Cyber recovery help in UK

Been Hacked Fix UK

Plain-English cyber recovery support for people and small businesses across UK. Contain the incident first, then secure accounts and plan recovery.

Check the signs

Recognise the warning signs before changing anything

Organisations that rely on email, Microsoft 365, online banking and cloud services can be disrupted by one compromised mailbox or reused password. In UK, investigate unexpected Microsoft 365 sign-ins, new mailbox forwarding rules and supplier bank details changing without verification promptly.

An incident may begin with a convincing call, a fake sign-in page, a supplier invoice, stolen browser credentials or an unpatched device. Write down what each person saw and when it happened. A reliable timeline is more useful than guessing how an attacker got in.

Warning signSafe first action
unexpected Microsoft 365 sign-insReview recent sign-ins from a clean device.
new mailbox forwarding rulesPreserve the message or rule before removing it.
supplier bank details changing without verificationPause payment and verify through a known number.
1

Limit the damage

Disconnect a device if malware is suspected, but do not wipe it. Stop remote-access sessions and suspicious calls. If business email in UK is involved, warn anyone who approves invoices or supplier changes.

2

Use a clean route

Use a separate phone or computer to contact your bank, IT provider and account services. Type known addresses yourself and avoid links in the message that caused concern.

3

Secure accounts

Start with email, Microsoft 365 or Google Workspace, banking, domain names and website administration. Reset unique passwords, review recovery details, remove unknown sessions and enable MFA.

Recovery in UK

Check people, accounts, devices and backups together

An account compromise rarely stays inside one inbox. Attackers may study real conversations, imitate trusted contacts or wait until a genuine payment is due. Review sent items, deleted items, forwarding rules, delegated access, administrator roles and sign-in locations.

Ask staff to report unusual prompts without blame. Tell them which route to use if normal email cannot be trusted. Check laptops, phones and shared computers for unfamiliar browser extensions or remote tools.

Confirm backups exist, are separate from the affected system and can be restored before deleting or rebuilding anything. Keep screenshots, email headers, phone numbers, URLs, bank messages and login alerts.

A practical response plan

Businesses coordinating with customers or suppliers across Ireland, England, Wales should check any shared accounts and payment processes too. Record each password reset, device isolation and bank call so recovery work is not repeated or missed.

If personal data may have been exposed, assess whether the relevant regulator and affected people need to be told. Check your cyber-insurance terms before taking actions that may affect a claim.

The aim is to regain control, understand the likely exposure and reduce the chance of a follow-up attack. Recovery should leave accounts, devices and working practices safer than they were before the incident.

Report fraud in UK

Use official routes and trusted contact details

If money has moved, call your bank immediately and ask whether a transfer can be stopped or recalled. Report through Report Fraud. Use NCSC guidance for independent prevention and recovery guidance.

Keep reference numbers and note who was contacted. Reporting does not replace containment. Secure accounts and devices at the same time using a route the suspected attacker cannot monitor.

Questions from UK

Frequently asked questions

What should I do first if I have been hacked in UK?

Disconnect affected devices safely, pause payments, preserve messages and screenshots, then use a separate trusted device to secure important accounts.

Who should I report online fraud to in UK?

Contact your bank immediately if money may be at risk. Use Report Fraud for the appropriate official reporting route.

Can Been Hacked Fix support someone in UK remotely?

Yes. Initial containment, account checks and recovery planning can often start remotely. We will explain if a device needs hands-on investigation.

Should I wipe the affected computer or phone?

Not before evidence and recovery options have been checked. Wiping too early can remove useful logs, messages and other evidence.

Get practical cyber recovery help in UK

Tell us what happened, which accounts or devices are affected and whether money or customer data may be at risk.