The clearest signs your network has been hacked are logins from places nobody works, new inbox rules you did not create, security tools that have been switched off, MFA prompts you did not trigger, unexplained new accounts, and vendors or customers reporting emails you never sent. Any one of these deserves a same-day check; two or more mean you should assume an attacker is inside and start containment while you investigate.

Most small-business breaches on the Treasure Coast are discovered weeks after they began, usually when money goes missing or ransomware detonates. The signs were there earlier. Here are the ten we see most, how to verify each, and what to do in the first hour.

What are the warning signs of a hacked business network?

1. Sign-ins from unexpected locations or at odd hours

A login to a Vero Beach bookkeeper's mailbox from overseas at 3 a.m. is not a glitch. How to check: in Microsoft 365, review the sign-in logs in the Entra admin center for each user, filtering for unfamiliar countries, impossible travel and unknown devices.

2. Inbox rules you did not create

Attackers who take over a mailbox almost always add rules that forward mail outside, move messages from the bank or a client to a hidden folder, or delete replies so the victim never sees them. How to check: open Outlook rules for each user and look for forwards, deletions or rules with blank names. Administrators can search the whole tenant for forwarding rules.

3. Unexpected multi-factor authentication prompts

If staff receive MFA push notifications they did not request, someone has their password and is trying to get past the second factor. This is also how MFA fatigue attacks work: repeated prompts until a tired user taps approve. How to check: ask staff directly and review MFA logs. Treat any approved prompt the user does not remember as a compromise.

4. Security tools disabled or missing

Antivirus off, EDR agent uninstalled, Windows Defender tamper protection disabled, firewall rules changed. Attackers do this before deploying ransomware. How to check: your management console should show every device reporting in; any that stopped checking in or show protection disabled need attention today.

5. New user accounts, admin rights or applications

A new global admin, a user you do not recognize, or an unfamiliar application granted permission to read mail. OAuth app consent is a favorite persistence trick because it survives a password change. How to check: review users, admin roles and enterprise applications in Microsoft 365, and local administrator groups on servers.

6. Customers or vendors receiving emails you did not send

Invoices with changed bank details, password reset links, or requests to open a shared document. By the time someone calls to ask, the mailbox has been compromised for a while. How to check: review the Sent Items and deleted folders of the affected user, and the message trace in Exchange.

7. Systems suddenly slow, crashing or rebooting

Not every slow computer is hacked, but a server that suddenly runs hot with high disk activity may be encrypting or exfiltrating. How to check: look at running processes and network traffic on the affected machine, and at firewall logs for large outbound transfers, especially overnight.

8. Files renamed, encrypted or with strange extensions

The obvious ransomware sign, but also the last one. Shadow copies deleted and backup jobs failing often precede it. How to check: spot-check shared folders and look at backup job history for sudden failures.

9. Locked-out accounts and password reset notices

A burst of lockouts across the company suggests a password-spraying attack. Password reset emails nobody requested suggest an attacker probing accounts. How to check: review account lockout events and reset requests in your identity logs.

10. Unusual outbound traffic or unfamiliar remote access tools

Remote control software you did not install, new VPN connections, or the firewall showing steady traffic to unfamiliar addresses. How to check: inventory installed software for remote tools and review firewall logs for persistent connections.

What should you do in the first hour if you suspect a breach?

  1. Do not tip off the attacker by half measures. Changing one password while they hold three other accounts just tells them you noticed.
  2. Contain identities. From a clean device, reset passwords and revoke all sessions for affected accounts, remove suspicious inbox rules and app consents, and re-register MFA.
  3. Isolate affected machines from the network without powering them off, and pause backup and sync jobs so clean copies are not overwritten.
  4. Preserve logs before they roll over. Export sign-in, audit and firewall logs.
  5. Call for help. Notify your IT provider or an incident response team, and your cyber insurer if you have a policy; most require prompt notice.
  6. Warn finance. Until the scope is clear, verify every payment instruction by phone with a known number.

How can you catch these signs earlier?

Every sign above generates a log entry long before a human notices. A managed security service watches those logs 24x7, correlates them, and isolates a device or disables an account automatically when the pattern is clear. That is the difference between finding a breach in hours and finding it in weeks. Our cybersecurity services combine endpoint detection, identity monitoring and email security for small businesses across the Treasure Coast, with local technicians who can be on site when needed.

If something on this list looks familiar, call MainSail Data now at (772) 794-1194; we answer 24x7x365. If you simply want to know how you would find out, request a free security assessment and we will check your environment for these signs before an attacker exploits them.