Skip to main content

Network Essentials

Your Business Was Hacked. When Do You Call the FBI, and What Actually Happens?

What to do in the first hour after a cyber incident, how to report to IC3 and FBI Charlotte, what the Recovery Asset Team can get back, how to verify an FBI call, and where your IT provider hands off.
Charlotte business owner on the phone with an incident checklist and a closed laptop on his desk

Most Charlotte business owners never call the FBI after a cyber incident, for two reasons: they assume the FBI only cares about big companies, and they are afraid of what an investigation would mean for them. The FBI’s own 2026 Cyber Strategy answers both. It commits every field office to building relationships with local businesses before an incident, to notifying companies that have been compromised, often before they know, and it says in plain words that “the FBI pursues the actor, not the victim.” This guide covers what to do in the first hour, how to report, what the FBI can actually do for a small business, and where your IT provider hands off.

The first hour

  1. Stop the money first. If a payment went to the wrong account, call your bank immediately, ask for a recall or reversal, and ask for a Hold Harmless Letter or Letter of Indemnity. That is the IC3’s own guidance, and it works only if it happens in hours, not days.
  2. Call your IT provider, then your cyber insurer. Your provider contains the intrusion: isolating machines, disabling accounts, preserving logs. Your insurer’s policy usually requires notice before you engage anyone else, and it often pays for the lawyer and forensics.
  3. Do not wipe anything. Reformatting the laptop that was hit destroys the evidence that lets your provider find how they got in and lets the FBI connect your case to others.
  4. Write down what you know, with times. Which account, which device, which email, what was sent where. You will type it into the IC3 form and tell it to your insurer, and memory fades fast.

How to report, and what happens after

File at ic3.gov, the FBI’s Internet Crime Complaint Center. Anyone affected by a cyber-enabled crime can file, the form takes about 20 minutes, and it asks for the transaction details, the sender’s email headers, and the subject information you have. Fill in every banking field; the IC3 says that is “vital.”

Be clear about what the IC3 is not. It is a reporting and analysis center, not a case desk. Its FAQ says plainly, “You will not hear from the IC3.” Your report feeds two things: the investigators who connect your incident to a wider campaign, and the Recovery Asset Team below. For a time-sensitive situation, also call the local field office directly.

FBI Charlotte covers all of North Carolina: 7915 Microsoft Way, Charlotte, NC 28273, (704) 672-6100, answered 24 hours a day, or tips.fbi.gov.

Wire fraud: the team that gets money back

The IC3’s Recovery Asset Team, set up in 2018, works directly with banks to freeze fraudulent transfers to domestic accounts. In 2025 it handled 3,574 incidents with $833 million in reported losses and froze $507 million of it, a 61 percent recovery rate, according to the IC3’s own process sheet. Two things decide whether you are in the 61 percent: the money went to a U.S. bank, and you reported before it moved again. Business email compromise, the wire fraud that hits real estate closings and accounts-payable desks, is exactly the crime this team exists for.

If the FBI calls you

The 2026 strategy commits the FBI to “proactively notify organizations that have been compromised or are at imminent risk, often reaching them before they know there is a problem.” Those calls are real, and they are also the perfect script for a scammer. Do not act on the call itself. Hang up, look up FBI Charlotte’s number yourself, call it, and ask to be connected to the agent who contacted you. A real agent expects that. Then call your IT provider before anyone touches a system.

What the FBI will and will not do for a small business

  • Will: take your report, connect it to other victims of the same actor, attempt to freeze fraudulent domestic transfers, share indicators so your provider can block them, and notify you if your name turns up in someone else’s case.
  • Will not: restore your systems, negotiate with a ransomware crew for you, or give you status updates on the investigation. Recovery is your provider’s job and your insurer’s money.
  • The privacy point that keeps people from reporting: the strategy states the FBI “scopes its collection strictly to the crime” and uses “the least intrusive investigative method feasible.” Reporting a wire fraud does not turn your books into evidence.

Two things to do before anything happens

  1. Get a name at FBI Charlotte now. The strategy says field offices want the relationship before the crisis. Call the main number, say you run a Charlotte business and want the cyber squad’s contact for incident reporting, and keep it with your incident plan.
  2. Join InfraGard. It is the FBI’s partnership with the private sector for the protection of critical infrastructure, offering education, information sharing, networking and workshops on emerging threats. Membership is vetted, with identity verification through ID.me and an application to the FBI, and the local chapter puts you in the room with the people you would otherwise meet for the first time during an incident.

Where your IT provider fits

A written incident response plan, the one the FTC Safeguards Rule requires for CPA firms and every insurer now asks for, should name who calls the bank, who calls the insurer, who preserves evidence, and who files the IC3 report, with the FBI Charlotte number on the page. At Network Essentials that plan is part of onboarding, our security operations center contains the intrusion before the report is filed, and clients have after-hours emergency support so the first hour does not wait for the morning. Attackers move in 29 minutes; the response has to as well. Independently owned in Charlotte since 2002, CISSP-led, flat monthly fee with a $2,000 per month minimum and no long-term lock-in. Call (704) 206-8900 or request a free IT audit, and ask to see the incident response plan we would write for you.

Frequently asked questions

Should a small business report a cyberattack to the FBI?

Yes. File at ic3.gov and, if money moved or systems are down, call FBI Charlotte at (704) 672-6100. Reports connect your case to others and can trigger a freeze on fraudulent transfers. The FBI pursues the actor, not the victim.

Can the FBI get wired money back?

Sometimes. The IC3 Recovery Asset Team froze $507 million of $833 million reported in 2025, a 61 percent rate, but only for transfers to U.S. accounts reported quickly. Call your bank first, then file at ic3.gov with the full banking details.

Will the FBI call me if my business is compromised?

The FBI’s 2026 strategy commits it to proactive victim notification. Verify any such call by hanging up and phoning the field office number you look up yourself.

What is InfraGard?

The FBI’s partnership with the private sector for the protection of critical infrastructure, offering education, information sharing, networking and workshops on emerging threats. Membership is vetted through ID.me identity verification and an FBI application, and is open to business executives, IT professionals and other qualified applicants.

Smart Technology to Maximize Productivity