1/3

InsightWays — Predictable Migration Strategy | Watch the Session

2/3

New GUI for SQLWays | Watch the Live Product Tour

3/3

IDM: New Way to Automate Data Migration | Watch the Session

How Do You Know If Your Company Is Already Compromised? 7 Hidden Signs

Summary: Many companies never lack security tools, they lack a rule for what happens when one alert looks strange without being obviously bad, and that gap is what turns a 14-day intrusion into one that lasts months. This piece walks through the seven company compromised signs hiding in systems you already run, from identity logs to backup consoles, plus a two-page incident response plan built on NIST guidance for the day one of them turns out to be real.

·
Talk to expert
How Do You Know If Your Company Is Already Compromised? 7 Hidden Signs

Companies that end up sending breach notifications rarely skipped security. They had firewalls, endpoint protection and a password policy with an owner.

What failed was visibility. The first traces of an intruder looked like ordinary weekday activity, and nobody had a reason to look twice.

Three cases from 2025 show how quiet that looks. All three happened inside companies that sell security for a living, which is exactly why they are worth reading.

In August 2025, F5 found that a nation-state group had held long-term access to its BIG-IP product development environment and engineering platforms. The company disclosed the incident on 15 October, Bloomberg's sources put the intruders inside the network for at least a year, and CISA issued an emergency directive the same day.

In September 2025, SonicWall reported suspicious activity against its cloud backup service. The first estimate covered fewer than 5% of customers; the investigation closed in October and confirmed that everyone who had used the service was affected.

Also in August 2025, attackers stole OAuth tokens from the Salesloft Drift integration and pulled Salesforce data from more than 700 organisations. The victim list included Cloudflare, Zscaler, Palo Alto Networks and Proofpoint.

The industry produces a steady supply of these stories: antivirus companies compromised through their own suppliers, a software company hacked at the build level, a tech company hacked through a token it issued and forgot. Each of them also travels downstream, because a stolen configuration file or a leaked token becomes an exposure for every organisation that trusted the integration.

None of those teams were careless. They had security staff, budgets and their own threat intelligence, and the intrusions still ran quietly for weeks. The conditions that allow it are more common everywhere else: alert volume, patchy logs, attackers imitating administrators.

What a cybersecurity company hacked in 2025 has in common with everyone else

All three cases followed one route: valid credentials or valid tokens, activity that matched normal administrative behaviour, and a scope that grew after the first assessment.

That route has nothing to do with the industry the victim works in. Vendors publish detailed post-mortems because regulators, customers and stock exchanges require it, which makes their intrusions easier to study. The mechanics are the same in a logistics firm, a clinic or an accounting practice, and so are the reasons nobody notices for weeks.

Mandiant's M-Trends 2026 report, built on more than 500,000 hours of investigations across every sector during 2025, puts the global median dwell time at 14 days. Espionage cases and intrusions involving fraudulent IT workers reached a median of 122 days.

Who finds the intrusion changes the arithmetic:

How the breach came to light

Share of cases, 2025

Average cost of the breach

Internal security team or tooling

52%

USD 4.18 million

Notification from an outside party

34%

USD 4.43 million

The attacker announced it

14%

USD 5.08 million

Detection shares:Mandiant M-Trends 2026. Costs:IBM Cost of a Data Breach 2025.

The gap between the top row and the bottom row is about USD 900,000, plus several weeks in which someone else controls the timeline.

"The teams we assess almost never lack alerts. They lack a rule for what happens and what to do when one alert is strange without being obviously bad. That gap costs nothing to close. It needs a named owner and a written escalation path." 

Ispirer Security Lab expert

How do businesses detect hacking?

There are two routes. Someone outside tells you, or your own people notice something that does not reconcile.

The second route depends on knowing what normal looks like in your environment. The seven signals below are signs of a compromised company that appear repeatedly in incident reports published over the past two years.

Most of them have an innocent explanation on their own. Two or three in the same month change the odds.

