When people imagine being hacked, they picture something dramatic: a locked screen, a ransom note, an obvious alarm going off. In reality, most breaches are quiet. An attacker who gets into your email or systems usually wants to stay hidden, because the longer they go unnoticed, the more they can steal or set up.
That is what makes the warning signs worth knowing. Often the only clue is something small and easy to dismiss as a glitch. The owners who catch a breach early are usually the ones who noticed one odd thing and asked the question rather than shrugging it off. Here are the signs that something may be wrong, what to do straight away, and why moving quickly matters so much.
Sign 1: Logins From Places That Make No Sense
One of the clearest signals is a login to your email or systems from a location or device you do not recognise. Microsoft 365 and most business systems keep a record of where accounts sign in from. A login from interstate or overseas at 3am, when everyone on your team is asleep in Sydney, is a red flag.
Many systems email you about a “new sign-in” or an unusual login attempt. It is tempting to ignore these, but a genuine unexpected login is exactly the kind of early warning that lets you act before any damage is done.
A stolen password is the most common way in. If an attacker has your credentials but you have multi-factor authentication switched on, the login often fails and you get the alert. Our guide to MFA for small business explains why that second step blocks most account takeovers.

Sign 2: Email Rules You Did Not Set Up
This is one of the most common and most overlooked signs of a compromised mailbox. An attacker who gets into your email will often create a hidden rule that automatically forwards your messages to an outside address, or quietly moves certain emails into a folder you never check, so their activity stays out of sight.
It is worth knowing how to look. In your email settings, check the rules or forwarding section for anything you did not create, especially rules that forward to an unfamiliar address or delete messages containing words like “invoice”, “payment”, or “bank”. If you find one you cannot explain, treat it as a serious warning.
These rules are the engine behind invoice fraud. The attacker watches your conversations, waits for a payment to be discussed, and steps in at the right moment. You can read how this plays out in our guide to business email compromise.
Sign 3: People Getting Strange Messages From You
Sometimes the first person to notice a breach is not you. A client, supplier, or colleague mentions they got an odd email from you: an unexpected request to pay an invoice, a strange link, a message asking them to buy gift cards, or a reply to a conversation you never had. If more than one person says this, take it seriously straight away.
When your genuine account is sending messages you did not write, an attacker is almost certainly inside it, using your credibility to trick the people who trust you. The damage here is twofold: the immediate fraud risk, and the hit to your reputation as contacts start to distrust email from your business.
Do not brush this off as someone else’s spam problem. If the message genuinely came from your address, the issue is on your side, and the sooner you act the less harm it does.
Sign 4: Files Locked, Renamed, or Missing
Some signs are not subtle at all. Files that suddenly will not open, documents with strange new extensions on the end of their names, folders full of content you cannot access, or a note appearing that demands payment, these point to ransomware that has already triggered. At this stage the attacker has usually been in your systems for a while.
If you see this, speed matters enormously. Disconnecting affected machines from the network can stop the encryption spreading to shared drives and other devices. The difference between catching it on one machine and letting it run across the whole business is often the difference between a bad afternoon and weeks of recovery.
Sign 5: MFA Prompts and Slowdowns You Cannot Explain
Two quieter signals are worth watching. The first is unexpected multi-factor authentication prompts: your phone buzzing to approve a login you did not start. That usually means someone has your password and is trying to get past the second step. Never approve a prompt you did not trigger, and change that password immediately.
The second is systems that suddenly run slow, devices that behave strangely, or programs you do not recognise appearing. On their own these can be harmless, but combined with anything else on this list they can indicate malicious software running in the background. The point is not to panic at every slow morning, but to treat a cluster of odd behaviour as a reason to look closer.
What to Do If You Spot the Signs
If you notice any of these, act rather than wait and hope. First, change the passwords on the affected accounts, starting with email, and make sure multi-factor authentication is switched on. Second, check your email for forwarding rules or filters you did not create and remove any you find. Third, if you suspect ransomware, disconnect the affected devices from the network to limit the spread.
Then get expert help quickly. An IT or security professional can confirm whether a breach happened, work out how far it reached, and close the door the attacker came through. Our guide to what happens after a cyber attack walks through the steps in order. Acting early genuinely limits the damage: it is the difference between catching an intruder at the door and finding them after they have emptied the house.
Where to Start
The hardest part is that you cannot watch for signs in systems you have no visibility over. Many owners would not know where to check for a rogue email rule or an unusual login, and that blind spot is exactly what attackers count on.
The fix is to get a clear picture of your current security and the monitoring around it. Our IT maturity assessment gives you a plain-English read in a few minutes and shows where your visibility and protection fall short.
For a documented review of your environment, including how exposed your email and accounts are and what monitoring you actually have, a $990 plus GST IT Audit gives you a prioritised action plan. We are a Sydney-based team in Bella Vista, helping businesses across the metro area spot trouble early and shut it down, with direct access to the engineers doing the work.