserve emails, texts, login alerts and screenshots, then use a clean phone or computer to secure banking, email and Microsoft 365 first.
Yes. We can help review sign-ins, forwarding rules, delegated access, mailbox rules, MFA settings, administrator accounts and recovery options so the mailbox is not quietly still under someone else's control.
No. This Chester recovery page is for Chester and nearby areas including Hoole, Boughton, Saltney, Upton, Ellesmere Port, Deeside, Wrexham and surrounding villages.
Usually not. Wiping too early can remove useful evidence and may not fix the account or cloud-service compromise. Contain the problem, preserve evidence and check the account routes first.
Tell us what happened, what is affected and whether money, customer data or business systems may be at risk.