Saltar al contenido

Administration

If you suspect someone got in

The first twenty minutes, in order, and who to tell.

Updated on 13/08/2026

The instinctive reaction is to investigate first. It is the wrong one: while you investigate, whoever got in is still inside. The right order is close, then look, and notify in parallel.

The first twenty minutes

  1. 1

    Close that account's sessions

    And change its password. It is the only urgent thing; everything else can wait ten minutes.

  2. 2

    Enable or require two-factor

    If it was not on, that is how they got in. A stolen password without a second factor opens the whole door.

  3. 3

    Read that account's log

    What was opened, what was downloaded and from where. Now it is time to investigate.

  4. 4

    Notify the right people

    The affected person, and whoever handles data protection if third-party data was reached.

What to look for in the log

SignalWhat it usually means
Bulk downloadsSomeone taking information, not a mistake
Access from a place or time that does not fitCheck first whether that person was travelling
Permission changesAn attempt to keep access after you close it
A contact or bank account modifiedFraud in progress: check this before anything else

Important

If third parties' personal data was reached — payroll, identity documents, client files — there may be notification duties on short deadlines. Tell whoever handles data protection that same day, even before you know the scope.

Watch out

Do not delete anything while investigating, not even to tidy up. The log is what lets you know what happened and prove how you responded.

Worth knowing

The commonest cause is not a sophisticated attack: it is a password reused on another service that leaked. Which is why mandatory two-factor is the measure that returns most for how little it costs.

Can I see whether they downloaded anything?

Yes, accesses and downloads are logged.

Do I notify affected clients?

That decision is not only technical. Let data protection make it with your adviser.

What if it was a false alarm?

All the better. Closing one session too many costs one person a minute.

A real case

The situation

An employee reports an odd access alert on their account.

What you do

  1. Their sessions are closed and the password changed
  2. Two-factor is made mandatory for the whole organisation
  3. Their log is reviewed: nothing was downloaded

What you get

The scare closes in half an hour and the organisation comes out with protection it did not have before.

The situation

Access appears from an unexpected location.

What you do

  1. Closes the sessions and changes the password

What you get

Access is cut while it is investigated.

The situation

There is a suspicion and nobody knows what was touched.

What you do

  1. Checks that session's log

What you get

The scope becomes known.

The situation

Raising it is delayed out of uncertainty.

What you do

  1. Raises it anyway and documents the suspicion

What you get

The response does not wait for certainty.

The situation

The second factor was switched off.

What you do

  1. Turns it on for everyone after the incident

What you get

The cause is closed.

The situation

There is no record of what was done.

What you do

  1. Records what was done and when

What you get

The incident can be explained.

This article answers

  • i think someone accessed our account
  • unauthorised access what do i do
  • an employee's password was stolen
  • close open sessions