What to Do if You’ve Been Hacked – And How to Avoid it

What to Do if You’ve Been Hacked

According to an October report compiled by the nonprofit ‘Identity Theft Resource Center’ (ITRC), 2022 could well be the seminal year for data breaches.

This assumption is based largely on recent trends, with the total number of breaches recorded up to September 30th, 2021 exceeding the cumulative amount through the previous year.

In total, more than 281.5 million people were affected by large corporation data breaches through 2021 alone, and this number is definitely expected to increase markedly this year.

So, while there’s a tendency to believe that big businesses are the ones that suffer in the event of a successful data breach, it’s the private data of individual customers that’s immediately placed at risk. As customers, we’re also at the risk of individual attacks by hackers, so it’s crucial that we take steps to avoid being targeted and learn how to react in the event of our data being compromised.


How Do You Know if You’ve Been Hacked

How Do You Know if You’ve Been Hacked

In instances where your data is compromised as part of a corporate data breach, you’ll find that news of this event spreads like wildfire in a matter of hours.

So, even if the corporation in question is slow in contacting you and confirming the details of the attack, you can keep yourself fully informed simply by following the news as it unfolds online.

But what if you’re the sole victim of a stealth attack? For example, your credit card could be compromised or replicated by a nefarious online merchant or simple card skimmer, while snippets of your identity could be used to open mail order accounts or take out lines of credit.

In these instances, you probably won’t be aware of the attack until a select few unexpected and random purchases begin to appear on your relevant statements. Typically, thieves will make a relatively small number of initial purchases that are spaced out, making it harder for you to spot these on your monthly billing information.

Banks and lenders also utilise increasingly sophisticated fraud detection systems in the digital age, meaning that a sudden excess of large-scale purchases are more likely to be spotted prior to a particular card or account being blocked.

If scammers utilise your personal data to launch a less direct attack (such as opening credit accounts and apply for loans), you may find that this practice goes undetected for considerably longer. In fact, you may only be alerted either when applying for a new line of credit yourself (this is likely to be rejected if a rogue account remains open and unpaid in your name) or through the process of regularly checking your credit score.

Through relatively advanced phishing attacks, hackers may also use a compromised email account to share malicious spam or potentially issue targeted messages to people listed in your contacts. The latter is commonly referred to as ‘spear’ phishing, as it’s more targeted in nature and attacks individuals rather than corporations and entities en masse.

With this type of attack, you may become aware of precisely what’s happening a little sooner. For example, a common iteration of the scam is to send a message from a duplicate of your email account claiming that you’re stranded at an airport overseas, urging the recipient to send money urgently to help you out.

So, your more savvy friends may well call or message you asking if you’re OK and genuinely in need of help, alerting you to the fact that something may be amiss.


Once You’ve Been Hacked – The Next Steps

Being alerted to the attack is the first step in a potentially long and extended recovery, and at this stage it’s important to remain calm and measured in your response.

The precise steps that you take will depend on the nature of the attack too, so we’ve outlined the desired response based on different types of hack. These include:

  • #1. Recovering From Credit Card Fraud: We’ll start with what’s arguably the easiest type of fraud to overcome, particularly in the age of increasingly proactive banks and financial lenders. In instances where your credit or debit card details are used by a cyberthief, you won’t be responsible for any fraudulent charges, while the lender will refund any stolen cash once the fraud has been established. In fact, all you’ll have to do is update your payment information and associated passwords in the relevant locations online.
  • #2. Regaining Control of a Compromised Email Account: Now for something a little more challenging, as this will require you to contact your email provider and share demonstrable proof that you’re the true owner of the account (such as photographic identification or the provision of answers to specific security questions). Often, a hacker will change the password to your email account, so you may have to create a new address from which to contact the provider. Once you’ve proved your identity and reset your account information, you can create a new and hopefully more secure password (we’ll touch more on this below).
  • #3. Recovering Your Identity: If you’re the victim of full-scale identity theft, who can end up spending huge amounts of time and money trying to reclaim your online self. Because of this, it’s important to seek out expert help with this process as quickly as possible, initially by reporting instances of identity theft via Action Fraud on 0300 123 2040. The independent organisation Citizens Advice can also provide step-by-step advice on how to recover from identity theft, but the key is that you’re proactive in your response and raise the issue as a matter of urgency.

Now for the Important Stuff – How to Avoid Being Hacked in the First Place!

Perhaps the biggest contributing factor to cybersecurity threats is a lack of action, as people are too reactive in their approach and fail to safeguard their accounts and online identity in the first place.

Certainly, experts are united in their belief that the majority of victims impacted by large-scale data breaches do nothing at all to further protect themselves, making them viable targets for future hacks and malicious attacks.

Ultimately, reacting to an online attack or instance of cybertheft represents little more than damage limitation, at which point your data or finances have already been breached. So, it’s far better to create a proactive mindset and implement preventative measures to protect your information online, focusing on specific types of fraud and the risks that you deem most relevant.

