Email comes first even when email is not what was compromised, because it is the reset mechanism for everything else. Whoever controls it can request password resets on your bank, your domain, your payment processing, and your customer systems. Securing it is what stops the situation spreading while you work out what happened.

Then look for persistence, which is the part that gets missed. Attackers commonly add a forwarding rule so they continue receiving copies of your mail, add a recovery email or phone number so they can regain access later, or authorise a connected application that retains permission independently of your password. Each of those survives a password change and none of them are visible unless you go looking. Check forwarding, filters, recovery details, connected applications, and active sessions, then sign out everywhere.

Change the password everywhere the same one was used, which is usually more places than you remember. Compromises of small businesses are overwhelmingly automated attempts using credentials leaked from somewhere else, which means one exposed password is a key tried against every account you own. This is also the moment that makes the case for a password manager permanently.

Contact your bank immediately if money is involved rather than waiting to establish what happened. Recovery windows for fraudulent transfers are measured in hours rather than days, and a bank informed while the transaction is pending has options that disappear once it settles. The same urgency applies to your payment processor if customer payments are affected.

Work out what was exposed rather than only how they got in, because your obligations depend on it. If customer personal information was accessible, you may have notification duties under state law, and Nevada has its own requirements alongside any that apply through the states your customers live in. Establishing what data was in reach is the first step toward knowing whether that applies.

Preserve the evidence before cleaning up. Screenshots of the unfamiliar rules, the login history showing unexpected locations, and the timestamps. If this becomes an insurance claim, a police report, or a notification, the record made at the time is considerably more useful than a reconstruction, and cleaning first destroys it.

Turn on two factor authentication on everything as part of the recovery rather than as a later project, because this is the moment the value is obvious and the effort is justified. An authenticator application is meaningfully better than codes by text, since the text method is vulnerable to somebody persuading a mobile provider to transfer your number.

Then tell anybody affected, promptly and plainly. If a customer received a message from your account, or a supplier was contacted, they need to know before they act on it. That conversation is uncomfortable and it is considerably less damaging than the alternative, which is somebody discovering it independently and wondering what else you did not mention.

Assume the compromise is broader than the evidence until you have checked, because attackers rarely stop at one account. If a password was reused anywhere, treat every account using it as affected regardless of whether anything looks wrong, since the automated attempts that produce these incidents work through a list rather than targeting one service.

Then write down what happened while it is fresh, including the timeline and what you changed. That record is what lets you answer questions from a bank, an insurer, or a customer later, and it is also what tells you which gap to close so the same route is not available a second time.