None of the seven requires a monitoring platform you do not already own. The evidence sits in consoles you already pay for: the identity provider, the mail platform, the database, the backup service.

1. Identity events nobody asked for

A new device enrolled in MFA, a password reset for someone on holiday, a push notification approved at 03:40, a sign-in from a country where you have no staff.

Stolen credentials remain the thread running through more breaches than any other technique in the Verizon 2026 DBIR, which makes identity events the highest-value company compromised signs available to a team without round-the-clock monitoring.

Microsoft 365 and Google Workspace both send these events to an administrator once the setting is switched on. Route each one to the account owner as well, so verification takes a single message.

2. Alerts that were closed as routine

Attackers work with the same tools your administrators use. The 2026 DBIR records a sharp rise in attacker use of remote monitoring and management software, and M-Trends 2026 describes groups that stay inside existing tooling and clear the forensic artefacts behind them.

Keep a short list of alert types that always get a second pair of eyes:

  • directory replication requests from unexpected sources
  • changes to domain administrator group membership
  • new RMM or remote access software on any endpoint
  • authentication from a new country or hosting provider
  • an account that suddenly gains privileges it never had

If an external provider handles your IT, agree which of those events reach you directly, and which they are allowed to close inside their own ticket system.

3. Company credentials appear in a breached credentials database

Most ransomware victims in the 2026 DBIR had an infostealer infection or a credential leak during the year before the attack, and half of those saw it within 95 days of the ransomware landing.

Those three months are a usable head start, and most companies never use them. Roughly two in five organisations do not watch breached databases at all, or cannot say whether anyone does.

A scheduled database breach check across your own domains should cover staff, contractors and service accounts. Domain-level monitoring services make it a monthly task, and a breached database then works as your early warning.

4. Reads in your data stores that nobody scheduled

Exfiltration looks unremarkable in the logs. In the Drift case, the attackers counted records first, then exported the objects worth taking, using legitimate tokens throughout.

The most useful database breach indicators are behavioural:

  • a service account querying tables it has never touched
  • export volumes that spike outside business hours
  • a reporting user issuing writes
  • a bulk job with no ticket behind it
  • API calls from an integration you retired months ago

Data aggregators attract exactly this attention. In the 2024 background check company breach at National Public Data, the company said the intrusion attempt began in late December 2023, with data leaking from April 2024. That background check company data breach reached the public in August 2024 through a class action.

5. Backup and recovery systems behaving strangely

Anyone planning to extort a company looks at the backups first. M-Trends 2026 describes a shift towards recovery denial, where the intruder degrades the systems you would use to restore yourself before deploying anything visible.

Signals worth checking every week:

  • backup jobs failing quietly, or finishing far faster than usual
  • retention periods shortened by someone who cannot say why
  • a new account or new permissions on the backup console
  • snapshots or immutable copies deleted ahead of schedule
  • restore tests that stopped being scheduled at some point

"We always ask if anybody checks the results of backup jobs, when someone last restored from a backup and how often back ups are tested. Having backups and being able to restore from them are two different things, and companies tend to discover the difference on the worst possible day." 

Ispirer Security Lab expert

6. Quiet changes in configuration you trust

Dormant administrator accounts, mailbox forwarding rules created last quarter, an OAuth application connected to your CRM by someone in marketing, a remote access tool your IT provider installed for one project, a firewall configuration backup sitting in a vendor's cloud.

The SonicWall case shows what the last one carries: network topology, VPN definitions, access rules and encrypted credentials in a single file.

Third-party access is now involved in almost half of the breaches recorded in the 2026 DBIR, and missing MFA on vendor cloud accounts is one of the slowest gaps to get closed. A monthly review of who and what holds standing access takes about an hour.

7. The first notification comes from outside

A customer asks about a strange invoice, a partner's security team calls, an insurer flags a claim pattern, or an extortion note arrives in the inbox.

Speed still matters after that moment. Aflac, an insurance company hacked in June 2025, told regulators that it identified unauthorised access on 12 June and believes it contained the intrusion within hours.

