Cybercrime
Cybercrime uses a computer, phone, account, network, digital identity, or online platform as the target, evidence source, or tool of a crime.
Cybercrime includes unauthorized account or network access, malware, ransomware, data theft, identity theft, extortion, impersonation, cyberstalking, payment fraud, and crimes coordinated through digital systems.
A strange message or device problem does not automatically prove an attacker has access. The first task is to identify the observable event: a login, password change, forwarding rule, transaction, file encryption, data exposure, impersonation, or threat.
Sources: FBI IC3: Internet Crime Complaint CenterFBI IC3: Data Breach Response
Changing one password may not end the compromise. Attackers can retain active sessions, recovery email addresses, phone numbers, application passwords, forwarding rules, trusted devices, API tokens, cloud access, or malware on a device.
The entry point may be phishing, password reuse, a fake support call, malicious software, a stolen session cookie, a data breach, a relationship with legitimate prior access, or an exposed business system.
Sources: FBI IC3: Data Breach ResponseCISA: Use Logging On Business Systems
Separate proof of access from threatening claims. Sextortion and ransomware messages sometimes include an old password or public information without current access.
- Successful login alerts, unknown sessions, recovery changes, forwarding rules, password resets, or new devices.
- Transactions, messages, posts, files, account settings, or security changes you did not make.
- Malware findings, encrypted files, disabled security tools, unusual network traffic, or repeated access after passwords change.
- Platform, carrier, bank, employer, or security-provider records confirming unauthorized activity.
Sources: FBI IC3: Data Breach ResponseCISA: Use Logging On Business Systems
Cyber evidence is time-sensitive. Logs rotate, sessions expire, accounts are deleted, and reinstallation can remove local artifacts. Balance immediate containment with preservation based on the seriousness of the incident.
- Full message headers, original emails, texts, DMs, links, usernames, profile URLs, phone numbers, domains, and files received.
- Login history, IP addresses, device lists, recovery settings, forwarding rules, account changes, and security alerts.
- Bank, payment, cryptocurrency, shipping, carrier, platform, and transaction records with identifiers and timestamps.
- System, firewall, authentication, application, cloud, and endpoint logs for a business or network incident.
- A timeline showing first sign, accounts affected, actions taken, support contacts, reports, and whether access continued.
Sources: FBI IC3: Internet Crime Complaint CenterFBI IC3: Data Breach ResponseCISA: Use Logging On Business Systems
- A personal account takeover usually requires immediate password and session changes, while a serious business intrusion may require forensic capture before systems are rebuilt.
- Taking screenshots helps document what you saw, but screenshots alone may omit headers, logs, URLs, metadata, and original files.
- Resetting one device does not secure cloud accounts, recovery channels, routers, email rules, or other devices.
- Anyone who privately offers to hack back, recover an account, or retrieve money for a fee may be running a recovery scam.
Sources: FBI IC3: Data Breach ResponseCISA: Use Logging On Business Systems
Use a clean device when the affected device may be monitored. For a business, preserve critical logs and involve the responsible IT, security, legal, and insurance contacts before evidence disappears.
- Stop active financial loss and immediate danger by contacting banks, platforms, carriers, employers, or emergency services through verified channels.
- From a clean device, change unique passwords, end active sessions, secure recovery methods, and enable strong multifactor authentication for personal accounts.
- Preserve messages, alerts, logs, transaction records, affected devices, and the response timeline; obtain professional forensic help before rebuilding a serious business system.
- Report internet-enabled crime to IC3 and use the police, FTC, CISA, platform, insurer, regulator, or attorney channels that apply to the incident.
Sources: FBI IC3: Internet Crime Complaint CenterFBI IC3: Data Breach ResponseCISA: Use Logging On Business Systems
How do I know whether I was actually hacked?
Look for confirmed access or change: unknown successful logins, sessions, recovery changes, transactions, messages, files, forwarding rules, malware, or provider records. A threatening email alone is not proof.
Should I preserve evidence before changing passwords?
Capture the alerts, login history, recovery settings, messages, and transaction details you can reach quickly, but do not delay stopping active theft or account takeover. Serious business incidents need a coordinated forensic response.
Why does the attacker return after I change the password?
The attacker may retain an active session, recovery channel, forwarding rule, trusted device, application token, malware foothold, or access to the email account used for resets.
Can someone online recover or hack back my account?
Only the platform or a legitimate authorized professional can use the proper recovery process. Unsolicited private messages promising recovery or hacking services are a common second scam.