Report an Incident
Think you've been hacked or had a data breach? Here's what to do right now — step by step, in plain English.
Stay calm
Panic leads to mistakes. Take a breath — most incidents can be contained if you act methodically.
Disconnect the affected device
If you suspect a device has been compromised, disconnect it from Wi-Fi and any other network connections immediately.
Change your passwords
From a separate, clean device, change passwords for your email account first, then any accounts that use the same password.
Enable two-factor authentication
Add two-factor authentication (2FA) to your email and any critical accounts you can access.
Check for unauthorised activity
Review recent logins and account activity. Look for emails you did not send, purchases you did not make, or settings changes.
Report to the relevant authority
Report fraud to Action Fraud (0300 123 2040). Businesses should also notify the ICO within 72 hours of a personal data breach.
Useful contacts
- Action Fraud — 0300 123 2040 or actionfraud.police.uk
- NCSC — report.ncsc.gov.uk (suspicious emails)
- ICO — ico.org.uk (data breach reporting for businesses)
Want to reduce your risk of future incidents? Create a free Cyber Nova AI account and get your personalised security checklist.