Investigating a hacked or taken-over account
With a taken-over account the question is rarely only how to get back in. More often it is what happened meanwhile, and what else could be reached.
What we examine
- How the access came about, as far as that can be derived from what is available.
- From which devices and at which times sign-ins occurred.
- What was changed during that access: passwords, recovery methods, forwarding rules, linked devices.
- Whether the same password was in use elsewhere and whether there was access there too.
- Which data may have been viewed or downloaded.
What you receive
A report setting out what happened and in what order, with the record attached.
A list of what was changed and what needs putting back, so nothing is left open.
For a company, an assessment of whether notification to the regulator or to those affected is needed. That judgement is yours; we supply the technical basis for it.
What we do not do
- We do not restore access to accounts that are not yours and whose ownership you cannot demonstrate.
- We do not approach the other party.
- We cannot guarantee all traces still exist. Many services keep sign-in records for a limited period, so the longer you wait, the less there is to see.
Do not wait too long. At many services the data this investigation rests on disappears within weeks.
Tell us what you are seeing. We will take it from there.