Most network breaches aren't discovered the moment they happen. On average, attackers spend weeks quietly operating inside a compromised network before anyone notices — which means the earlier you catch the warning signs, the less damage there is to undo. Here are ten signs worth taking seriously.

1. Unexplained Slowdowns

A network or device that's suddenly sluggish, especially without an obvious cause like a large update, can indicate malware consuming resources in the background or an attacker moving data off your network.

2. Unfamiliar Programs or Processes

Software you don't recognize appearing in your installed programs list, startup items, or running processes deserves immediate attention — especially if it appeared without anyone knowingly installing it.

3. Accounts Locking Out or Password Resets You Didn't Request

Repeated lockouts or "your password was reset" emails you didn't trigger are a strong signal someone is attempting to access, or has already accessed, an account.

4. Unusual Outbound Network Traffic

A spike in data leaving your network, particularly to unfamiliar destinations or at odd hours, is one of the clearest indicators of an active compromise — often a sign that data is being exfiltrated.

5. Disabled Security Software

If antivirus, firewall, or endpoint protection tools are unexpectedly disabled and no one on your team turned them off, treat it as a red flag rather than a glitch.

6. New Admin Accounts You Didn't Create

Attackers often create their own administrative accounts to maintain access even if the original entry point is discovered and closed. Regularly audit who has admin-level access.

7. Pop-Ups, Redirects, or Browser Changes

Unexpected pop-ups, a homepage that's changed itself, or browser toolbars no one installed are classic signs of adware or more serious malware.

8. Emails Being Sent That You Didn't Write

If contacts report receiving strange emails "from you" that you never sent, your email account or an internal mail server may be compromised and used to spread further attacks.

9. Files That Are Missing, Encrypted, or Renamed

Files with unfamiliar extensions, folders that suddenly require a password, or data that's simply gone are often the first visible sign of a ransomware attack already underway. See our guide on ransomware protection for what to do next.

10. Security Alerts You're Used to Ignoring — Now Happening Constantly

A firewall or antivirus alert here and there is normal. A sudden flood of alerts, especially of the same type, usually means something is actively trying to get through — or already has.

The businesses that recover fastest from a breach are the ones that catch it early. Don't wait for certainty before investigating — a false alarm costs you an hour; a missed breach can cost weeks.

What to Do If You Spot These Signs

  1. Don't panic, but don't dismiss it either — document what you're seeing.
  2. Isolate the affected device from your network if possible.
  3. Avoid changing settings or "cleaning things up" yourself before a professional has looked at it — you may erase useful evidence.
  4. Contact your IT support provider to investigate and confirm whether it's a false alarm or an active incident.

Prevention Beats Detection

Catching a breach early is good. Never having one is better. Layered firewall, VPN, and intrusion prevention systems, combined with proactive network monitoring, dramatically reduce how often these warning signs show up in the first place.