Fortunately, we’ve prepared a brief guide to help you avoid being hacked and maintain the integrity of your online data! So, let’s get into it.

#1. Get Serious About Your Passwords

Even the best protected accounts can be compromised on a poorly secured website, but the use of an overly simple and repetitive password exposes you to uncomplicated and often brutal attacks from relatively unskilled hackers.

What’s more, this is a surprisingly common security issue, with a list of the most popular passwords (from analysis of around 15 billion online accounts) including entries like ‘123456’, ‘qwerty’ and the iconic ‘password’. Each of these passwords can take less than a second for a seasoned hacker to access, leaving account data and personal information laid bare.

Ultimately, the best and most secure passwords should comprise a random combination of letters, numbers and symbols, while also featuring both upper and lowercase letters where possible.

Ideally, this will create a unique, alphanumeric phrase that contains between eight and 12 characters, establishing a much greater barrier between access to your account and would-be hackers.

You should create such a password for each online account and app, taking care to ensure that you don’t utilise the same phrase or alphanumeric sequence on multiple occasions.

Of course, you’ll need a secure and encrypted password manager to keep up-to-date with what may be an extensive list of passwords, but this at least enables you to safeguard individual accounts while making the process of managing and updating these through a single interface relatively easy.

Certainly, you should look to update your passwords every three months or so, in order to stay at least one step ahead of potential hackers.

#2. Use a VPN

Use a VPN

Another excellent way of securing your devices and data is to use a VPN (virtual private network), which is often discussed in relation to streaming video content and accessing restricted geographical libraries through platforms like Netflix.

But what exactly is a VPN and what does a VPN do? In simple terms, they can create a secure private network within a public Internet connection, routing your data through an encrypted tunnel that masks the content that you’re transmitting from an Internet service provider.

Through a VPN connection, the provider can only see a stream of encrypted data as it travels from one device to another, while the sender’s unique IP address is also masked and remains invisible at all times.

It’s the latter point that allows users to access restricted content while streaming, but it also delivers immense security benefits across the board.

For example, masking your IP address also makes your device and its stored data completely invisible to cyberthieves, immediately minimising the risk of malware, ransomware and DDoS (Denial of Service) attacks. Sure, it’s still possible for devices with an active VPN connection to be hacked, but the task is much harder and cyberthieves are known to target more accessible and less protected  individuals.

Clearly, the meaning and purpose of a VPN is often misunderstood, and it can provide significant protection at times when your device is surfing online, streaming content or connected to a vulnerable public Internet connection.

The key is to identify a reputable and effective VPN service provider, ideally one that boasts exceptional network coverage and flexible pricing that can be tailored to your usage.

#3. Utilise Two or Multi-Factor Authentication

For some email accounts and app providers, you’ll have the opportunity to enact two or multi-factor authentication as a way of optimising online security.

But how exactly does this work? Well, in the case of two-factor authentication, an attempted login will generate a unique numerical code, which is subsequently sent to a separate and registered device (such as your smartphone).

This will typically be delivered via SMS, at which point you’ll have a limited window in which to enter the unique code and your password to secure access to your account.

This provides an additional and corporeal layer of security to your online accounts, as a hacker must have real-time access to both your password information and your mobile phone to successfully log in. With multi-factor authentication, you can incorporate additional devices and methods of authentication, enhancing an already secure process further.

Where possible, you should look to activate two or multi-factor authentication on your accounts and devices, while combining this with the type of strong and unique passwords referenced earlier.

#4. Streamline Your On and Offline Presence

When it comes to avoiding cybertheft, your objective should once again be to implement measures that deter hackers and establish yourself as a difficult and challenging target.

There are a couple of ways in which you can achieve this objective. Firstly, we’d recommend that you avoid filling out any unnecessary data on web forms or online surveys, particularly key information like your email or physical addresses.

If you’re asked to fill this information in but the data is completely irrelevant to what you’re trying to achieve, enter spurious text that’s fake and doesn’t tie into your on or offline persona.

Remember, the goal here is to minimise the scope of personal information that’s available online, while making this less accessible to hackers.

For those of you who still have paper bills and statements, it’s crucial that you don’t simply throw old or unwanted letters out with the garbage. This is because identity thieves can also target your information through offline channels, and it would be a shame to protect your online accounts only to have your personal data accessed elsewhere.

So, invest in a cheap and handy shredder for all statements and paper bills, ensuring that they’re completely destroyed prior to being discarded in the recycling bin.


The Last Word

Responding proactively to instances where your information or accounts have been hacked is crucial, while some of the key measures here (such as deploying more secure passwords and checking your credit report) should also be continued on a more regular basis.

These measures, coupled with the use of a reputable VPN and multi-factor authentication where relevant, can significantly boost the security of your online accounts and make you less vulnerable to the machinations of hackers in the future.

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

Similar Posts