Someone says they have your customer database. They give you a deadline. Perhaps they include a spreadsheet that looks familiar.
You now have a problem to investigate. You do not yet necessarily know what that problem is.
New Zealand insurer Tower is in that uncomfortable position. A criminal group claims it obtained Tower data. In its statement to Insurance Business, Tower describes the information as unverified. It says it is working with external cybersecurity consultants, has notified relevant authorities and is continuing heightened monitoring. It says customers or stakeholders identified as affected would be contacted immediately.
As of 4 October 2026, that account does not establish a confirmed ransomware breach or theft of customer information. A criminal leak-site listing is a claim, not a forensic finding.
For a smaller business, the useful question is what to do during that gap between receiving an allegation and knowing what happened.
Name the uncertainty properly
The first warning might arrive through an extortion email, a journalist, a supplier or a customer complaint. Someone might find credentials online or contact the business directly with a threat.
The claim could be genuine, exaggerated or fabricated. The information might be old, copied from a third party or assembled from another breach. An old password can be real without proving current access to your email.
I would keep four descriptions separate:
- Allegation: someone claims an incident occurred.
- Suspected incident: there is enough concern to investigate possible compromise.
- Confirmed unauthorised access: evidence establishes that someone reached a system or account without permission.
- Confirmed data breach: evidence establishes that information was accessed, disclosed, lost or otherwise compromised in a way it should not have been.
These are working distinctions, not a legal notification test or a sequence every incident follows. Data can be exposed without someone breaking into your server.
Neither “we've been hacked” nor “nothing happened” is a useful reflex. “We are investigating this claim” can be accurate, provided someone is actually doing the investigation.
Preserve what arrived and what your systems recorded
Do not delete the threatening email. Retain the original message with full headers, rather than relying on a forwarded copy or screenshot. Headers can help establish how it arrived; the sender name alone tells you very little.
Keep screenshots of claims already available to you, with the address, date and time recorded. Preserve attachments without opening unfamiliar files on an ordinary work computer. Let a qualified responder handle suspicious material and any further collection from criminal sites.
Ask your providers to preserve relevant server, website, email and authentication logs before routine retention removes them. Record suspicious account activity, unexpected forwarding rules and changes to administrator access. Include timestamps and time zones. A login recorded in UTC and a phone call recorded in Sydney time need aligning before they form a useful chronology.
Keep originals securely, limit access and record who collected each item. Relevant devices may need preservation too; get advice before resetting or repurposing them.
New Zealand's NCSC explains in its centralised logging guidance that logs help establish when an incident began and how it happened. That usefulness depends on the records still existing.
Evidence preservation does not mean leaving an attacker connected. Contain immediate risk while avoiding unnecessary destruction of the records needed to understand it.
Do not let cleanup become a second problem
Deleting an account, wiping a server or rebuilding a website can remove evidence along with the suspicious activity. Rotating every credential without coordination can break services and make the sequence harder to reconstruct.
That does not justify delaying an urgent credential change. If an attacker is actively using an account, disable access, revoke sessions and rotate exposed credentials as appropriate. Use a trusted device and record what changed and when. A responder may isolate a device or service while preserving it for examination.
Where it is safe, capture relevant logs and account settings before changing them. Where waiting would allow further harm, contain first and document the decision. The order depends on the risk, not a rigid checklist.
My Mathspace incident-response article covers the related distinction between fixing a weakness and establishing whether somebody used it. A clean replacement server cannot answer every question about its predecessor.
Establish what the claimant could actually have
Start with the material available. Does a sample match records the business holds? Are there internal references or recent details that would not normally be public? Could the same information have come from an old export or a supplier?
Do that comparison in a controlled setting. Circulating a supposed customer-data sample to everyone in the office creates another copy of potentially sensitive information.
Then connect the claim to independent records. Look for relevant sign-ins, downloads, account changes or unusual application activity. Establish which account or service was involved, what it could reach and the period the available evidence covers.
Supplier-held information needs its own enquiry. A real document in an extortionist's possession does not, by itself, identify which organisation lost it. The third-party cyber risk article explains why those relationships belong in the investigation.
Missing logs limit the answer. “We found no suspicious activity in the records available” is different from proving that no access occurred. Document the gaps alongside the findings.
Communicate facts without waiting for perfect certainty
Give one person responsibility for coordinating updates. Keep a short record of what is known, what remains uncertain, who is checking it and when the next update is due.
An initial message might say that the business has received a claim, is investigating with technical assistance and will contact people if action is needed. Only describe steps actually taken. Avoid assurances about customer information until the evidence supports them.
Reporting and advice should happen alongside the technical work. Contact your insurer or broker promptly about policy notification conditions and approved assistance, and involve legal or privacy advisers where needed. Preserve the threat for reporting to the appropriate cyber authority or police.
For New Zealand organisations, the Privacy Commissioner’s NotifyUs guidance says serious privacy breaches must be notified, with affected people also told unless an exception applies. The office expects notification ideally within 72 hours of awareness of a notifiable breach, even while investigation continues. That guidance is not permission to wait for a complete forensic report. Australian businesses need their own applicable obligations assessed.
Careful wording and timely notification can coexist.
The small-business version needs an owner
Most SMEs do not have incident responders, internal counsel, security analysts and a communications team waiting for the phone to ring. The owner may be answering customers while the web developer tries to locate the hosting account.
The sensible sequence is to preserve what you have, verify what you can, contain obvious risk, get qualified help and communicate carefully. Some of those jobs happen together. Assign them explicitly so everyone does not assume somebody else has called the provider.
Solway Web Consulting's small-business cybersecurity support connects website and server security, secure hosting arrangements, domain and DNS ownership, authentication and email security. Knowing how those systems fit together helps initial incident triage: fewer hours disappear into finding accounts, locating logs and establishing who can act. Specialist forensic assistance may still be needed.
For private and HNW clients, the same uncertainty can involve claims about private photos, cloud files, identity documents, credentials, personal email or household systems. The claim itself is not proof. Establish what the extortionist actually possesses without spreading private material further during the enquiry.
When someone claims to have hacked you, the first job is to establish what is actually true. Preserve enough evidence to answer that question, and protect the business while you find out.
Tags: security, small-business, private-client, australia