Not sure how many of these seven you could actually see in your environment today?Book a call with Ispirer Security Lab and get a straight answer

A security plan for a company which has been compromised

Judgement under pressure is unreliable, and email may be the system you cannot trust. A security plan for a company which has been compromised has to exist on paper before the day it gets used. NIST published a workable skeleton in April 2025 as SP 800-61 Revision 3.

Stage

What it covers

Who owns it

Typical timing

Decide

Authority to disconnect systems, agreed out-of-band communication channel

Named lead and deputy

First 30 minutes

Preserve

Logs and disk images captured before any rebuild

IT lead or provider, with forensics support

First 2 hours

Contain identity

Revoked sessions and refresh tokens, disconnected integrations, rotated API keys and passwords

IT lead and security partner

First 24 hours

Scope

Written answers on what was accessed, what left the network, whether access continues

Security partner

Days 1 to 14

Notify

Regulators, customers, insurer, bank, law enforcement

Owner or managing director, with legal counsel

GDPR: 72 hours where feasible

Harden and re-test

MFA coverage, least privilege, patching, segmentation, log retention

IT lead and security partner

Weeks 2 to 12

Two rows deserve a comment. Rebuilding a server feels productive and erases the record of what happened, which is why preservation comes before cleanup. Mandiant links many of the longest dwell times to logs that had already rolled over.

Password rotation alone also leaves valid session tokens working. Containment in the Drift incident meant revoking every OAuth token tied to the affected application.

Six things to have ready before anything happens:

✓ Named incident lead and deputy, with mobile numbers printed on paper

✓ A messaging channel independent of corporate email and SSO

✓ A written agreement with your IT provider on who declares an incident

✓ Log retention long enough to investigate a 90-day intrusion

✓ One offline backup copy that someone has actually restored from

✓ Contact details for your bank's fraud desk, insurer and legal counsel

"The plan that works fits on two pages and contains real phone numbers. Companies with a 60-page policy and no out-of-band contact list still spend the first six hours deciding who is allowed to unplug something." 

Ispirer Security Lab expert

Want a plan built around your infrastructure? See what a security hardening covers

How Ispirer works with this

Ispirer has spent 27 years on enterprise data, running database migration and application conversion projects for customers in finance, banking, healthcare, retail and logistics. Alongside those projects the team writes its own software, under the secure development practices required by ISO/IEC 27001:2022, so the products carry the same controls the company applies internally:

Migration projects create the exact conditions described above: access widened for convenience, temporary accounts opened for a sprint, copies of production data in places nobody documented. A team that knows where data lives can tell which read pattern belongs there.

Ispirer Security Lab applies that experience through four services for companies that need the security standards used in banking and insurance without carrying an in-house security department:

  • Security assessment: security report, CVSS-scored vulnerability list, remediation roadmap, executive summary, quick wins
  • Penetration testing: web and mobile applications, external infrastructure, internal network; white box, grey box, and black box
  • Security hardening: MFA, firewall configuration, access control, backup architecture, endpoint protection, logging and monitoring
  • Ongoing advisory: vulnerability monitoring, incident support, review of new systems and changes, staff awareness training

"Most of what we find in a first assessment costs nothing to fix. An administrator account with MFA switched off, a firewall rule someone added for a project that ended years ago, a service account with a password from the original install. The hard part is knowing it is there."

Ispirer Security Lab expert

If any of the seven signs sounded familiar, start with a conversation.Talk to Ispirer Security Lab.

What this comes down to

The signs your company is compromised look mundane on the day they appear: a closed alert, an unexpected password reset, a query at an odd hour, a partner asking a slightly strange question.

Three habits cover most of the gap:

  • write down which anomalies always get a second look, and who looks
  • check your own domains against breached databases on a schedule
  • keep the response plan and the phone numbers somewhere that survives a bad Monday

None of the three needs a budget line, a new platform or a person hired for the purpose. What they change is the answer to the only question that matters once an incident is confirmed: how long was someone inside before anybody noticed.