Services / Signs Your Business May Have Been Breached
Warning Signs

Signs Your Business May Have Been Breached

Not every incident announces itself with a ransom note. Here are the signs worth taking seriously, on both the technical and business side.

Key Takeaways
  • Technical warning signs often show up in account activity and network traffic before anything else fails visibly.
  • Business-side signs, like customers reporting suspicious emails, are often the first thing anyone actually notices.
  • Ambiguous signs deserve a second look, not automatic dismissal.
  • Acting fast on a false alarm costs far less than acting slow on a real one.

Technical Warning Signs

Technical indicators often show up in account activity and system behavior before anything more dramatic happens. Unexpected account lockouts, password reset emails you didn't request, or new admin accounts nobody recognizes are all worth investigating immediately rather than dismissing as noise.

Unusual outbound network traffic, especially at odd hours when normal business activity should be minimal, is another pattern worth watching — it often indicates data being exfiltrated or a compromised system communicating with external infrastructure.

  • Unexpected account lockouts or password reset emails you didn't request
  • Unusual outbound network traffic, especially at odd hours
  • New admin accounts or permission changes no one recognizes
  • Files that are suddenly encrypted, renamed, or missing
  • Antivirus or endpoint tools reporting disabled or tampered-with status

Business Warning Signs

Sometimes the first sign isn't technical at all — it's a customer or partner noticing something wrong before your own team does. Customers reporting suspicious emails that appear to come from your domain, or vendors flagging unusual requests, are both worth investigating immediately rather than assuming it's someone else's problem.

Unexplained financial transactions or invoice changes can also indicate a business email compromise, where an attacker has gained access to communications and is using that access for fraud rather than obvious technical disruption.

  • Customers reporting suspicious emails that appear to come from you
  • Vendors or partners flagging unusual requests from your domain
  • Unexplained financial transactions or invoice changes

What to Do If You See These

Don't wait for certainty. Isolate what you can without destroying evidence, and get a response team involved early — the cost of overreacting to a false alarm is far lower than the cost of reacting too late to a real one.

If you're not sure whether something warrants a full response, a short triage conversation with a response team can usually clarify quickly, without committing to a full engagement before you know it's actually needed.

Questions
What if we're not sure it's actually a breach?

Treat ambiguous signs as worth a second look rather than dismissing them. A short triage call can usually tell you quickly whether it warrants a full response, without the cost or disruption of a full engagement.

Should we tell customers immediately if we suspect a breach?

It depends on what you actually know and what regulations apply to your business. Getting a response team involved quickly helps you make that communications decision with better information rather than reacting on incomplete facts.

Can these signs be false alarms?

Yes, some of them commonly are — but the cost of investigating a false alarm is far lower than the cost of dismissing a real one, which is why we recommend erring toward investigation.

Related Reading

Have a Question We Didn’t Cover?

Email Our Team