You think you have been hacked.
Read this, then call us.
The next hour matters more than the next week. Stop, read the steps below, then phone the number. We will get you into containment before you finish the call.
Already an existing Real Bytes client? Mention your account name and you go straight to the priority queue.
Right now, before anything else
Six things to do in the next five minutes
In order. The first one is the most important.
Call us first
07 3114 2808. An engineer answers within minutes. We will triage on the phone, get you into containment, and start formal investigation in parallel. Do this before you do anything else on this page. Do not call your insurer first. The first hour decides the next six months.
Do not power off compromised machines
Pulling the plug destroys forensic evidence and may not stop the attacker. Disconnect from the network instead. Unplug the ethernet cable, disable Wi-Fi, leave the device powered on. We will instruct on safe isolation when we are on the call with you.
Do not pay a ransom yet
Paying a ransom is sometimes legal in Australia but it funds the criminal ecosystem, may breach sanctions, often does not recover the data and marks you as a future target. Do not negotiate without specialist advice. We will tell you honestly when payment is the only commercial path.
Do not change passwords yet
Counterintuitive, but changing passwords on a compromised account before containment can alert the attacker and accelerate damage. We coordinate password resets with isolation so the attacker loses access without realising why.
Do not delete the suspicious email
If you found a phishing email, screenshot it, but do not delete it. The full email headers are evidence. Forward the suspicious email as an attachment to the engineer on the call, do not delete it from the mailbox.
Start a written timeline
Write down what you noticed, when, and what you did about it. Use a phone or paper, not the compromised machine. Times do not need to be exact. This timeline becomes the foundation of the OAIC assessment and insurance claim if either applies.
Not sure if you have been hacked?
Common warning signs
If you see any of these in a small business or mid-market environment, treat it as an active incident until proven otherwise. False alarms are cheap. A missed real incident is not.
If in doubt, call. A 10-minute triage call costs nothing and tells you definitively whether what you are seeing is an incident or a misconfiguration.
- Files renamed with strange extensions or sitting in unfamiliar folders
- Ransom note text files appearing on the desktop or across shared drives
- A staff member reports their account doing things they did not do
- Microsoft 365 sign-in alerts from unexpected countries
- Bank or accounting system showing unauthorised transactions or payee changes
- Customers receiving emails from your domain that you did not send
- Your phone provider tells you a SIM swap has occurred
- Antivirus or EDR has fired alerts and stopped responding to admin
- Workstations restarting themselves or running unusually slowly
- MFA prompts hitting your phone that you did not initiate
What happens once we are engaged
The first two weeks of an active incident
Same discipline whether it is a single compromised inbox or a full ransomware event.
Hour 0 to 1: Containment
We isolate compromised identities and devices. Network segments closed where needed. Mail flow rules paused if BEC is in play. We get the immediate bleeding stopped before forensic perfection.
Hour 1 to 8: Investigation
We confirm what was accessed, what was changed, and whether the attacker still has persistence. Log review, EDR telemetry, M365 unified audit log, sign-in logs. We document to evidentiary standard from the first minute.
Day 1 to 3: Eviction and recovery
All persistence mechanisms removed. Identity rebuild where required. Clean restoration from immutable backup if data was encrypted. Coordinated communications with staff and (if appropriate) customers.
Day 3 to 14: Notification and hardening
OAIC notifiable data breach assessment finalised. Cyber insurer engaged with full evidence. Affected individuals notified where required. Written hardening plan delivered so the same incident cannot repeat.
Was AI part of this incident?
Four AI-augmented incident patterns we are seeing in 2026
If any of these match what you are dealing with, the calm steps above still apply. What changes is the evidence you need to preserve and the questions your insurer and the OAIC will ask afterwards.
Deepfake voice or video call
What it looks like. Staff member received a phone call, Teams call or video meeting from someone who sounded like a director, the CEO or a known supplier, and was asked to move money, change payee details, share credentials or approve a transaction.
