Contain before investigating

The first instinct is usually to "figure out what happened." That's a mistake: every minute a compromised device stays connected is another minute for the attacker to move to other systems or extract more data. Contain first, investigate later.

Step 1: isolate the device, don't power it off

Unplug the network cable and turn off WiFi on the affected device. Don't power it off if you suspect something more serious than simple malware: powering off can wipe evidence in memory that helps understand what happened. Just isolate it from the network.

Step 2: change passwords from ANOTHER device

If you used that device to access email, banking, or management systems, change those passwords immediately — but from a different, trusted device, never from the suspect one, since a keylogger would capture the new password too.

Step 3: enable MFA everywhere it's missing

If any critical service (email, systems administration, banking) still doesn't have multi-factor authentication, turn it on right now. It's the most effective barrier against a stolen password being used — see password and MFA best practices.

Step 4: notify support immediately

Contact [email protected] or WhatsApp (+39 345 243 5103), flagging the case as severity S1 or S2 depending on impact — see what each severity level means. The sooner technical support is involved, the faster the incident can be contained and other systems checked if needed.

Step 5: document what you remember

Note what you did before noticing the problem (did you open an email? install something? visit an unusual site?), the approximate time, and any strange message or behavior you saw. That information speeds up technical analysis significantly.

What not to do

Don't try to "clean" the device yourself by uninstalling programs or running antivirus before support reviews it — you could erase evidence needed to understand the real scope of the incident.