A client who works from home rang us one Saturday evening, worried their home network had been hacked. For someone whose work lives on the same computers and the same internet connection as the rest of the household, that’s not a worry that can sit until Monday.
We gave advice on the phone that evening, then went to the house to check properly. We logged 3.5 hours on it.
Advice on the phone first
The first priority was to cut off any access someone might already have. We advised that if the router had been compromised, a factory reset would remove any unauthorised access to it. A reset wipes the router’s settings back to how it left the factory, which clears out anything an intruder may have changed.
Checking the computer
On site, we started with the main computer. It already had antivirus software, so we checked its logs. There was no suspicious activity recorded.
A clean antivirus log is reassuring, but it isn’t the end of it. So we added our own monitoring and security tools, ran a full audit of the system, and set it to send logging data to our offsite server for deeper analysis over the following days.
The door that was open
A diagnostic scan of what starts with Windows turned up something worth a closer look: a remote access program, the kind used to let someone control a computer from somewhere else.
Its logs showed unattended access was enabled. That means someone with the right details could connect to the computer without anyone at the keyboard accepting the connection.
Programs like this are often installed for a legitimate reason, a support call years ago or a family member helping out, and then forgotten. Left in place with unattended access switched on, they’re an open door. We removed it completely.
A full malware scan afterwards came back clean.
The router and the rest of the network
Next was the router. We updated its firmware to the latest version. Router firmware updates often close security holes, and routers rarely update themselves.
We checked the other computers on the network and found no issues. Then we checked three mobile phones, and added antivirus and monitoring to one of them.
What we found
Across the computers and phones, we found no evidence of compromise. The computers were protected with added monitoring, and data kept flowing to our server so any anomaly would be picked up.
That’s a good result, and worth being clear about. A scare doesn’t always mean a hack. But this one did find a real risk, the remote access program, which is now gone.
If you work from home
Your home network is your work network. A few checks go a long way:
- Look through the programs on any computer you work on and remove remote access software nobody uses.
- Update your router’s firmware, or ask your internet provider how.
- Keep work on devices that have security software and updates switched on.
- If something feels wrong, ring someone that day. After-hours support exists for a reason.
If you’d like us to check your home office set-up, get in touch.
