Been hacked? BEC and the common types of attack

If you think you have been breached, act fast and get help. Here is what business email compromise and the other common attacks look like, and what to do.

Insights · 6 September 2026

If you suspect you have been hacked, the first minutes matter. Do not panic, and do not start deleting things. Isolate the affected accounts and devices, change passwords from a device you trust, and get expert help quickly.

If you are dealing with a live incident now, our incident response team can help you contain it and recover. The rest of this article explains the attacks we see most, so you can spot them and reduce the chance of the next one.

Business email compromise: the costly one

Business email compromise, or BEC, is one of the most expensive attacks for small and medium businesses, and it often involves no malware at all. An attacker gets into, or convincingly spoofs, an email account and then redirects a payment, sends a fake invoice, or impersonates a director to authorise a transfer. It works because it targets trust and a moment’s inattention rather than technology.

Warning signs include a supplier’s bank details suddenly changing, hidden rules quietly forwarding or deleting your email, an urgent payment request that breaks the usual process, and invoices that do not quite match previous ones. The single best defence is simple: verify any change to payment details by phone, using a number you already hold, before you pay.

The other attacks we see most

Phishing is the way in for the majority of breaches: an email or text that tricks someone into handing over credentials or clicking a malicious link. Ransomware encrypts your files and demands payment, and the advice is not to pay but to get help and restore from backups. Account takeover exploits reused or weak passwords and missing multi-factor authentication. Malware arrives through attachments, downloads or infected devices. And supply-chain attacks reach you through a trusted supplier or a compromised software update.

Why it keeps working, and how to stop it

Most of these attacks target people and process, not just technology, which is why buying a product rarely fixes them on its own. Multi-factor authentication everywhere, staff who know what a scam looks like, a firm rule to verify payment changes, monitoring that spots trouble early, and backups you have actually tested, together stop the great majority of what we see.

What to do now

If you are in an incident, get help immediately. If you are not, this is the moment to check your defences honestly: get the basics certified with Cyber Essentials, turn on MFA, add monitoring, and consider a penetration test to find the gaps before an attacker does.

Common questions

What is business email compromise?

An attack where a criminal accesses or spoofs an email account to redirect payments, send fake invoices, or impersonate a senior person to authorise a transfer. It relies on trust rather than malware.

I think we have been hacked, what is the first thing to do?

Do not delete anything. Isolate the affected accounts and devices, change passwords from a trusted device, and get expert help. Acting quickly limits the damage.

Should we pay a ransom?

The strong advice is no. Get expert help, restore from tested backups where possible, and report it. Paying funds the criminals and does not guarantee recovery.

Related

Think you have been hacked?

Honest, independent, CREST-accredited advice. No sales team, no obligation.