Respond to a suspected compromise
What to do first when something looks wrong, in the order that limits the damage.
Version 1.0 · Last updated
When you would do this
When you see a payment nobody admits to creating, a counterparty address you do not recognise, a team member you did not invite, a card transaction from nowhere, or a colleague reporting a phishing email that someone may have acted on.
Act on suspicion. Do not wait until you have established what happened.
Steps
- Engage the emergency lock. An Admin does this from Settings › Security, typing LOCK to confirm. It halts payments immediately. It is reversible and it costs you an hour. Do this first, before investigating.
- Contact support. Tell us what you have seen and that you have locked the account.
- Cancel anything in flight. Anything in the signing queue that is not fully signed can be cancelled. Nothing has moved yet.
- Freeze cards that could be involved. See "Freeze or close a card".
- Check the audit log for the period in question: sign-ins including fallback sign-ins, payments created, counterparty addresses added or changed, policy changes, and team changes.
- Check your team list for members or pending invitations you did not authorise, and revoke them.
- Check counterparty addresses for anything added recently, especially on suppliers you pay regularly. Archive anything you cannot account for.
- Have affected people re-secure their access through support. See "Recover access to your account".
- Release the lock only when you understand what happened and have removed the cause.
What you cannot undo
A payment that has been broadcast cannot be recalled. If funds have already left, the lock stops further loss but does not recover what has gone. See "What can and cannot be reversed".
This is why the lock comes first and the investigation second.
The most common real scenarios
A changed supplier address. Someone acted on an email asking to update payment details. Check every counterparty address added recently, and see "Manage counterparty addresses safely".
A compromised email account. Payment instructions arrived from a genuine address belonging to someone whose mailbox was taken over. Verify by phone, always.
A shared or reused sign-in. Check the audit log for sign-ins that do not fit the person's working pattern.
A card number leaked. Freeze, review, close and reissue.
What to expect
Everything you do during the response is recorded, which is what you will need afterwards for your insurer, your bank or your regulator.
Stablerail cannot reverse blockchain payments and cannot recover sent funds. We can help you understand what happened and secure what remains.