Preserve evidence and adjust
- Do not delete the call log, Teams meeting record, voicemail or chat history.
- If a transaction was actioned, contact your bank's fraud line directly. Do not call back the number that called you.
- Capture the caller ID, time of call, and any meeting ID or invite link. These are evidence.
- Treat the impersonated person's account as potentially compromised. Their voice may have been cloned from a public recording, but their account may also have been the source of meeting metadata.
AI-assisted business email compromise
What it looks like. The phishing or impersonation email is unusually well written for the sender it claims to be from. Tone, signature style and reply threading look correct. Often references real recent events inside the business.
Preserve evidence and adjust
- Preserve full email headers, do not delete the message. Forward as an attachment, not inline.
- Check Microsoft 365 unified audit log for mailbox rule creation, forwarding rules and unusual sign-in geography for the impersonated sender.
- Assume the attacker had inbox visibility for some period before the send. Past correspondence may be compromised even if the active account is not.
- If the email refers to a current transaction, contact the real counterparty out of band before any further action.
Compromised Copilot, ChatGPT or AI agent
What it looks like. An AI tool returned data it should not have access to, started behaving unusually, or a staff member received output that referenced confidential material from another team. Or a Copilot Studio agent took an action no one authorised.
Preserve evidence and adjust
- Disable the affected Copilot licence and any custom agent immediately. Document the agent name, scope and connected data sources before any changes are made.
- Review the SharePoint and OneDrive permission boundary the agent was operating under. Oversharing is the most common cause of unintended AI disclosure.
- Pull the Microsoft 365 audit log entries for the agent's service principal or the user's Copilot interactions. Microsoft retains these.
- Treat any data the agent surfaced as potentially exposed beyond the intended audience for OAIC assessment purposes.
Confidential data pasted into a public AI tool
What it looks like. A staff member used ChatGPT, Gemini, Claude or another consumer AI tool with client data, source code, financial records, health information or anything else covered by a confidentiality obligation.
Preserve evidence and adjust
- Capture the exact prompts and responses if still visible in the user's account history.
- Check whether the account had training opt-out enabled at the time. For most consumer tier accounts the answer is no.
- Assume the data is in the model provider's logs for at least 30 days regardless of opt-out status.
- Assess whether the exposure meets the OAIC notifiable data breach threshold. Often it does for client personal information.
Once the incident is contained, the followup is usually an AI acceptable use policy, a Copilot tenant audit and a staff briefing on the AI threats we are seeing across Australian SMBs.
What 2026 looks like across 22,000 confirmed breaches
If you are reading this in the middle of an incident, the Verizon 2026 DBIR is where the numbers come from. Vulnerability exploitation is now the leading way attackers get in, edge devices are hit within hours of a CVE going public, and the human element is still in most breaches. None of that means you did something wrong. It means you are in the same window thousands of other organisations are managing right now.
Read the Verizon 2026 DBIRTop vector
Vulnerability exploitation now the leading initial access vector for breaches
Overtook stolen credentials in 2026. The patch backlog has become the front door.
0 days
0 days median time from edge-device CVE disclosure to mass exploitation
Firewalls, VPN gateways and remote-access appliances are now hit at internet speed.
62%
62% of breaches still involved a human element across all sectors
Identity, awareness and process discipline remain the controllable variables.
96%
96% of ransomware victims in the DBIR dataset are small or medium businesses
Attackers run a volume model. Smaller operators are the easier mark, not the safer one.
Source: Verizon 2026 Data Breach Investigations Report. Dataset window Oct 2024 to Nov 2025. 31,000+ incidents and 22,000+ confirmed breaches across 145 countries.
Honest answers
Frequently asked questions in active incidents
Once the dust settles
An incident response retainer is the cheapest cyber insurance you will ever buy.
Once your current incident is resolved, talk to us about a retainer. Pre-agreed access, documented runbooks, quarterly tabletop exercises and a guaranteed response window. The first hour does not get spent figuring out how to log in.

Remote Support