Guides Recovery
What to do when an account is hacked
Order matters. Doing these in the wrong sequence lets the attacker undo your work while you are still doing it.
1. Start with email
Whatever was breached, secure the email account first. It can reset the password of nearly everything else, so it is the account the attacker wants. Regaining a shopping account while they still hold your inbox achieves nothing.
2. Change the password from a device you trust
If malware on the machine is a possibility, use a different device. Changing a password on a computer with a keylogger simply tells the attacker the new one.
3. Sign out everywhere
Changing a password does not always end existing sessions. Most services have an option to sign out of all devices or revoke active sessions - use it, or the attacker stays signed in with the old credential.
4. Check what they changed
- Recovery email address and phone number - a common quiet change that keeps access open after you reset the password.
- Mail forwarding rules and filters, which silently copy or hide messages.
- Connected apps and third-party access, which can act on the account independently of your password.
- Second-factor devices registered to the account.
- Reply-to address and signature.
5. Turn on a second factor
If it was not on before, now is the moment. If it was on and they got in anyway, re-register it and remove any device you do not recognise.
6. Work outwards
Any account that used the same password, and any account whose recovery goes through the compromised one. This is the point at which reuse turns one incident into an afternoon of work.
7. Tell the people who will be targeted next
Contacts often receive messages from a compromised account. A short note saying it was compromised and to ignore anything unusual costs nothing and prevents the next person falling for it.
If money is involved
Contact the bank or card provider straight away - this is genuinely time-sensitive in a way the rest is not. Keep the messages and any transaction references. Depending on where you are, reporting it to the national fraud or cybercrime body may also be worthwhile.