---
id: KB-AD-007
url: https://app.codecontract.io/help/administration/what-to-do-if-you-suspect-unauthorised-access
idioma: en
categoria: administracion
audiencia: administrador
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-AD-002, KB-AD-006, KB-AD-016]
citadoPor: [KB-AD-009, KB-AD-012, KB-AD-019]
---

# If you suspect someone got in

_The first twenty minutes, in order, and who to tell._

**Responde a:** i think someone accessed our account · unauthorised access what do i do · an employee's password was stolen · close open sessions

The instinctive reaction is to investigate first. It is the wrong one: while you investigate, whoever got in is still inside. The right order is close, then look, and notify in parallel.

## The first twenty minutes

1. **Close that account's sessions** — And change its password. It is the only urgent thing; everything else can wait ten minutes.
2. **Enable or require two-factor** — If it was not on, that is how they got in. A stolen password without a second factor opens the whole door.
3. **Read that account's log** — What was opened, what was downloaded and from where. Now it is time to investigate.
4. **Notify the right people** — The affected person, and whoever handles data protection if third-party data was reached.

## What to look for in the log

| Signal | What it usually means |
| --- | --- |
| Bulk downloads | Someone taking information, not a mistake |
| Access from a place or time that does not fit | Check first whether that person was travelling |
| Permission changes | An attempt to keep access after you close it |
| A contact or bank account modified | Fraud in progress: check this before anything else |

> [!IMPORTANT]
> If third parties' personal data was reached — payroll, identity documents, client files — there may be notification duties on short deadlines. Tell whoever handles data protection that same day, even before you know the scope.

> [!WARNING]
> Do not delete anything while investigating, not even to tidy up. The log is what lets you know what happened and prove how you responded.

> [!NOTE]
> The commonest cause is not a sophisticated attack: it is a password reused on another service that leaked. Which is why mandatory two-factor is the measure that returns most for how little it costs.

**Can I see whether they downloaded anything?**

Yes, accesses and downloads are logged.

**Do I notify affected clients?**

That decision is not only technical. Let data protection make it with your adviser.

**What if it was a false alarm?**

All the better. Closing one session too many costs one person a minute.

## Ejemplos

**An employee reports an odd access alert on their account.**

- Their sessions are closed and the password changed
- Two-factor is made mandatory for the whole organisation
- Their log is reviewed: nothing was downloaded

→ The scare closes in half an hour and the organisation comes out with protection it did not have before.

**Access appears from an unexpected location.**

- Closes the sessions and changes the password

→ Access is cut while it is investigated.

**There is a suspicion and nobody knows what was touched.**

- Checks that session's log

→ The scope becomes known.

**Raising it is delayed out of uncertainty.**

- Raises it anyway and documents the suspicion

→ The response does not wait for certainty.

**The second factor was switched off.**

- Turns it on for everyone after the incident

→ The cause is closed.

**There is no record of what was done.**

- Records what was done and when

→ The incident can be explained.
